Skip to content

feat(publish): add protected R2 staging rehearsal#9

Merged
jmgilman merged 4 commits into
mainfrom
feat/phase4-staging
Jul 18, 2026
Merged

feat(publish): add protected R2 staging rehearsal#9
jmgilman merged 4 commits into
mainfrom
feat/phase4-staging

Conversation

@jmgilman

@jmgilman jmgilman commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add a prefix-confined R2 adapter that applies the existing content/index/activation/state/delete plan and rehydrates for verification
  • add an opt-in protected staging job using the signing-only GPG subkey and a one-year _staging/ R2 credential
  • prove remote no-op behavior and clean installs through pkgs.meigma.dev on Debian, Ubuntu, and Fedora
  • keep production, GitHub Release discovery, cache rules, and the explicit disaster-recovery drill outside this slice

Verification

  • mise exec -- moon run root:check --summary minimal
  • local real staging rehearsal: ordered actions, verified repeat no-op, clean installs on Debian 13, Ubuntu 26.04, and Fedora 44
  • hosted protected rehearsal with the replacement credential: https://github.com/meigma/packages/actions/runs/29658613934

External prerequisites already provisioned

  • R2 bucket and active custom domain with r2.dev disabled
  • GitHub staging environment restricted to main and this review branch
  • GPG primary backup and CI signing subkey stored in the 1Password Homelab vault; only the signing subkey is in GitHub
  • locally signed R2 credential confined to meigma-packages/_staging/, expiring 2027-07-18

Remaining Phase 4 work

  • install the planned cache rules once a Cloudflare token with Cache Rules Edit is available
  • run the explicit empty-prefix recovery rehearsal
  • consider automated credential renewal or an OIDC broker before July 2027

@jmgilman
jmgilman merged commit f2e361e into main Jul 18, 2026
4 checks passed
@jmgilman
jmgilman deleted the feat/phase4-staging branch July 18, 2026 21:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant