deploy/CICD.md documents which git push/tag triggers which pipeline
steps; deploy/AUTH.md documents the Authelia OIDC integration contract
with a sequence diagram of the login flow. Cross-link from README and
INSTALL. The 0.1.0 release also ships the previously-committed security
hardening (server-side session expiry + nosniff on served files).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replace the workflow_dispatch deploy with an Activate step in build.yml
that runs only for X.Y.Z tags: it repoints the ~/hsa-app/hsa symlink and
restarts the user service. Pre-release tags (e.g. 0.0.0a2) are still
built, tested, and staged into releases/ but not activated. Remove
deploy.yml and update INSTALL.md accordingly.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
build.yml now only stages the binary into ~/hsa-app/releases on tag
(no symlink swap or restart). Activation is a separate workflow_dispatch
workflow (deploy.yml) the user triggers from the Forgejo Actions tab,
passing the tag to point the symlink at and restart. Update INSTALL.md
to describe the stage/activate split.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
On tag push, scp the binary to ~/hsa-app/releases/hsa-app-V<tag>/hsa,
repoint the ~/hsa-app/hsa symlink, and restart the user systemd
service. Add deploy/hsa_app.service unit and deploy/INSTALL.md with
host layout, one-time install, deploy, and rollback steps.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>