Operations¶
Cloud Run hosts Scribe's application and worker. Cloud SQL for MySQL, GCS, and Secret Manager own durable state. Production Cloud SQL uses regional HA; there is no VM, Cloud Compose, Traefik, or cloud Vault service. Availability settings alone do not establish a coordinated recovery objective; isolated restore evidence remains required.
Before deployment:
Every push to main requests a production apply. The repository workflow binds
the credentialed job to the production GitHub environment; an operator must
configure that environment with required reviewers before release so the job
waits for approval.
Use manual dispatch with mode=plan for a non-mutating plan.
Same-repository pull requests automatically request a preview deployment,
which binds credentialed work to the preview environment. Required reviewers
for that environment are likewise an externally configured release
prerequisite.
Forks receive secret-free CI only.
Start with configuration and deployment. Use the bounded production troubleshooting runbook for Cloud Run, Cloud SQL, credential, and readiness failures. Then ensure the backup and job recovery procedures have been exercised. Use observability for health, logs, metrics, audit metadata, queue state, and alert response.