2.3 KiB
2.3 KiB
TASK: Multi-account deploy — packaging + runbook, 9 accounts / 2 hosts (Redmine 494)
Context
Spec: docs/SPEC-20260829-charles-brief.md (account list inside). The PMO runtime CANNOT ssh or sudo — this turn produces everything so that deployment is a ~10-minute Charles window executing one runbook.
Accounts
- ultix-streaming: reachableceo, TSGBOD, TSGCOO, TSGCTO, TSGCCO
- ultix-offstage (ssh reachableceo-offstage, passwordless sudo there): reachableceo-offstage, COSRCEO-Personal, COSRCEO-Biz, COSWFO
Scope
deploy/directory in the harness repo:deploy/accounts.tsv— account, host, vertical, redmine project scope, port assignments (events/serve per account: derive a scheme, e.g. base port 4100+ / 8090+ offset by account index).deploy/install-account.sh <account>— idempotent, runs AS the target user (no root needed if binary path is ~/.local/bin): creates ~/.mopac/{bin,state,reports}, installs static binary (built in the Docker builder for linux/amd64), writes harness.toml from a template (per-account substitutions), refuses to overwrite existing harness.toml or secrets.deploy/runbook.md— the exact Charles sequence: build once (docker), copy/ssh loop per host+account, run install script, start command per account (nohup or cron @reboot line — NO systemd claims without root; document both options), verify (healthz curl-equivalent- first
loop --oncedry output), rollback (stop + rm ~/.mopac/bin).
- first
- Per-account harness.toml template with vertical/redmine-scope/ports substituted; secrets stay env refs (0600 env files per account, bootstrap instructions).
- Static binary build: Makefile target
release(docker builder, GOOS=linux GOARCH=amd64, CGO=0) producingbin/harness-linux-amd64. - Concurrency guard: distinct state dirs + ports per account so multiple daemons on one host never collide; document the account-port table.
- Tests where feasible (template substitution, port derivation, idempotence of install script in a fake HOME). Docs standard.
Deliverable
Commits pushed to ukrrs/MOPAC main (deploy/ + Makefile release target +
README deploy section). REPORT-20260829-0900-deploy.md in
~/.coordinate/inbox-pmo/: what Charles executes, per-host time estimate,
verification steps, rollback.