conjurer: deploy bot on its own [deploy]-gated image channel

The production bot now tracks conjurer-bot-deploy instead of conjurer-bot,
so it updates only when the conjurer CI promotes a build (commit message
contains [deploy]). Adds the image-updater 'deploy-bot' alias and the
kustomization images entry for it; DEPLOY-BOT.md documents the channel and
the one-time bootstrap. Test bot + librarian keep tracking every build.

Pairs with conjurer#20 (the CI promotion step).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-08-03 20:12:29 +02:00
parent e60473318d
commit fd7e5c81b0
4 changed files with 36 additions and 3 deletions
+23
View File
@@ -12,6 +12,29 @@ namespace, sharing the same librarian / musician / radio and the shared
Files: `deploy-bot.yaml` (Deployment + Service), `deploy-bot-backup.yaml`
(daily backup CronJob). Both are wired into `kustomization.yaml`.
## Update channel — only on `[deploy]`
Unlike the test bot (which tracks every build), the production bot updates **only
when you promote a version**. It runs a **separate image**,
`conjurer-bot-deploy`, which the conjurer CI tags **only when the commit message
contains `[deploy]`** (it re-tags the already-built `conjurer-bot:<sha>` — same
bytes). The image-updater's `deploy-bot` alias then bumps this bot's tag.
So: normal commits update the test bot + librarian; a commit with `[deploy]` in
its message is the one that also rolls the production bot.
**Bootstrap (first run):** `conjurer-bot-deploy` doesn't exist until the first
`[deploy]` build. Either land one commit with `[deploy]` in the message, or seed
it once by hand:
```bash
docker pull gitea.czernobog.pl/gitea/conjurer-bot:ac16b77f
docker tag gitea.czernobog.pl/gitea/conjurer-bot:ac16b77f \
gitea.czernobog.pl/gitea/conjurer-bot-deploy:ac16b77f
docker push gitea.czernobog.pl/gitea/conjurer-bot-deploy:ac16b77f
```
(match the tag in `kustomization.yaml`). Note the librarian is shared, so it
still tracks latest — mind large bot⇄librarian version skews.
## One-time setup
1. **Secret** — already exists as `deploy-conjurer-netrc` (a netrc carrying the