837f0fa63f
Close deployment IDOR and gate stub payment endpoints, add production secret validation, health probes, Redis-backed build progress, GitHub Actions CI, expanded tests, billing/k8s refactors, and ops runbooks. Co-authored-by: Cursor <cursoragent@cursor.com>
1.7 KiB
1.7 KiB
CloudHost — Operations Runbook (English)
Short operational guide. For architecture details see ARCHITECTURE.md. For Persian production deploy steps see RUNBOOK.fa.md.
Stack
- Frontend: Next.js 16 (
/fa-IR,/en-USroutes) - Backend: NestJS 11 (
/api/v1, Swagger at/api/docs) - Data: PostgreSQL 16, Redis 7
- Build: Kaniko in-cluster (
cloudhost-buildsnamespace) - Deploy: Helm charts (
cloudhost-platform,cloudhost-app,cloudhost-logging)
Health checks
| Endpoint | Purpose |
|---|---|
GET /api/v1/health |
Liveness |
GET /api/v1/ready |
Readiness (DB ping) |
Local development
docker compose up -d postgres redis
cd backend && cp .env.example .env && npm run start:dev
cd frontend && cp .env.local.example .env.local && npm run dev
SQL migrations
- Add file under
backend/migrations/ - Run
cd backend && npm run sync:migrations(copies into Helm chart) - Helm post-install Job applies migrations on upgrade
Build namespace bootstrap
kubectl apply -f backend/k8s/builds/cloudhost-builds-bootstrap.yaml
Configure REGISTRY_URL, BUILD_NAMESPACE, and CLUSTER_KUBECONFIG_KEY in backend env.
Backups (optional Helm)
Enable in values.yaml:
backups:
postgres:
enabled: true
schedule: "0 3 * * *"
storageSize: 10Gi
Restore: gunzip -c backup.sql.gz | psql against the control-plane database.
Monitoring (optional)
Enable Prometheus ServiceMonitor:
monitoring:
enabled: true
Requires kube-prometheus-stack or compatible Prometheus Operator in the cluster.
CI
GitHub Actions runs backend/frontend tests, typecheck, build, and helm lint on push/PR.