Files
headquarter/openspec/changes/deployment-config/specs/production-compose-stack/spec.md
T
alex 78aaddb2b5
CI / Web CI (push) Failing after 12s
CI / API CI (push) Failing after 1m1s
docs(openspec): add OpenSpec changes for FN-005, FN-006, FN-008, FN-009, FN-010
- Add frontend-foundation change (FN-005) with 46 tasks
- Add deployment-config change (FN-006) with 27 tasks
- Add runfusion-poc/opencode-poc change (FN-008) with 25 tasks
- Add config-secrets change (FN-009) with 31 tasks
- Add codeserver-spawn change (FN-010) with 38 tasks
- Include project specsheet and configuration
- Archive completed deployment-config change
2026-05-14 17:35:20 +02:00

1.1 KiB

ADDED Requirements

Requirement: Production stack includes all required services

The system SHALL provide a production Docker Compose stack with API, web, Traefik, and PostgreSQL.

Scenario: Stack services

  • WHEN the production stack is deployed
  • THEN the following services run: api, web, traefik, db
  • AND Traefik routes requests to the appropriate service
  • AND services communicate via isolated Docker networks

Scenario: Environment configuration

  • WHEN the stack starts
  • THEN it reads environment variables from .env
  • AND sensitive values are not hardcoded

Requirement: Production stack is secure by default

The system SHALL configure security headers and access controls in production.

Scenario: HTTPS only

  • WHEN the stack runs in production
  • THEN all traffic uses HTTPS
  • AND HTTP redirects to HTTPS

Scenario: Network isolation

  • WHEN the stack is deployed
  • THEN platform services and tool containers are on separate networks
  • AND tool containers cannot access the database directly