README.md
README.md is a file in Bane's Lab Deploy. 77 lines of code and 0 definitions.
<!-- Auto-generated 2026-10-04T16:25Z v6 -->
# @banes-lab/deploy
<!-- concern:overview -->
## Purpose
The member has a deployment entry point and an nginx entry point. `runtime/entrypoints/deployment.entrypoint.ts` builds the site with Vite, connects to the droplet, archives the live site into the directory declared as `app.backups`, prunes old archives, uploads the build output and reports the outcome. A failure restores the archive it just took. `runtime/entrypoints/nginx.entrypoint.ts` pushes the managed nginx files from the directory declared as `app.nginx` to the droplet, tests and reloads nginx and verifies it is active. It can also pull the live configuration into a local backup. Every remote action goes through `core/adapters/shell.adapter.ts`, every Discord message through `core/adapters/webhook.adapter.ts`, and every location through `@ssot/paths`.
<!-- /concern:overview -->
<!-- concern:use -->
## When to use
- Publishing the site. `npm run deploy` runs from this member after the gate is green.
- Changing nginx. Edit the files under the directory declared as `app.nginx`, then run `npm run nginx`.
- Inspecting the live nginx configuration with `npm run nginx -- pull` or `pull-full`.
## When NOT to use
- Building for local preview. The web member's own `npm run build` does that without touching the droplet.
- Provisioning a new droplet. This member assumes nginx, the site directory and the SSH key already exist.
<!-- /concern:use -->
<!-- concern:charts -->
## Architecture charts
The structure, logical-flow and dependency diagrams derived from the source AST live in [_code.info.generated/mermaid-charts.generated.md](./_code.info.generated/mermaid-charts.generated.md).
<!-- /concern:charts -->
<!-- concern:install -->
## Install
Hoisted from the root workspace. Secrets are read from the vault through `@ssot/secrets`, which needs the vault open: `DEPLOY_HOST`, `DEPLOY_DISCORD_WEBHOOK_URL` and `NGINX_DISCORD_WEBHOOK_URL` (required) and `SSH_PASSPHRASE` (optional). The SSH key is read from the developer's `.ssh` directory.
## Quick start
```bash EXAMPLE: Deploy the site
npm run deploy --workspace @banes-lab/deploy
```
```bash EXAMPLE: Push the nginx configuration
npm run nginx --workspace @banes-lab/deploy -- push
```
<!-- /concern:install -->
<!-- concern:api -->
## API
The package exposes no public API.
<!-- /concern:api -->
<!-- concern:config -->
## Configuration
- `configuration/constants/deployment.constants.ts` — the remote site directory, backup retention, upload concurrency and the monitoring links.
- `configuration/constants/nginx.constants.ts` — the remote nginx locations and the test, reload and status commands.
- `configuration/constants/ssh.constants.ts` — the droplet user and the key file name.
<!-- /concern:config -->
<!-- concern:deps -->
## Dependencies
- `@banes-lab/build-scripts`
- `@banes-lab/web`
- `@govlab/content-fingerprint`
- `@ssot/paths`
- `@ssot/secrets`
<!-- /concern:deps -->
<!-- concern:ai-context -->
## AI context
- No step spells a location. Local paths resolve through `@ssot/paths`, and remote paths are constants in `configuration/constants/`.
- A step never talks to the network directly. It takes the `Shell` and reports through the `Journal`.
- Copy shown to the developer or posted to Discord lives in `configuration/strings/`.
<!-- /concern:ai-context -->
<!-- concern:domains -->
## Domains
This package serves these software domains, which `_manifest.json` declares in `domains` from the two-tier software-domain vocabulary (`meta → sub`):
- **communication** — notifications
- **devops** — deployment
<!-- /concern:domains -->
<!-- concern:quality-governance -->
## Quality governance
The canonical quality catalog resolves the quality concepts that govern this package. `_manifest.json` declares them in `governedBy`, and a lint package derives them from the concepts its own rules enforce. Each maps to the custom lint rules that enforce it:
- **separation-of-concerns** — _complexity_
- **type-safety** — _correctness_
<!-- /concern:quality-governance -->
<!-- concern:disposal -->
## Disposal
- Remove the member's workspace entry from the root `package.json`.
- Remove its governed-root entry from `containers` and `specialContainers` in `.govlab/shared/configs/taxonomy.config.ts`.
- Remove the `deploy`, `nginx`, `nginxSite`, `server` and `backups` keys from the `app` branch of `project.paths/paths.yaml`, and the deploy keys from the `@ssot/secrets` schema and the vault when no other member reads them.
- Delete the directory, reinstall, run the gate.
<!-- /concern:disposal -->
<!-- concern:metrics -->
---
experimental · 0 exports · 5 deps · 0 principles · 2 concepts
<!-- /concern:metrics -->