Files
Zumri-Backend/Documentation/PRODUCTION_RUNBOOK.md
Sathira Sri Sathara 5158c52db5
CI / test (push) Successful in 10m56s
CI / test (pull_request) Successful in 11m1s
feat: Add Phase 11 analytics and production readiness features
- Introduced new endpoints for account overview, analytics, and metrics.
- Implemented authorization matrix and backup/restore documentation.
- Added smoke test script and updated package dependencies.
- Created detailed production checklist and runbook for deployment.
- Established cron operations and notification event matrix documentation.
- Enhanced security and validation audits for analytics and metrics services.
- Added unit tests for analytics and metrics functionalities.
2026-09-16 10:59:19 +05:30

19 lines
1.7 KiB
Markdown

# Production Runbook
## Deployment
Provision MySQL 8.4, authenticated Redis, private encrypted S3-compatible storage, SMTP, payment-provider credentials, TLS reverse proxy, API replicas, independent worker replicas, and exactly one cron scheduler. Inject secrets; never bake them into images.
1. Validate `.env` with `node server.js` in a sealed staging environment.
2. Take database/object-storage backups and run legacy prechecks.
3. Run `npx sequelize-cli db:migrate` against staging first; verify `SequelizeMeta`, constraints, indexes and counts.
4. Seed required roles/permissions, document types, shipping/configuration, SLA/help data using approved idempotent procedures.
5. Build the Node 22 image, scan it, deploy workers, API, and one `RUN_CRON=true` scheduler.
6. Configure Nginx/TLS/proxy trust; verify `/health/live` and `/health/ready`.
7. Run `npm run smoke`; run the staging-only commerce sequence with designated test identities/provider sandbox.
8. Monitor 5xx rate, readiness, DB/Redis, queue failures/backlog, webhook failures, cron failures, latency, memory and disk/log pressure.
Commands: API `npm start`; worker `node app/workers/index.js`; syntax `npm run check:syntax`; tests `npm test -- --runInBand`; dependencies `npm ls --depth=0`; audit `npm audit`; smoke `npm run smoke`; OpenAPI `npm run validate:openapi`.
Incident basics: stop hazardous writers, preserve logs/request IDs/provider event IDs, assess customer impact, rotate exposed credentials, prefer forward fixes, reconcile payments/inventory/ledgers, and communicate from verified database/provider truth. Roll back application images only when schema compatibility is proven; restore data only through the approved recovery procedure.