Phase 0 Runbook — Execute in Order¶
Status: Ready to execute (pending APPROVED) Operator: Thomas Scola Authority: Oracle IASC Migration Plan v1.0.0
Pre-flight Checks¶
# Verify oracle-vm runner is online
glab runner list --group blueflyio | grep oracle-vm
# Check K8s
ssh oracle "systemctl status k3s 2>/dev/null | head -5"
# Check unhealthy containers
ssh oracle "docker ps --filter 'health=unhealthy' --format '{{.Names}}'"
# Count secrets on disk (names only)
ssh oracle "grep -cE '^[A-Z_]+=' /opt/.env"
Task 0.1 — Unblock oracle-vm GitLab Runner (MR !405)¶
glab mr view 405
# If runner is paused: go to Settings > CI/CD > Runners > oracle-vm > Resume
# If pipeline blocked: re-run failed jobs from GitLab UI
Task 0.2 — Fix K8s¶
ssh oracle "systemctl status k3s"
ssh oracle "journalctl -u k3s -n 100"
# If stopped:
ssh oracle "sudo systemctl start k3s"
ssh oracle "kubectl get nodes"
Task 0.3 — Fix Unhealthy Containers¶
# contractplane-gateway
ssh oracle "docker logs contractplane-gateway --tail 50"
ssh oracle "docker exec contractplane-gateway env | grep -v PASSWORD | grep -v SECRET | grep -v TOKEN"
# litellm-proxy
ssh oracle "docker logs litellm-proxy --tail 50"
# dragonfly COMPLIANCE_ENGINE_URL fix
ssh oracle "docker exec dragonfly-core env | grep COMPLIANCE"
# Must be: COMPLIANCE_ENGINE_URL=http://compliance-engine:3010
# If wrong: update docker-compose and restart
Task 0.4 — Move Secrets Off Disk¶
# Audit env var names (NAMES ONLY — never print values)
ssh oracle "grep -E '^[A-Z_]+=' /opt/.env | cut -d= -f1 | sort"
# For each key, create GitLab CI Variable:
# gitlab.com/groups/blueflyio/-/settings/ci_cd > Variables > Add
# After ALL variables are in GitLab CI:
# Update all docker-compose files to remove: env_file: /opt/.env
# Test one profile at a time before removing /opt/.env
Task 0.5 — Enable Terraform CI¶
# Push iac/ changes to MR:
cd iac/
git checkout -b feature/phase-0-iac-baseline
git add .
git commit -m "feat(iac): Phase 0 — enable Terraform CI with GitLab HTTP backend"
git push origin feature/phase-0-iac-baseline
# Create MR in GitLab UI → targeting main
# tf-plan jobs will run automatically on MR
Task 0.6 — Import Live CF/GitLab/OCI State¶
cd iac/
npm ci
# Import (run with 1Password):
op run --env-file=.op-env --account blueflyiollc -- ./scripts/import-state.sh
# Review generated files:
git diff terraform/cloudflare/imported_tunnels.tf
git diff terraform/cloudflare/imported_dns.tf
# Commit and push — CI will run terraform plan
git add terraform/
git commit -m "feat(terraform): import live CF/GitLab state via cf-terraforming"
git push
Verification Gates¶
# Runner online
glab runner list --group blueflyio | grep "oracle-vm.*online"
# K8s healthy
ssh oracle "kubectl get nodes | grep Ready"
# No unhealthy containers
ssh oracle "docker ps --filter 'health=unhealthy' --format '{{.Names}}'" | wc -l
# Must be 0
# Terraform plan clean (check MR pipeline — tf-plan jobs green)
# Secrets off disk (after Phase 0 completes)
ssh oracle "test ! -f /opt/.env && echo 'OK' || echo 'FAIL: .env still exists'"
Phase 0 Complete When¶
- [ ] oracle-vm runner online + processing jobs
- [ ] K8s running (
kubectl get nodesreturns Ready) - [ ] 0 unhealthy containers
- [ ] terraform/cloudflare tf-plan job green on MR
- [ ] All secrets in GitLab CI Variables
- [ ] /opt/.env removed from Oracle
APPROVED: Phase 1 → only after all checkboxes above are complete.