Know the artifact boundary

The backend image carries damd, dam-worker, damctl and the media tools they invoke. The SvelteKit frontend is built and deployed separately.

An image is not a production deployment. TLS termination, a reverse proxy, human authentication, durable search storage, configured virus scanning and an operational backup policy remain the operator’s responsibility.

Build a traceable image shell
docker build -t damrs:$(git rev-parse --short HEAD) .

Deployment order

  1. 01

    Migrate once

    Run damctl migrate --all as a distinct job before new code serves. Do not let every replica race DDL at startup.

  2. 02

    Roll the API

    Start damd, verify liveness and readiness, then admit traffic.

  3. 03

    Roll at least one worker

    A healthy API with no worker accepts staging bytes but produces no usable asset.

  4. 04

    Verify through the user path

    Upload, derive, search and redeem one delivery URL. Probes alone cannot prove the workflow.

Migration job shell
docker run --rm damrs:TAG damctl migrate --all

Configuration

Environment keys use DAMRS_ with a double underscore between sections.

KeyWhy production must set it
DAMRS_DATABASE__URLThe default points to local development
DAMRS_SERVER__URL_SIGNING_KEYThe public placeholder is rejected in production
DAMRS_STORAGE__BUCKETThe default is damrs-dev
DAMRS_SECURITY__CLAMD_ADDRESSScanning is off when this is absent
DAMRS_SERVER__PUBLIC_URLAbsolute links and integrations need the external origin
Inspect the resolved configuration shell
docker run --rm damrs:TAG damctl config

Probes and alerts

Endpoint or metricMeaningAction
/healthProcess livenessRestart a dead or wedged process
/readyPostgreSQL and object store reachableRemove from traffic on 503
/metricsPrometheus output with bearer protection404 means disabled or wrong token
damrs_jobs{state="dead"}Work exhausted its retriesPage an operator
5xx request classHandler or dependency failureCorrelate with structured logs

Production checklist

  • Terminate TLS and preserve the correct public hostname for signed object-store requests.
  • Configure clamd and verify a clean, infected and unavailable-scanner path.
  • Put a seven-day lifecycle safety net under each tenant staging prefix and abort orphaned multipart uploads.
  • If using customer-managed KMS, configure both API and workers and enforce the key in the bucket policy.
  • Run a logical backup and restore drill; a completed backup process alone is not recovery proof.
  • Alert on dead jobs, not merely worker process health.