Skip to content

feat(deploy): self-host broker + Postgres on the lab Synology - #45

Merged
kastnerp merged 1 commit into
mainfrom
deploy/synology-nas
Oct 4, 2026
Merged

kastnerp merged 1 commit into
mainfrom
deploy/synology-nas

Conversation

@kastnerp

@kastnerp kastnerp commented Oct 4, 2026

Copy link
Copy Markdown
Member

What

Adds a self-hosted deployment path next to Render + Supabase:

  • deploy/synology/compose.yaml: Postgres 17 and the broker in one Container Manager project. The broker binds 127.0.0.1:8010 only; DSM's reverse proxy terminates TLS in front of it. Only the broker carries the Watchtower enable label, so Postgres is never auto-upgraded.
  • deploy/synology/README.md: runbook covering one-time setup, moving the campaign off Supabase, rollback by tag, and nightly pg_dump backups.
  • deploy/synology/.env.example: placeholders only. The filled-in .env lives on the NAS and is never committed.
  • CI:
    • publish-image pushes ghcr.io/sustainableurbansystemslab/casebroker:latest and :sha-<sha> on pushes to main, gated on the same jobs as the Render deploy.
    • nas-deploy-check polls $NAS_BROKER_URL/healthz until it reports this commit. It is skipped while vars.NAS_BROKER_URL is unset, so it cannot go red before the NAS exists. Like the Render check, it never prints the response body.
  • Dockerfile: CASEBROKER_COMMIT build arg, so /healthz reports its commit outside Render.
  • Version 0.26.1 → 0.27.0.

The Render deploy job is unchanged. It is retired after cut-over, per the runbook.

After merge

  1. Make the casebroker GHCR package public (first run creates it private).
  2. Set up the DSM reverse proxy rule with X-Forwarded-Proto: https, plus the DNS record.
  3. Set the repo variable NAS_BROKER_URL.

Tests

Locally: 377 passed, 30 skipped, plus 1 failure in test_concurrent_opens_of_one_case_share_one_building_query. That test passed 3/3 on rerun, so it's timing-flaky, and this PR touches no Python code.

🤖 Generated with Claude Code

One Container Manager project runs Postgres and the broker together;
DSM's reverse proxy fronts it. CI now pushes the image to GHCR after
the suites pass, Watchtower on the NAS pulls :latest, and
nas-deploy-check waits for /healthz to report the pushed commit
(skipped until vars.NAS_BROKER_URL is set). The Render deploy stays
until cut-over.

The image takes a CASEBROKER_COMMIT build arg so /healthz names its
commit outside Render.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kastnerp
kastnerp merged commit 5629511 into main Oct 4, 2026
8 checks passed
@kastnerp
kastnerp deleted the deploy/synology-nas branch October 4, 2026 18:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant