Know the artifact boundary
The backend image carries damd, dam-worker, damctl and the media tools they invoke. The SvelteKit frontend is built and deployed separately.
An image is not a production deployment. TLS termination, a reverse proxy, human authentication, durable search storage, configured virus scanning and an operational backup policy remain the operator’s responsibility.
docker build -t damrs:$(git rev-parse --short HEAD) .Deployment order
- 01
Migrate once
Run damctl migrate --all as a distinct job before new code serves. Do not let every replica race DDL at startup.
- 02
Roll the API
Start damd, verify liveness and readiness, then admit traffic.
- 03
Roll at least one worker
A healthy API with no worker accepts staging bytes but produces no usable asset.
- 04
Verify through the user path
Upload, derive, search and redeem one delivery URL. Probes alone cannot prove the workflow.
docker run --rm damrs:TAG damctl migrate --allConfiguration
Environment keys use DAMRS_ with a double underscore between sections.
| Key | Why production must set it |
|---|---|
| DAMRS_DATABASE__URL | The default points to local development |
| DAMRS_SERVER__URL_SIGNING_KEY | The public placeholder is rejected in production |
| DAMRS_STORAGE__BUCKET | The default is damrs-dev |
| DAMRS_SECURITY__CLAMD_ADDRESS | Scanning is off when this is absent |
| DAMRS_SERVER__PUBLIC_URL | Absolute links and integrations need the external origin |
docker run --rm damrs:TAG damctl configProbes and alerts
| Endpoint or metric | Meaning | Action |
|---|---|---|
| /health | Process liveness | Restart a dead or wedged process |
| /ready | PostgreSQL and object store reachable | Remove from traffic on 503 |
| /metrics | Prometheus output with bearer protection | 404 means disabled or wrong token |
| damrs_jobs{state="dead"} | Work exhausted its retries | Page an operator |
| 5xx request class | Handler or dependency failure | Correlate with structured logs |
Production checklist
- Terminate TLS and preserve the correct public hostname for signed object-store requests.
- Configure clamd and verify a clean, infected and unavailable-scanner path.
- Put a seven-day lifecycle safety net under each tenant staging prefix and abort orphaned multipart uploads.
- If using customer-managed KMS, configure both API and workers and enforce the key in the bucket policy.
- Run a logical backup and restore drill; a completed backup process alone is not recovery proof.
- Alert on dead jobs, not merely worker process health.