Add the Render → Cloud Run cutover runbook - #266
Conversation
Pre-flight checks, the ordered cutover steps with a check for each, rollback before and after Render is suspended, and follow-ups. Cloud Run only gets the Stellar key after Render is suspended, so two escrow keepers never run at once; the Stripe endpoint is edited rather than recreated so its signing secret stays the same. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
DevAsign Code Review
📝 Nitpicks (1)
✅ Merge score: 98/100
9 of 9 acceptance criteria met.
The PR adds a single documentation file, backend/deploy/gcp/CUTOVER.md, containing the Render to Cloud Run cutover runbook.
Tests: 7 passed, 2 unverifiable — see the "Tests by DevAsign" comment.
|
|
||
| Run everything from the checkout that holds the gitignored files the import script | ||
| generated (`backend/deploy/gcp/.env.cloudrun.yaml` and `.env.cloudrun.secrets`). Today that's | ||
| `/Users/ram/Documents/devasign-app/.claude/worktrees/app-navigation-sidebar-redesign-3dc50c`. |
There was a problem hiding this comment.
📝 Note (nit) — This hardcodes a personal absolute filesystem path (/Users/ram/...worktrees/...). It is brittle (wo…
This hardcodes a personal absolute filesystem path (/Users/ram/...worktrees/...). It is brittle (worktree names change, it's specific to one machine) and leaks a local directory layout into a committed runbook. Consider phrasing it as 'the worktree/checkout that generated the gitignored files' without the machine-specific path.
Tests by DevAsign✅ 7 of 9 criteria verified by tests, 2 unverifiable. Each verdict below links to its evidence. 1 — A new documentation file is added at backend/deploy/gcp/CUTOVER.md. (pass)Verdict: pass Test confirms backend/deploy/gcp/CUTOVER.md exists with a top-level cutover runbook heading. Test: 2 — The runbook documents pre-flight checks to be done the day before, including checking whether the project allows a public Cloud Run service (with --no-invoker-iam-check as fallback), adding API_ORIGIN to the env file, deciding whether un-deployed main changes go to Render first, pre-registering extra callback URLs, and checking dashboard access. (pass)Verdict: pass All five pre-flight subtests pass, covering public Cloud Run check with fallback, API_ORIGIN, Render decision, callback URLs, and dashboard access. Test: 3 — The runbook lays out the cutover as an ordered sequence of steps, each with a corresponding check. (unverifiable)Verdict: unverifiable The numbered-and-ordered subtests pass; the failing subtest demands the literal token 'Verify' in every step body, which is stricter than the criterion's 'a corresponding check' and does not build the case the criterion names. Test: 4 — The cutover steps direct creating the prod Cloud Run service WITHOUT STELLAR_ADMIN_SECRET first, and adding the Stellar key to Cloud Run only after Render is suspended, so that two escrow keepers never run against real escrow funds at once. (pass)Verdict: pass Subtests confirm prod Cloud Run created without STELLAR_ADMIN_SECRET, Render suspension precedes and gates the Stellar handoff, and the two-keepers rationale is stated. Test: 5 — The runbook instructs editing the existing Stripe endpoint rather than recreating it, so the signing secret stays the same and webhooks are not rejected. (pass)Verdict: pass Subtests confirm the runbook instructs editing the existing Stripe endpoint and explains a new endpoint would get a new signing secret. Test: 6 — The runbook documents a rollback procedure for both cutover stages, in which after Render is suspended Cloud Run's Stellar key is removed before Render is resumed. (pass)Verdict: pass Subtests confirm rollback procedures for both stages, with the after-step-6 rollback removing Cloud Run's Stellar secret before resuming Render. Test: 7 — The runbook documents follow-ups: an uptime check on writeThrough:"stalled", cleanup of docs still using the Render URL, and an optional custom domain. (pass)Verdict: pass Subtests confirm follow-ups documenting the writeThrough:stalled uptime check, Render-URL doc cleanup, and optional custom domain. Test: 8 — The runbook notes that all users are signed out once because the session cookie belongs to the old host, and instructs warning users. (pass)Verdict: pass Subtests confirm the runbook explains the sign-out is caused by the session cookie belonging to the Render host and instructs warning users beforehand. Test: 9 — The change is documentation-only and does not alter Render's runtime or the deployment behavior of existing triggers (the devasign-api-main trigger ignores backend/deploy/**). (unverifiable)Verdict: unverifiable The test itself asserts the diff-scope/footprint claim cannot be established from a single checkout, so it does not exercise whether the change is documentation-only or leaves triggers unaffected. Test: |
Adds
backend/deploy/gcp/CUTOVER.md, the runbook for moving the production API from Render to thedevasign-apiCloud Run service. It's documentation only: thedevasign-api-maintrigger ignoresbackend/deploy/**, and Render's runtime is unaffected.What's in it
allUsers, and--no-invoker-iam-checkis the fallback.API_ORIGINto the env file and confirm the newest image built.mainchanges (currently Let the criteria review read the repo outside the diff #264) go to Render first.STELLAR_ADMIN_SECRETand check it.VITE_API_BASEon both Vercel apps and redeploy.v1tag._DEPLOY=true.writeThrough:"stalled", cleanup of docs that still use the Render URL, and an optional custom domain.Design choices
Checked
STELLAR_ADMIN_SECRET.https://devasign-sponsor.vercel.appagainst the live Render API (same code).gcloud builds triggers update github … --update-substitutionsandgcloud run deploy --[no-]invoker-iam-checkexist in the installed gcloud (565.0.0).rowsLoadedAtBoot11671, booted 2026-09-17,stellar: live.🤖 Generated with Claude Code