Skip to content

Deploy Centrifugo securely on Fly.io - #52

Open
fkesheh wants to merge 2 commits into
mainfrom
feat/centrifugo-fly-rollout
Open

Deploy Centrifugo securely on Fly.io#52
fkesheh wants to merge 2 commits into
mainfrom
feat/centrifugo-fly-rollout

Conversation

@fkesheh

@fkesheh fkesheh commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add a digest-pinned, single-Machine Fly deployment for Centrifugo in gru
  • disable the Centrifugo admin and HTTP API, restrict origins, and keep health private
  • add validation-only CI plus an explicitly approved manual Fly deployment
  • close production registration by default for the current single-user deployment
  • harden the legacy AWS rollback workflow and document rollout, rollback, and security findings

Validation

  • Centrifugo checkconfig
  • Fly config validation
  • container build and WebSocket origin smoke tests
  • public admin/API/health route checks
  • GitHub Actions actionlint
  • 118 Vitest tests
  • TypeScript check
  • production Next.js build
  • secret-pattern scan

Rollout note

This PR prepares the deployment but does not create the Fly app, import its HMAC secret, provision certificates, or change DNS. Follow docs/centrifugo-fly-rollout.md after merge.

@vercel

vercel Bot commented Aug 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
ftown Ready Ready Preview Aug 3, 2026 9:12pm

Request Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant