Add deployment/operations guide
parent
410a75af3d
commit
c56e1b5b3a
1 changed files with 115 additions and 0 deletions
115
Deployment.md
Normal file
115
Deployment.md
Normal file
|
|
@ -0,0 +1,115 @@
|
|||
# Deployment
|
||||
|
||||
Running Echo in production. Echo is the account and channel **authority** for a
|
||||
network, so the two things that matter most are durability and backups; both are
|
||||
covered below.
|
||||
|
||||
## Build
|
||||
|
||||
```sh
|
||||
git clone https://git.devtronic.pro/fedserv/echo.git
|
||||
cd echo
|
||||
cargo build --release # protoc is vendored; no system protobuf needed
|
||||
```
|
||||
|
||||
The binary is `target/release/echo`.
|
||||
|
||||
## Install
|
||||
|
||||
Run Echo as a dedicated unprivileged user, with `config.toml` and the event log
|
||||
in one data directory.
|
||||
|
||||
```sh
|
||||
useradd --system --home-dir /opt/echo --shell /usr/sbin/nologin echo
|
||||
install -d -o echo -g echo /opt/echo
|
||||
install -o echo -g echo target/release/echo /opt/echo/echo
|
||||
install -o echo -g echo config.example.toml /opt/echo/config.toml # then edit it
|
||||
install -m0644 scripts/echo.service /etc/systemd/system/echo.service # edit paths/User
|
||||
systemctl daemon-reload
|
||||
systemctl enable --now echo
|
||||
```
|
||||
|
||||
`scripts/echo.service` is a hardened unit (no new privileges, read-only system,
|
||||
private tmp, restart on failure). Adjust `ProtectSystem=strict` for a read-only
|
||||
root if you use a network mail relay rather than a local sendmail.
|
||||
|
||||
## Configure the ircd link
|
||||
|
||||
On the InspIRCd uplink, add a `<link>` block matching `[uplink]` / `[server]` in
|
||||
`config.toml` (name, SID, password, port). Echo links as its `[server] name`.
|
||||
The full `config.toml` reference is on the [Configuration](Configuration) page.
|
||||
|
||||
## Durability
|
||||
|
||||
Every committed change (registration, password, access, ban, …) is `fsync`'d to
|
||||
the event log before the command reports success, so a crash or power loss can
|
||||
not lose it. Compaction rewrites the log to a temp file, `fsync`s, and renames
|
||||
atomically, so a crash during compaction leaves the previous log intact. The log
|
||||
tolerates a truncated final line on load (it is skipped), which is what makes a
|
||||
plain file copy a safe backup.
|
||||
|
||||
## Back up
|
||||
|
||||
The event log is the whole database. Back it up regularly with
|
||||
`scripts/backup.sh` (gzips a timestamped snapshot and prunes old ones):
|
||||
|
||||
```ini
|
||||
# /etc/systemd/system/echo-backup.service
|
||||
[Service]
|
||||
Type=oneshot
|
||||
User=echo
|
||||
Environment=ECHO_DATA_DIR=/opt/echo ECHO_BACKUP_DIR=/opt/echo/backups
|
||||
ExecStart=/opt/echo/scripts/backup.sh
|
||||
```
|
||||
|
||||
```ini
|
||||
# /etc/systemd/system/echo-backup.timer
|
||||
[Timer]
|
||||
OnCalendar=hourly
|
||||
Persistent=true
|
||||
[Install]
|
||||
WantedBy=timers.target
|
||||
```
|
||||
|
||||
`systemctl enable --now echo-backup.timer`. Copy backups off-box as well.
|
||||
|
||||
## Restore
|
||||
|
||||
```sh
|
||||
systemctl stop echo
|
||||
gunzip -c /opt/echo/backups/echo.db.<stamp>.jsonl.gz > /opt/echo/echo.db.jsonl
|
||||
systemctl start echo
|
||||
```
|
||||
|
||||
## Upgrade
|
||||
|
||||
```sh
|
||||
git pull
|
||||
cargo build --release
|
||||
install -o echo -g echo target/release/echo /opt/echo/echo
|
||||
systemctl restart echo
|
||||
```
|
||||
|
||||
The on-disk format is an append-only event log; new event kinds are additive and
|
||||
old logs replay unchanged. Take a backup before upgrading regardless.
|
||||
|
||||
## Monitor
|
||||
|
||||
- `systemctl status echo` and `journalctl -u echo -f` (the log records write
|
||||
failures, compaction, and account-store load at startup).
|
||||
- Optional `[jsonrpc]` HTTP endpoint exposes stats for a status page.
|
||||
- Systemd `Restart=on-failure` brings it back after a crash.
|
||||
|
||||
## Federation (multiple nodes)
|
||||
|
||||
Give each node a `[gossip]` bind + shared secret and a `[[peer]]` for the others
|
||||
(mutually-authenticated TLS via `[gossip.tls]`). Account identity replicates to
|
||||
every node; channel state stays local to the node that owns it. See
|
||||
[Federation](Federation). Start with a single node until you are comfortable.
|
||||
|
||||
## Honest caveats
|
||||
|
||||
Echo is pre-1.0. It is memory-safe, panic-free on the wire, and durable, but it
|
||||
has not yet accumulated a long production track record. Run it on your own
|
||||
network first, keep backups, and watch the logs. Declare a license before anyone
|
||||
else runs it.
|
||||
Loading…
Add table
Add a link
Reference in a new issue