Files
worker/docs/sessions/2026-07-19-standalone-deployment.md
Gleb Tv e987f24903
Все проверки выполнены успешно
CI / test (push) Successful in 2m32s
Docker / Build and publish worker image (push) Successful in 18m17s
fix(worker): harden control-plane lifecycle
- reconnect safely after token rotation and retry leased results
- reject malformed tasks and remove production cluster debug mutation
- validate environment files and require immutable container images

BREAKING CHANGE: Docker install, deploy, and Compose now require an
immutable repository@sha256 image reference.
2026-07-19 23:11:43 +03:00

59 строки
2.3 KiB
Markdown

# Session: Standalone Worker Deployment
Date: 2026-07-19
## Goal
Make `rsmon-worker` independently installable and deployable without requiring
the main `rsmon` repository. Keep direct binary plus systemd installation as the
default and offer the prebuilt Docker image as an explicit alternative.
## Completed
- Audited build and runtime paths for dependencies on `/data/_devops/rsmon` and
`/data/rsmon`.
- Removed the obsolete local certificate-bundle fallback.
- Switched the Dockerfile to public `golang:1-trixie` and `debian:13-slim`
bases.
- Implemented local binary and Docker installation in `internal/installer`.
- Implemented SSH deployment with key, password, passphrase, known-hosts, and
fingerprint support.
- Added `install` and `deploy` command handling and secret-file options to the
CLI.
- Added and updated installer tests, systemd packaging, deployment docs, and
the legacy installation wrapper.
- Reviewed the implementation for release blockers and secret exposure.
- Committed and pushed the work to `origin/master` as `3256dcd`.
## Decisions
- The default service uses `Type=simple`, runs as `root`, and restarts only on
failure.
- Docker deployment pulls an explicitly selected immutable image digest on the
target host instead of uploading a local image or binary. The original
mutable `latest` default was superseded by a supply-chain hardening change.
- The existing source-available license remains unchanged until public-release
licensing is decided.
- Worker credentials are supplied at deployment time and are not stored in the
repository.
## Verification
- `make test`
- `make build`
- `go vet ./cmd/rsmon-worker ./internal/installer`
- `go mod verify`
- Docker image pull and `--version` execution
- Compose configuration with a temporary environment fixture
- Live WebSocket connection, configuration receipt, job execution, and result
reporting
## Operational State
- A local worker was left running as `./bin/rsmon-worker --no-web`, PID
`211207`, with logs in `/tmp/rsmon-worker-local.log`.
- The worker received configuration as worker ID `test` and continued reporting
results after automatic reconnections caused by periodic WebSocket EOFs.
- Pushing `master` triggered `.github/workflows/docker.yml`; workflow completion
was not checked during the session.