Register scha for deploy on all webservers (scha#19 Part B) (#3)
Sync runner checkout / sync (push) Successful in 6s

## Summary
- Register `scha` in `app_catalog` and `host_apps` on adama, roslin, and ai-server-4080 (prod port **8002**; beta **8012** reserved).
- Update `IMPLEMENTATION.md` ports, apps, Postgres, and NPM tables so every app lists beta + prod.
- Include `scha` in `deploy.sh` help.

Part A (dockerize / CI in the `scha` repo) is tracked separately in [scha#19](ai_ml_operations/scha#19).

## Test plan
- [ ] Confirm inventory YAML loads: `ansible-inventory --list` shows `scha` under each host
- [ ] After Part A merges + `~/Documents/secrets/scha/scha_prod.env` exists: dry-run `./scripts/deploy.sh --app scha --env prod --check`
- [ ] Create DB `scha` on shared Postgres (`10.0.0.230`) and point NPM at `adama:8002` + `roslin:8002` (+ optional `ai-server-4080:8002`)

Reviewed-on: #3
This commit was merged in pull request #3.
This commit is contained in:
2026-07-14 03:06:46 -07:00
parent d9d2dc246a
commit 04ccbecbd7
6 changed files with 43 additions and 15 deletions
+30 -14
View File
@@ -187,15 +187,16 @@ After Docker install, re-SSH so the `docker` group membership takes effect.
### Apps
| App | Type | Hosts | Notes |
|-----|------|-------|-------|
| `company_site` | django (docker) | adama + roslin | active/active behind NPM |
| `dta_service` | django (docker) | adama + roslin + ai-server-4080 | active/active behind NPM |
| `dta_webapp` | node/vite static | adama + roslin | active/active; built to `/var/www/<env>_dta_webapp`, served by web-static nginx |
| App | Type | Hosts | Envs | Notes |
|-----|------|-------|------|-------|
| `company_site` | django (docker) | adama + roslin (+ ai-server-4080) | prod | active/active behind NPM; beta port reserved |
| `dta_service` | django (docker) | adama + roslin + ai-server-4080 | beta + prod | active/active behind NPM |
| `dta_webapp` | node/vite static | adama + roslin (+ ai-server-4080) | beta + prod | active/active; built to `/var/www/<env>_dta_webapp`, served by web-static nginx |
| `scha` | django (docker) | adama + roslin + ai-server-4080 | prod | active/active behind NPM; beta port reserved |
Both environments (`beta`, `prod`) are deployed. Django apps use a **shared external
Postgres** (via `DATABASE_URL` in each host's env file) so active/active replicas
share one database.
Django apps use a **shared external Postgres** (via `DATABASE_URL` in each host's
env file) so active/active replicas share one database. Beta and prod never share
a DB.
### Data model
@@ -206,11 +207,16 @@ share one database.
### Ports
| App | beta | prod |
|-----|------|------|
| company_site | 8010 | 8000 |
| dta_service | 8011 | 8001 |
| dta_webapp (nginx) | 8081 | 8080 |
Reserved host ports for NPM upstreams. Ports must match across every host that
serves the same app+env. Rows marked *not deployed* keep the port free for a
future beta replica.
| App | beta | prod | Deployed on |
|-----|------|------|-------------|
| company_site | 8010 (*not deployed*) | 8000 | adama, roslin, ai-server-4080 |
| dta_service | 8011 | 8001 | adama, roslin, ai-server-4080 |
| scha | 8012 (*not deployed*) | 8002 | adama, roslin, ai-server-4080 |
| dta_webapp (nginx) | 8081 | 8080 | adama, roslin, ai-server-4080 |
### Flow
@@ -243,6 +249,13 @@ point each domain at the backend(s):
adama+roslin you need the **Advanced** tab with a custom `upstream {}` block
(or a real LB). Confirm this before relying on active/active.
| App | Domains | Backends |
|-----|---------|----------|
| company_site | aimloperations.com (+ www) | `adama:8000` + `roslin:8000` |
| dta_service | (see DTA NPM hosts) | `adama:8001` / `8011` + same on roslin / ai-server-4080 |
| dta_webapp | (see DTA NPM hosts) | `adama:8080` / `8081` + same on roslin |
| scha | `schawheaton.aimloperations.com`, `schawheaton.com` (+ www) | `adama:8002` + `roslin:8002` (+ `ai-server-4080:8002`) |
### Required changes IN each app repo (owned separately)
- [ ] `docker-compose.prod.yml`: drop the bundled `db` service; `web` reads
@@ -266,8 +279,10 @@ do not).
| company_site | beta | `company_site_beta` | `postgres://westfarn:<pw>@10.0.0.230:5432/company_site_beta` |
| dta_service | prod | `dta_service` | `postgres://westfarn:<pw>@10.0.0.230:5432/dta_service` |
| dta_service | beta | `dta_service_beta` | `postgres://westfarn:<pw>@10.0.0.230:5432/dta_service_beta` |
| scha | prod | `scha` | `postgres://westfarn:<pw>@10.0.0.230:5432/scha` |
| scha | beta | `scha_beta` | `postgres://westfarn:<pw>@10.0.0.230:5432/scha_beta` |
Server prereqs on 10.0.0.230: create the 4 DBs + grant `westfarn`;
Server prereqs on 10.0.0.230: create each DB + grant `westfarn`;
`listen_addresses` covers LAN; `pg_hba.conf` allows `10.0.0.0/24`; firewall opens
5432 to `10.0.0.0/24` only.
@@ -340,6 +355,7 @@ Store vault password for CI in a file readable only by the Act runner (e.g. `~/.
| 8a | Auto-sync runner checkout on `master` (`.gitea/workflows/sync-checkout.yml`) | Done |
| 9 | Stub `deploy-apps.yml` + update `company_site` workflow | Future |
| 10 | Dockerize `company_site` | Future (separate ticket) |
| 10a | Register + deploy `scha` (all webservers, port 8002) | In progress ([scha#19](https://git.aimloperations.com/ai_ml_operations/scha/issues/19)) |
| 11 | Gitea container registry (optional) | Future |
## Open Decisions