diff --git a/apps/backend/README.md b/apps/backend/README.md index 45c1ec2..32e53a7 100644 --- a/apps/backend/README.md +++ b/apps/backend/README.md @@ -177,6 +177,8 @@ The GitHub `staging` environment exists, but its secret inventory was empty when After the mode and evidence path are validated, every automated deployment writes an `attempting`, `failed`, or `verified` evidence artifact. Build, dry-run, prior-deployment lookup, source-ref, upload, and verification failures identify their stage. Failed post-upload evidence includes `priorDeployment`, the exact deployment state captured before upload. Recover staging with its prior 100% version: +Post-merge run `30886405702` exercised the missing-token path at commit `16eda20956f902e87baaf6d6c2ce7b84be87232e`. It made no staging upload and preserved an artifact with `outcome: "failed"`, `failureStage: "prior-deployment"`, `exitCode: 1`, and `priorDeployment: null`. + ```bash previous_version="$(jq -r '.priorDeployment.versions[] | select(.percentage == 100) | .version_id' /absolute/path/staging-deployment.json)" pnpm --filter @understudy/backend exec wrangler rollback "$previous_version" \ diff --git a/docs/network-blip-rollout-handoff.md b/docs/network-blip-rollout-handoff.md index f6176e1..826777b 100644 --- a/docs/network-blip-rollout-handoff.md +++ b/docs/network-blip-rollout-handoff.md @@ -4,7 +4,7 @@ ## Current state -This record applies to the protocol-3 stack merged into `dev` by PR #24 at `a35b8221111df6757ec6d87745cd7110e804536e`. Its historical comparison base is `origin/dev` at `857e0e3ebb8312be3e260e7339968f602703afdf`, and the semantic tranche starts after `554a09c53dd4a9b64755da38d0260d4da37fa3d2`. The first automatic staging deployment did not upload because its GitHub environment lacked `CLOUDFLARE_API_TOKEN`; production still serves the pre-change Worker until an operator completes the gated release process. +This record applies to the protocol-3 stack merged into `dev` by PR #24 at `a35b8221111df6757ec6d87745cd7110e804536e`. Its historical comparison base is `origin/dev` at `857e0e3ebb8312be3e260e7339968f602703afdf`, and the semantic tranche starts after `554a09c53dd4a9b64755da38d0260d4da37fa3d2`. Automatic staging still stops before upload because its GitHub environment lacks `CLOUDFLARE_API_TOKEN`; PR #26 made that failure auditable, and run `30886405702` uploaded the failed evidence artifact without changing staging. Production still serves the pre-change Worker until an operator completes the gated release process. Historical sanitized observations: diff --git a/docs/unattended-production-rollout.md b/docs/unattended-production-rollout.md index b45f5de..61733f7 100644 --- a/docs/unattended-production-rollout.md +++ b/docs/unattended-production-rollout.md @@ -2,7 +2,7 @@ # Finish the protocol-3 production rollout -This runbook defines the release sequence after PR #24 merged the protocol-3 implementation into `dev`. Source integration and the local automated checks are complete. The first automatic staging deployment stopped before upload because the `staging` GitHub environment had no `CLOUDFLARE_API_TOKEN`; no staging Worker change occurred. Staging credentials and provisioning, network disruption tests, publishing, production changes, destructive cleanup, canary acceptance, and the HTTPS Strict Transport Security (HSTS) apex rollout still require operator action. +This runbook defines the release sequence after PR #24 merged the protocol-3 implementation into `dev`. Source integration and the local automated checks are complete. Automatic staging stops before upload because the `staging` GitHub environment has no `CLOUDFLARE_API_TOKEN`; no staging Worker change occurred. PR #26 corrected early failure evidence, and post-merge run `30886405702` uploaded an artifact for the same external credential failure. Staging credentials and provisioning, network disruption tests, publishing, production changes, destructive cleanup, canary acceptance, and the HTTPS Strict Transport Security (HSTS) apex rollout still require operator action. ## Handoff baseline @@ -14,6 +14,7 @@ Use this table to establish the source and environment before you act: | Integration pull request | PR #24, merged 2026-08-04 | | Feature head | `414aa35d30115e5e157d81e1abe3add88dfe9e21` | | Integration merge | `a35b8221111df6757ec6d87745cd7110e804536e` | +| Deployment-evidence follow-up | PR #26, merged at `16eda20956f902e87baaf6d6c2ce7b84be87232e` | | Historical comparison base | `origin/dev` at `857e0e3ebb8312be3e260e7339968f602703afdf` | | Semantic tranche base | `554a09c53dd4a9b64755da38d0260d4da37fa3d2` (`feat: add guarded deployment workflow`) | | Release source | Current `origin/dev`; refresh it and resolve with `git rev-parse origin/dev` before acting | @@ -51,8 +52,8 @@ These results apply to the source code in this branch. A code or configuration c | Store package | Pre-workflow `0.2.0` artifact SHA-256 `3b492a1608131088c607e5254317708165e8785c67ee73c393c40578fff9b54f` | Superseded; rebuild after the deployment changes | | Wrangler | Generated types current; deployment dry run completed without upload | Passed | | Review lanes | Independent clean-code, architecture, and quality-assurance reviews returned clean after fixes | Passed | -| Integration workflows | PR #24 and post-merge CI passed; Version run `30883763357` opened release PR #25 | Passed | -| Automatic staging deployment | Run `30883763461` passed install, build, typecheck, tests, Worker types, extension verification, and dry run, then failed before upload because the `staging` environment had no `CLOUDFLARE_API_TOKEN` | Blocked; no staging mutation | +| Integration workflows | PR #24 and PR #26 passed CI and merged; post-PR #26 CI run `30886405878` and Version run `30886405689` passed; release PR #25 is open | Passed | +| Automatic staging deployment | Run `30883763461` exposed the missing token and absent failure artifact. After PR #26, run `30886405702` again stopped before upload, then successfully uploaded failed evidence for source `16eda20956f902e87baaf6d6c2ce7b84be87232e` | Blocked; no staging mutation | | Network baseline | Test A 10s and 30s passed; Test A 60s and 120s plus Test B 30s remain | Partial | | Production HSTS | 2026-08-04 probes found no HTTP upgrade and no HTTPS HSTS header; the 2026-08-02 DNS inventory found no apex address record | Pending | | Cloud-vault cleanup | No values, namespace, or production secrets were deleted | Pending |