feat(deploy): self-host broker + Postgres on the lab Synology - #45
Merged
Merged
Conversation
One Container Manager project runs Postgres and the broker together; DSM's reverse proxy fronts it. CI now pushes the image to GHCR after the suites pass, Watchtower on the NAS pulls :latest, and nas-deploy-check waits for /healthz to report the pushed commit (skipped until vars.NAS_BROKER_URL is set). The Render deploy stays until cut-over. The image takes a CASEBROKER_COMMIT build arg so /healthz names its commit outside Render. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds a self-hosted deployment path next to Render + Supabase:
deploy/synology/compose.yaml: Postgres 17 and the broker in one Container Manager project. The broker binds127.0.0.1:8010only; DSM's reverse proxy terminates TLS in front of it. Only the broker carries the Watchtower enable label, so Postgres is never auto-upgraded.deploy/synology/README.md: runbook covering one-time setup, moving the campaign off Supabase, rollback by tag, and nightlypg_dumpbackups.deploy/synology/.env.example: placeholders only. The filled-in.envlives on the NAS and is never committed.publish-imagepushesghcr.io/sustainableurbansystemslab/casebroker:latestand:sha-<sha>on pushes tomain, gated on the same jobs as the Render deploy.nas-deploy-checkpolls$NAS_BROKER_URL/healthzuntil it reports this commit. It is skipped whilevars.NAS_BROKER_URLis unset, so it cannot go red before the NAS exists. Like the Render check, it never prints the response body.Dockerfile:CASEBROKER_COMMITbuild arg, so/healthzreports its commit outside Render.The Render deploy job is unchanged. It is retired after cut-over, per the runbook.
After merge
casebrokerGHCR package public (first run creates it private).X-Forwarded-Proto: https, plus the DNS record.NAS_BROKER_URL.Tests
Locally: 377 passed, 30 skipped, plus 1 failure in
test_concurrent_opens_of_one_case_share_one_building_query. That test passed 3/3 on rerun, so it's timing-flaky, and this PR touches no Python code.🤖 Generated with Claude Code