Skip to content

Phase 0 Runbook — Execute in Order

Status: Ready to execute (pending APPROVED) Operator: Thomas Scola Authority: Oracle IASC Migration Plan v1.0.0

Pre-flight Checks

# Verify oracle-vm runner is online
glab runner list --group blueflyio | grep oracle-vm

# Check K8s
ssh oracle "systemctl status k3s 2>/dev/null | head -5"

# Check unhealthy containers
ssh oracle "docker ps --filter 'health=unhealthy' --format '{{.Names}}'"

# Count secrets on disk (names only)
ssh oracle "grep -cE '^[A-Z_]+=' /opt/.env"

Task 0.1 — Unblock oracle-vm GitLab Runner (MR !405)

glab mr view 405
# If runner is paused: go to Settings > CI/CD > Runners > oracle-vm > Resume
# If pipeline blocked: re-run failed jobs from GitLab UI

Task 0.2 — Fix K8s

ssh oracle "systemctl status k3s"
ssh oracle "journalctl -u k3s -n 100"
# If stopped:
ssh oracle "sudo systemctl start k3s"
ssh oracle "kubectl get nodes"

Task 0.3 — Fix Unhealthy Containers

# contractplane-gateway
ssh oracle "docker logs contractplane-gateway --tail 50"
ssh oracle "docker exec contractplane-gateway env | grep -v PASSWORD | grep -v SECRET | grep -v TOKEN"

# litellm-proxy
ssh oracle "docker logs litellm-proxy --tail 50"

# dragonfly COMPLIANCE_ENGINE_URL fix
ssh oracle "docker exec dragonfly-core env | grep COMPLIANCE"
# Must be: COMPLIANCE_ENGINE_URL=http://compliance-engine:3010
# If wrong: update docker-compose and restart

Task 0.4 — Move Secrets Off Disk

# Audit env var names (NAMES ONLY — never print values)
ssh oracle "grep -E '^[A-Z_]+=' /opt/.env | cut -d= -f1 | sort"

# For each key, create GitLab CI Variable:
# gitlab.com/groups/blueflyio/-/settings/ci_cd > Variables > Add

# After ALL variables are in GitLab CI:
# Update all docker-compose files to remove: env_file: /opt/.env
# Test one profile at a time before removing /opt/.env

Task 0.5 — Enable Terraform CI

# Push iac/ changes to MR:
cd iac/
git checkout -b feature/phase-0-iac-baseline
git add .
git commit -m "feat(iac): Phase 0 — enable Terraform CI with GitLab HTTP backend"
git push origin feature/phase-0-iac-baseline
# Create MR in GitLab UI → targeting main
# tf-plan jobs will run automatically on MR

Task 0.6 — Import Live CF/GitLab/OCI State

cd iac/
npm ci

# Import (run with 1Password):
op run --env-file=.op-env --account blueflyiollc -- ./scripts/import-state.sh

# Review generated files:
git diff terraform/cloudflare/imported_tunnels.tf
git diff terraform/cloudflare/imported_dns.tf

# Commit and push — CI will run terraform plan
git add terraform/
git commit -m "feat(terraform): import live CF/GitLab state via cf-terraforming"
git push

Verification Gates

# Runner online
glab runner list --group blueflyio | grep "oracle-vm.*online"

# K8s healthy
ssh oracle "kubectl get nodes | grep Ready"

# No unhealthy containers
ssh oracle "docker ps --filter 'health=unhealthy' --format '{{.Names}}'" | wc -l
# Must be 0

# Terraform plan clean (check MR pipeline — tf-plan jobs green)

# Secrets off disk (after Phase 0 completes)
ssh oracle "test ! -f /opt/.env && echo 'OK' || echo 'FAIL: .env still exists'"

Phase 0 Complete When

  • [ ] oracle-vm runner online + processing jobs
  • [ ] K8s running (kubectl get nodes returns Ready)
  • [ ] 0 unhealthy containers
  • [ ] terraform/cloudflare tf-plan job green on MR
  • [ ] All secrets in GitLab CI Variables
  • [ ] /opt/.env removed from Oracle

APPROVED: Phase 1 → only after all checkboxes above are complete.