Skip to content

docs: add deployment guide - #126

Merged
obchain merged 2 commits into
mainfrom
docs/deployment-guide
Jun 22, 2026
Merged

obchain merged 2 commits into
mainfrom
docs/deployment-guide

Conversation

@obchain

@obchain obchain commented Jun 22, 2026

Copy link
Copy Markdown
Owner

What

Add docs/deployment.md — a dedicated production deployment guide, so "how VolX is deployed" lives in one place instead of scattered across the README.

Contents

  • Topology diagram — Netlify frontend → Cloudflare Tunnel → the always-on server's Docker Compose stack → Sepolia.
  • Containers table — the six volx-* services (compose project volx-prod), which ports are published (only the API, loopback-only) and which stay internal.
  • Public exposure — the Cloudflare Tunnel model (host-installed vs containerized connector), no inbound ports opened.
  • Images & registry — Docker Hub, latest + git-sha tags, server pulls (no source checkout).
  • CI/CD pipeline — gated ci → deploy (build matrix → push → SSH-over-Cloudflare-Access → write .env from secrets → deploy.sh), with the concurrency/serialization guarantees.
  • deploy.sh — the idempotent pull-and-apply (recreates only changed services).
  • Configuration & secrets — runtime .env + GitHub Actions secrets tables; the rotate-both-or-drift note.
  • On-chain keeper — deviation/heartbeat push triggers + the staleness guard.
  • Local production-stack run.

Notes

obchain added 2 commits June 22, 2026 14:43
Document how VolX runs in production: the six-container Docker Compose stack
on a single always-on server, the Cloudflare Tunnel exposure model (only the
API published, no inbound ports), Docker Hub image registry with latest +
git-sha tags, the gated CI -> build -> pull-deploy pipeline, deploy.sh
behaviour, the runtime/secret configuration, and the on-chain keeper bridge.
Review feedback: the secrets section conflated CI build secrets with the
server runtime .env. Split them into two tables (server .env vs GitHub
Actions secrets), make explicit that the Docker Hub repos are public so the
server pulls anonymously and DOCKER_USERNAME/PASSWORD are never written to
the server .env, and note that the keeper timing constants are baked into
the compose file rather than .env-overridable.
@obchain
obchain merged commit 318c20e into main Jun 22, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant