docs: mark production hardening complete

This commit is contained in:
Christian Krakau-Louis
2026-05-22 22:31:49 +02:00
parent 87ecdc1d9c
commit ef80619726
3 changed files with 21 additions and 16 deletions
+7 -4
View File
@@ -64,13 +64,10 @@ Delivered:
Quality bar:
- Importing the same mailbox twice does not change aggregate totals, parse failures are visible, and source totals are not overwritten by the latest result.
## Production Hardening
## Completed Milestone: Production Hardening
Objective: make self-hosted deployments safer.
Priority tasks:
- Use the production hardening docs in at least one real production upgrade and capture any gaps.
Delivered:
- Documented a 1Password secret-injection deployment flow for local, Docker Compose, and systemd deployments.
- Redacted secret-like values from mail-source diagnostics, stored import history, OAuth error logs, and validated admin auth contexts.
@@ -78,6 +75,12 @@ Delivered:
- Added database backup and restore guidance for SQLite and PostgreSQL deployments.
- Added a release checklist covering migrations, tests, smoke checks, release automation, and rollback readiness.
Quality bar:
- A self-hosted deployment can be configured without copying secrets into source-controlled files or chat logs.
Follow-up:
- Use the production hardening docs in at least one real production upgrade and capture any gaps.
## Later Milestones
- Notifications and alert rules with Apprise.