Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -112,7 +112,7 @@ dotnet test Cluckwork.sln # 688 tests as of 2026-07; integratio
- **Migrate command + prod migration split (#263).** `dotnet Cluckwork.Api.dll migrate` applies migrations then exits — the pre-deploy-job entrypoint. Production sets `Database:MigrateOnStartup=false`, so the serving process never runs DDL; the guarantee is **ordering**, and `DatabaseReadyHealthCheck` is the backstop (`/health/ready` 503s while any migration is pending). → [`263-migrate-command.md`](docs/decisions/263-migrate-command.md)
- **Container health probe: the `healthcheck` verb (#266).** Dispatched before host build (no DI, DB or config), it GETs `/health/ready` over loopback and exits `0` only on a 2xx — the hardened image ships no curl/wget, and the probe must never report a false green. → [`266-container-health-probe.md`](docs/decisions/266-container-health-probe.md)
- **Container image hardening (#267).** Runtime stage runs non-root (`USER $APP_UID`), all three base images are digest-pinned, and Trivy fails the build on a fixable HIGH/CRITICAL. Keep the full glibc base per #264. → [`267-container-hardening.md`](docs/decisions/267-container-hardening.md)
- **Seed / simulation data is never boot-seeded (#280, #284, #279).** Run it explicitly against an already-base-seeded, non-Production database: `ASPNETCORE_ENVIRONMENT=Development dotnet Cluckwork.Api.dll seed --profile demo|simulation` (unset env → Production → blocked). The verb migrates, seeds, exits — authoritative and fail-loud. Both profiles require an Owner (#500). → [`280-seed-and-simulation.md`](docs/decisions/280-seed-and-simulation.md)
- **Seed / simulation data is never boot-seeded (#280, #284, #279).** Run it explicitly against an already-base-seeded, non-Production database: `ASPNETCORE_ENVIRONMENT=Development dotnet Cluckwork.Api.dll seed --profile demo|simulation` (unset env → Production → blocked). The verb migrates, seeds, exits — authoritative and fail-loud. Both profiles require an Owner (#500); `simulation` additionally requires `Simulation:CastPassword` and fails closed without it. → [`280-seed-and-simulation.md`](docs/decisions/280-seed-and-simulation.md) · [runbook](docs/runbooks/simulation-fixture-on-a-dev-database.md) for loading the simulation fixture into a local debug database
- **A write-contract change must update its non-CI callers (#394).** Coverage is not uniform: the seeders are covered only to the handler layer, so a **validator-only** tightening is invisible to every seeder test, and `tools/simulation/k6/` plus the Playwright specs are uncovered while a green baseline hides it. **Verify the request/status contract by reading the callers, not by running.** → [`394-write-contract-callers.md`](docs/decisions/394-write-contract-callers.md)
- **SPA E2E lives in `tools/simulation/ui/` (#277/#385).** Playwright drives the real built SPA over the same `seed --profile simulation` fixture k6 uses; `web/` stays Vitest. Three enforced rules, each of which has caught something: never hardcode a credential, never hardcode English, respect the farm clock. Anything reasoning about `inert` or the accessibility tree must go through CDP (`src/ax.ts`) — Playwright's own APIs do not model `inert` (#501). → [`277-spa-e2e.md`](docs/decisions/277-spa-e2e.md)
- **Production logs: compact JSON on stdout; base layer argument-free (#404).** The base `appsettings.json` Console entry carries `Name` only — a template left beside the formatter is **silently** bound instead of it. Trace fields differ by format (`@tr`/`@sp` in compact JSON, `{TraceId}`/`{SpanId}` in the Dev template), and compact JSON serializes **every** property, so anything pushed via `BeginScope`/`LogContext` reaches the collector. → [`404-production-logs.md`](docs/decisions/404-production-logs.md)
Expand Down
1 change: 1 addition & 0 deletions docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ Elsewhere in the repo:
| [`../README.md`](../README.md) | What Cluckwork is, and running it |
| [`../CONTRIBUTING.md`](../CONTRIBUTING.md) | Local development, tests, branches, commits |
| [`runbooks/aspire-local-development.md`](runbooks/aspire-local-development.md) | Local Aspire stack, persistence and safe reset |
| [`runbooks/simulation-fixture-on-a-dev-database.md`](runbooks/simulation-fixture-on-a-dev-database.md) | Bulk fixture data in a local debug database (Compose or Aspire) |
| [`../AGENTS.md`](../AGENTS.md) | The canonical rule set — every invariant, for humans and coding agents |
| [`../SECURITY.md`](../SECURITY.md) | Reporting a vulnerability; what CI enforces |
| [`../specs/product/`](../specs/product/) | Product & technical spec, phase plan, [glossary](../specs/product/GLOSSARY.md) |
Expand Down
1 change: 1 addition & 0 deletions docs/runbooks/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ an accessibility fix on real assistive tech.
| [First admin provisioning (`bootstrap-admin`)](first-admin-provisioning.md) | A fresh database has no Owner. |
| [New farm provisioning (`provision-account`)](provisioning-a-new-farm.md) | Add another farm and its first Owner. |
| [Break-glass account recovery (`recover-admin`)](break-glass-account-recovery.md) | An Owner exists but is locked out. |
| [Simulation fixture on a dev database](simulation-fixture-on-a-dev-database.md) | A local debug database needs far more rows than `seed --profile demo` provides. |
| [Backup & restore](backup-and-restore.md) | Disaster-recovery dump, and putting one back. |
| [Screen-reader verification](screen-reader-verification.md) | An announcement change needs real assistive-tech confirmation (jsdom cannot). |

Expand Down
Loading
Loading