platform/deployments
Bart Van Geyt 9f819df4d9 Phase 0: architecture docs, ADRs, and repo scaffold
Establish the design foundation for the heleosv2 multi-tenant hosting
platform before any implementation code:

- Monorepo skeleton: docs/, platform-infra/, site-templates/,
  deployments/, control-panel/ with orientation READMEs.
- docs/: roadmap index, architecture + threat model, naming conventions,
  site profiles, provisioning workflow, backup & DR runbook, repo/GitOps
  layout, and the approved architecture plan.
- docs/adr/: 9 ADRs recording the rationale for single-host Compose,
  Traefik edge, nginx+fpm split, shared MariaDB, ZFS-per-customer,
  decoupled backup streams, Forgejo, CLI-first, and SFTP-only.
- Secrets hygiene: .gitignore (only *.enc.* committed) and .gitattributes
  (LF for scripts/Dockerfiles/YAML run on the Linux host).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-07 12:26:00 +02:00
..
README.md Phase 0: architecture docs, ADRs, and repo scaffold 2026-07-07 12:26:00 +02:00

deployments

GitOps state — one directory per site, rendered by the provisioning CLI (Phase 4). Empty until the first site is provisioned.

Per-site layout (see ../docs/03-naming-conventions.md §7):

<slug>/
├── site.yaml            # declarative source of truth (slug, profile, domains)
├── docker-compose.yml   # rendered from a site-templates profile
├── .env.example         # non-secret references
└── secrets.enc.yaml     # SOPS/age-encrypted secrets (committed encrypted only)

Never commit plaintext secrets. Only *.enc.* / *.sops.* are allowed.