README.md

README.md is a file in Bane's Lab Deploy. 77 lines of code and 0 definitions.

<!-- Auto-generated 2026-10-04T16:25Z v6 -->

# @banes-lab/deploy

<!-- concern:overview -->

## Purpose

The member has a deployment entry point and an nginx entry point. `runtime/entrypoints/deployment.entrypoint.ts` builds the site with Vite, connects to the droplet, archives the live site into the directory declared as `app.backups`, prunes old archives, uploads the build output and reports the outcome. A failure restores the archive it just took. `runtime/entrypoints/nginx.entrypoint.ts` pushes the managed nginx files from the directory declared as `app.nginx` to the droplet, tests and reloads nginx and verifies it is active. It can also pull the live configuration into a local backup. Every remote action goes through `core/adapters/shell.adapter.ts`, every Discord message through `core/adapters/webhook.adapter.ts`, and every location through `@ssot/paths`.
<!-- /concern:overview -->

<!-- concern:use -->

## When to use

- Publishing the site. `npm run deploy` runs from this member after the gate is green.
- Changing nginx. Edit the files under the directory declared as `app.nginx`, then run `npm run nginx`.
- Inspecting the live nginx configuration with `npm run nginx -- pull` or `pull-full`.

## When NOT to use

- Building for local preview. The web member's own `npm run build` does that without touching the droplet.
- Provisioning a new droplet. This member assumes nginx, the site directory and the SSH key already exist.

<!-- /concern:use -->

<!-- concern:charts -->

## Architecture charts

The structure, logical-flow and dependency diagrams derived from the source AST live in [_code.info.generated/mermaid-charts.generated.md](./_code.info.generated/mermaid-charts.generated.md).
<!-- /concern:charts -->

<!-- concern:install -->

## Install

Hoisted from the root workspace. Secrets are read from the vault through `@ssot/secrets`, which needs the vault open: `DEPLOY_HOST`, `DEPLOY_DISCORD_WEBHOOK_URL` and `NGINX_DISCORD_WEBHOOK_URL` (required) and `SSH_PASSPHRASE` (optional). The SSH key is read from the developer's `.ssh` directory.

## Quick start

```bash EXAMPLE: Deploy the site
npm run deploy --workspace @banes-lab/deploy
```

```bash EXAMPLE: Push the nginx configuration
npm run nginx --workspace @banes-lab/deploy -- push
```

<!-- /concern:install -->

<!-- concern:api -->

## API

The package exposes no public API.
<!-- /concern:api -->

<!-- concern:config -->

## Configuration

- `configuration/constants/deployment.constants.ts` — the remote site directory, backup retention, upload concurrency and the monitoring links.
- `configuration/constants/nginx.constants.ts` — the remote nginx locations and the test, reload and status commands.
- `configuration/constants/ssh.constants.ts` — the droplet user and the key file name.

<!-- /concern:config -->

<!-- concern:deps -->

## Dependencies

- `@banes-lab/build-scripts`
- `@banes-lab/web`
- `@govlab/content-fingerprint`
- `@ssot/paths`
- `@ssot/secrets`

<!-- /concern:deps -->

<!-- concern:ai-context -->

## AI context

- No step spells a location. Local paths resolve through `@ssot/paths`, and remote paths are constants in `configuration/constants/`.
- A step never talks to the network directly. It takes the `Shell` and reports through the `Journal`.
- Copy shown to the developer or posted to Discord lives in `configuration/strings/`.

<!-- /concern:ai-context -->

<!-- concern:domains -->

## Domains

This package serves these software domains, which `_manifest.json` declares in `domains` from the two-tier software-domain vocabulary (`meta → sub`):

- **communication** — notifications
- **devops** — deployment

<!-- /concern:domains -->

<!-- concern:quality-governance -->

## Quality governance

The canonical quality catalog resolves the quality concepts that govern this package. `_manifest.json` declares them in `governedBy`, and a lint package derives them from the concepts its own rules enforce. Each maps to the custom lint rules that enforce it:

- **separation-of-concerns** — _complexity_
- **type-safety** — _correctness_

<!-- /concern:quality-governance -->

<!-- concern:disposal -->

## Disposal

- Remove the member's workspace entry from the root `package.json`.
- Remove its governed-root entry from `containers` and `specialContainers` in `.govlab/shared/configs/taxonomy.config.ts`.
- Remove the `deploy`, `nginx`, `nginxSite`, `server` and `backups` keys from the `app` branch of `project.paths/paths.yaml`, and the deploy keys from the `@ssot/secrets` schema and the vault when no other member reads them.
- Delete the directory, reinstall, run the gate.

<!-- /concern:disposal -->

<!-- concern:metrics -->

---

experimental · 0 exports · 5 deps · 0 principles · 2 concepts
<!-- /concern:metrics -->