Deploy guide
Every merge to main ships to production, usually within four minutes. There is no release train and no deploy freeze.
Shipping a change
- Branch from
mainand open a pull request. - Get one approving review. For anything touching payments, two.
- Merge. The pipeline builds, runs the test suite and deploys.
git switch -c fix/invoice-rounding
git push -u origin fix/invoice-rounding
Risky changes go behind a flag first: see Feature flags.
Checking it worked
- Watch the deploy in
#ship-it. The bot posts when the new build is live. - Open the Service map dashboard and compare error rates for ten minutes.
- Queue depth should stay under 500. If it climbs, page whoever is on the On-call rota.
Rolling back
Revert the merge commit and push; the revert deploys like any other change. If the pipeline itself is broken:
php artisan down --secret="halyard-ops"
./deploy/rollback.sh --to=previous
php artisan up
Then write it up within two working days, see Incident reviews.