_manifest.json
_manifest.json is a file in Bane's Lab Deploy. 82 lines of code and 0 definitions.
{
"label": "Bane's Lab Deploy",
"summary": "Ships the built site to the droplet over SSH with rolling backups and rollback, syncs the nginx configuration both ways, and reports every run to Discord.",
"maturity": "experimental",
"domains": [
{"meta": "devops",
"sub": "deployment"},
{"meta": "communication",
"sub": "notifications"}
],
"ecosystem": "typescript",
"visibility": {"private": true,
"hidden": false},
"capabilities": [
"build-and-upload-the-site",
"archive-and-restore-the-remote-site",
"sync-nginx-configuration",
"verify-nginx-after-reload",
"report-runs-to-discord"
],
"governedBy": [
"separation-of-concerns",
"type-safety"
],
"entries": ["runtime/entrypoints/*.entrypoint.ts"],
"docs": {
"overview": "The member has a deployment entry point and an nginx entry point. `runtime/entrypoints/deployment.entrypoint.ts` builds the site with Vite, connects to the droplet, archives the live site into the directory declared as `app.backups`, prunes old archives, uploads the build output and reports the outcome. A failure restores the archive it just took. `runtime/entrypoints/nginx.entrypoint.ts` pushes the managed nginx files from the directory declared as `app.nginx` to the droplet, tests and reloads nginx and verifies it is active. It can also pull the live configuration into a local backup. Every remote action goes through `core/adapters/shell.adapter.ts`, every Discord message through `core/adapters/webhook.adapter.ts`, and every location through `@ssot/paths`.",
"whenToUse": [
"Publishing the site. `npm run deploy` runs from this member after the gate is green.",
"Changing nginx. Edit the files under the directory declared as `app.nginx`, then run `npm run nginx`.",
"Inspecting the live nginx configuration with `npm run nginx -- pull` or `pull-full`."
],
"whenNotToUse": [
"Building for local preview. The web member's own `npm run build` does that without touching the droplet.",
"Provisioning a new droplet. This member assumes nginx, the site directory and the SSH key already exist."
],
"install": "Hoisted from the root workspace. Secrets are read from the vault through `@ssot/secrets`, which needs the vault open: `DEPLOY_HOST`, `DEPLOY_DISCORD_WEBHOOK_URL` and `NGINX_DISCORD_WEBHOOK_URL` (required) and `SSH_PASSPHRASE` (optional). The SSH key is read from the developer's `.ssh` directory.",
"quickStart": [
{"intent": "Deploy the site",
"lang": "bash",
"code": "npm run deploy --workspace @banes-lab/deploy"},
{
"intent": "Push the nginx configuration",
"lang": "bash",
"code": "npm run nginx --workspace @banes-lab/deploy -- push"
}
],
"configuration": [
{
"option": "configuration/constants/deployment.constants.ts",
"note": "the remote site directory, backup retention, upload concurrency and the monitoring links."
},
{
"option": "configuration/constants/nginx.constants.ts",
"note": "the remote nginx locations and the test, reload and status commands."
},
{"option": "configuration/constants/ssh.constants.ts",
"note": "the droplet user and the key file name."}
],
"disposal": [
"Remove the member's workspace entry from the root `package.json`.",
"Remove its governed-root entry from `containers` and `specialContainers` in `.govlab/shared/configs/taxonomy.config.ts`.",
"Remove the `deploy`, `nginx`, `nginxSite`, `server` and `backups` keys from the `app` branch of `project.paths/paths.yaml`, and the deploy keys from the `@ssot/secrets` schema and the vault when no other member reads them.",
"Delete the directory, reinstall, run the gate."
],
"apiNotes": [
{
"name": "createShell",
"note": "Wraps one `node-ssh` session. Every method except `connect` throws until `connect` has resolved, so a step can never run against a closed session."
},
{
"name": "archiveSite",
"note": "Creates the archive on the droplet, downloads it, then removes the remote copy. The returned name is what `restoreSite` takes back."
}
],
"aiContext": [
"No step spells a location. Local paths resolve through `@ssot/paths`, and remote paths are constants in `configuration/constants/`.",
"A step never talks to the network directly. It takes the `Shell` and reports through the `Journal`.",
"Copy shown to the developer or posted to Discord lives in `configuration/strings/`."
]
}
}