Support ongoing Scope EC2 deployments after promotional credits - #284
Merged
Merged
Conversation
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The original deployment guard expires with promotional credits, preventing an ongoing Scope EC2 deployment. This adds a recurring monthly guard mode with a $48 planning ceiling and monthly budget, while preserving the existing expired-credit-window rejection. CPU-credit mode, AMI, destination account allowlist, and budget recipients can be supplied through production variables.
Plan and apply now receive the same backup/variable-usage reserve. The EC2 snapshot policy avoids duplicate Name tags, and new host bootstrap configures Docker log rotation and build-cache collection after the original host exhausted disk space.
Validation: Terraform formatting and validation passed; all three mocked guard tests passed; deployment YAML parsed successfully. The destination production foundation applied with the original AMI, t3a.medium, encrypted 80 GiB gp3, and Unlimited CPU-credit mode. GitHub OIDC plan run 37101975432 passed against the destination backend and proposed one in-place disk-settings update, with no creates, replacements, or deletions. Production apply continues to require main.
Scope is live in the new AWS account. The cold-copy comparison matched all 51 persistent paths, all 44 SQL tables and 2,842 rows matched, and all 39 archived S3 assets matched. The original 21 running services passed restart and functional checks. The original server is stopped, its disk and snapshots retained, and temporary migration sharing removed. The deployed application images were preserved without rebuilding application code.
Infrastructure and security checks pass. Four CI jobs fail in unchanged application files: Core's SQLCipher dependency advisory, Intel's missing _has_travel_party_brief method, Frontend's UpcomingDenverRoute test, and Admin formatting in src/index.css. These application failures are outside this infrastructure-only change.
The $48 AWS Budget is a planning threshold, not a hard billing cap. Email subscriptions remain empty until a recipient is selected.