Skip to content

DEV infrastructure as code: deploy/ capture (compose, traefik, firewall, env contract, runbook) #205

Description

@damienriehl

Tracking issue for the U12 capture half (roundup plan U12, R11/R13).

Scope: promote the hand-rolled DEV server state into the repo as committed, placeholder-parameterized IaC:

  • deploy/compose.dev.yaml — the live DEV stack (verified byte-identical to the running /opt/ontokit/compose.yaml at capture, 2026-08-10)
  • deploy/traefik/ontokit-dev.yaml — proxy file-provider config (post-auth-flip: no basic-auth gate; ClientIP-exempt internal router)
  • deploy/firewall/ — idempotent port-lockdown script + systemd oneshot (replaces rules files that had no restore mechanism)
  • deploy/.env.example — the 12-key env contract, placeholders only
  • deploy/RUNBOOK.md — bootstrap/deploy/rollback/gotchas
  • deletes railway.json (superseded by the KD4 topology ruling)

The auto-deploy CI workflow half is deferred (blocked on a deploy keypair + CI).

PR: alea-institute/ontokit-api (branch feat/u12-dev-iac, stacked on feat/u7-zitadel-standup).

🤖 Generated with Claude Code

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions