Files
git.stella-ops.org/docs/implplan/SPRINT_501_ops_deployment_i.md
StellaOps Bot d92973d6fd
Some checks failed
Docs CI / lint-and-preview (push) Has been cancelled
Mirror Thin Bundle Sign & Verify / mirror-sign (push) Has been cancelled
sprints update
2025-11-25 07:49:24 +02:00

6.4 KiB

Sprint 501 - Ops & Offline · 190.A) Ops Deployment.I

Active items only. Completed/historic work now resides in docs/implplan/archived/tasks.md (updated 2025-11-08).

[Ops & Offline] 190.A) Ops Deployment.I Depends on: Sprint 100.A - Attestor, Sprint 110.A - AdvisoryAI, Sprint 120.A - AirGap, Sprint 130.A - Scanner, Sprint 140.A - Graph, Sprint 150.A - Orchestrator, Sprint 160.A - EvidenceLocker, Sprint 170.A - Notifier, Sprint 180.A - Cli

Topic & Scope

  • Ship deployable artefacts (Helm/Compose/offline kits) across modules without leaving deployment work inside dev sprints.
  • Provide signed mirror/export bundles and backup/restore guidance for regulated environments.

Dependencies & Concurrency

  • Upstream module artefacts must exist before packaging; see task-level dependencies (e.g., MIRROR-KEY-56-002-CI, LEDGER-29-009-DEV).
  • Can run in parallel to module development; outputs live under ops/deployment.

Documentation Prerequisites

  • docs/modules/devops/architecture.md
  • docs/modules/ci/architecture.md
  • docs/airgap/** (for mirror/import tasks)

Delivery Tracker

Task ID State Task description Owners (Source)
COMPOSE-44-001 BLOCKED Author docker-compose.yml, .env.example, and quickstart.sh with all core services + dependencies (postgres, redis, object-store, queue, otel). Deployment Guild, DevEx Guild (ops/deployment)
COMPOSE-44-002 TODO Implement backup.sh and reset.sh scripts with safety prompts and documentation. Dependencies: COMPOSE-44-001. Deployment Guild (ops/deployment)
COMPOSE-44-003 TODO Package seed data container and onboarding wizard toggle (QUICKSTART_MODE), ensuring default creds randomized on first run. Dependencies: COMPOSE-44-002. Deployment Guild, Docs Guild (ops/deployment)
DEPLOY-AIAI-31-001 TODO Provide Helm/Compose manifests, GPU toggle, scaling/runbook, and offline kit instructions for Advisory AI service + inference container. Deployment Guild, Advisory AI Guild (ops/deployment)
DEPLOY-AIRGAP-46-001 BLOCKED (2025-11-25) Provide instructions and scripts (load.sh) for importing air-gap bundle into private registry; update Offline Kit guide. Deployment Guild, Offline Kit Guild (ops/deployment)
DEPLOY-CLI-41-001 TODO Package CLI release artifacts (tarballs per OS/arch, checksums, signatures, completions, container image) and publish distribution docs. Deployment Guild, DevEx/CLI Guild (ops/deployment)
DEPLOY-COMPOSE-44-001 TODO Finalize Quickstart scripts (quickstart.sh, backup.sh, reset.sh), seed data container, and publish README with imposed rule reminder. Deployment Guild (ops/deployment)
DEPLOY-EXPORT-35-001 BLOCKED (2025-10-29) Package exporter service/worker Helm overlays (download-only), document rollout/rollback, and integrate signing KMS secrets. Deployment Guild, Exporter Service Guild (ops/deployment)
DEPLOY-EXPORT-36-001 TODO Document OCI/object storage distribution workflows, registry credential automation, and monitoring hooks for exports. Dependencies: DEPLOY-EXPORT-35-001. Deployment Guild, Exporter Service Guild (ops/deployment)
DEPLOY-HELM-45-001 TODO Publish Helm install guide and sample values for prod/airgap; integrate with docs site build. Deployment Guild (ops/deployment)
DEPLOY-NOTIFY-38-001 BLOCKED (2025-10-29) Package notifier API/worker Helm overlays (email/chat/webhook), secrets templates, rollout guide. Deployment Guild, DevOps Guild (ops/deployment)
DEPLOY-ORCH-34-001 TODO Provide orchestrator Helm/Compose manifests, scaling defaults, secret templates, offline kit instructions, and GA rollout/rollback playbook. Deployment Guild, Orchestrator Service Guild (ops/deployment)
DEPLOY-PACKS-42-001 TODO Provide deployment manifests for packs-registry and task-runner services, including Helm/Compose overlays, scaling defaults, and secret templates. Deployment Guild, Packs Registry Guild (ops/deployment)
DEPLOY-PACKS-43-001 TODO Ship remote Task Runner worker profiles, object storage bootstrap, approval workflow integration, and Offline Kit packaging instructions. Dependencies: DEPLOY-PACKS-42-001. Deployment Guild, Task Runner Guild (ops/deployment)
DEPLOY-POLICY-27-001 TODO Produce Helm/Compose overlays for Policy Registry + simulation workers, including Mongo migrations, object storage buckets, signing key secrets, and tenancy defaults. Deployment Guild, Policy Registry Guild (ops/deployment)
DEPLOY-MIRROR-23-001 BLOCKED (2025-11-23) Publish signed mirror/offline artefacts; needs MIRROR_SIGN_KEY_B64 wired in CI (from MIRROR-KEY-56-002-CI) and Attestor mirror contract. Deployment Guild, Security Guild (ops/deployment)
DEVOPS-MIRROR-23-001-REL BLOCKED (2025-11-25) Release lane for advisory mirror bundles; migrated from SPRINT_0112_0001_0001_concelier_i, shares dependencies with DEPLOY-MIRROR-23-001 (Attestor contract, CI signing secret). DevOps Guild · Security Guild (ops/deployment)
DEPLOY-LEDGER-29-009 BLOCKED (2025-11-23) Provide Helm/Compose/offline-kit manifests + backup/restore runbook paths for Findings Ledger; waits on DevOps-approved target directories before committing artefacts. Deployment Guild, Findings Ledger Guild, DevOps Guild (ops/deployment)

Execution Log

Date (UTC) Update Owner
2025-11-25 Marked COMPOSE-44-001 BLOCKED: waiting on consolidated service list + version pins from upstream module releases before writing compose/quickstart bundle. Project Mgmt
2025-11-25 Marked DEPLOY-AIRGAP-46-001 BLOCKED: waiting on Mirror staffing + DSSE plan (001_PGMI0101, 002_ATEL0101) before authoring load scripts and offline kit guide updates. Project Mgmt
2025-11-25 Ingested DEVOPS-MIRROR-23-001-REL from Concelier I sprint; track alongside DEPLOY-MIRROR-23-001 with same CI/signing dependencies. Project Mgmt
2025-11-23 Added DEPLOY-MIRROR-23-001 and DEPLOY-LEDGER-29-009; normalised sprint with template sections. Project Mgmt

Decisions & Risks

  • Mirror signing secret (MIRROR_SIGN_KEY_B64) and Attestor contract are outstanding; DEPLOY-MIRROR-23-001 remains blocked until provided.
  • Findings Ledger deployment assets cannot be committed until DevOps assigns target directories to keep module boundaries clean.

Next Checkpoints

  • 2025-11-25: Review mirror signing secret readiness with Security/DevOps.
  • 2025-11-26: Findings Ledger deployment path/backup runbook review with DevOps Guild.