-
Notifications
You must be signed in to change notification settings - Fork 0
Azure Platform
Steven Tomlinson edited this page Jul 31, 2026
·
1 revision
Infrastructure and deployment automation for staging environments are defined in Azure Bicep and scripts.
- Web app:
https://staging.nodezero.social - Solid server:
https://solid.nodezero.social/ - Relay service:
https://nodezero-social-staging-testnet-relay.azurewebsites.net - Provisioner service:
https://nodezero-social-staging-testnet-provisioner.azurewebsites.net
infrastructure/azure/main.bicepinfrastructure/azure/main.parameters.staging-testnet.jsonscripts/azure/deploy.sh.github/workflows/staging-deploy.yml
- Mandatory parameter file enforcement.
- Environment mismatch rejection.
- What-if preflight before deployment.
- Blocking onboarding/authentication E2E gate (
pnpm qa:smoke:auth) with one retry for transient IdP/OIDC timing churn. - Latest staging deploy evidence: workflow run
#46completed with auth gate success (step #28).
Rollout order:
- Build hardened Solid runtime image.
- Deploy staging in
shadowmode. - Review and triage deny candidates.
- Remediate legacy malformed ACL data.
- Promote staging to
enforcemode.
Commands:
bash ./scripts/azure/build-solid-themed-image.shbash ./scripts/azure/deploy-solid-server.shcorepack pnpm policy:validate-env
Identity endpoint continuity check (required after every Solid deploy):
- Confirm the Solid custom hostname remains bound to ACA ingress.
- Validate OIDC discovery over the custom domain returns HTTP 200.
Commands:
az containerapp hostname list --resource-group rg-nodezero-social-staging-testnet --name nz-staging-testnet-solid -o jsoncurl -i https://solid.nodezero.social/.well-known/openid-configuration
Failure signature:
- Browser sign-in/onboarding shows
Failed to fetch. - Browser console/network shows
ERR_CONNECTION_RESETforhttps://solid.nodezero.social/.well-known/openid-configuration.
Operational safeguard:
-
scripts/azure/deploy-solid-server.shnow enforces managed-certificate + hostname binding forcssCustomDomainafter each deployment so the custom domain does not silently drop. -
scripts/azure/deploy-solid-server.shhard-fails deployment whencssCustomDomainresolves tosolid.nodezero.socialand the effectivecssImageis not the NodeZero themed image family (/solid/community-server-nodezero-auth-ui:<tag>).
Required evidence:
- Image reference and build timestamp.
- Azure deployment operation ID(s).
- Shadow start timestamp.
- Enforce cutover timestamp.
Rollback:
- Switch policy mode back to
shadow. - Keep telemetry capture enabled.
- Record incident with violating
ruleIdvalues and samplecorrelationIds.
docs/staging-deployment-blueprint.mddocs/environment-isolation-matrix.mddocs/staging-readiness-and-agent-plan.mddocs/staging-runtime-implementation-roadmap.mddocs/testnet-azure-release-requirements.md