Deployment¶
MedTracker uses profiles in a single compose.yaml file for development,
testing, and local validation of the production image.
Compose profiles¶
dev: development stacktest: test stackprod: local validation of the production image
Development deployment¶
Use Taskfile wrappers:
task dev:portless
task dev:seed
Stop or inspect:
task dev:stop
task dev:logs
task dev:ps
Test deployment¶
Start/stop test services when needed:
task test:up
task test:stop
task test:logs
Run full tests in the test environment:
task test
Local production-image validation¶
The prod profile builds the production image and migrates its local PostgreSQL
database before starting the application. It is not a real production
deployment.
task prod:build
task prod:up
task prod:ps
task prod:up runs the migrate-prod service before starting the web service.
Use the Task wrappers to inspect and stop the local stack:
task prod:logs
task prod:stop
For a real reachable deployment, follow the hosted private beta runbook or the Kubernetes runbooks linked below.
Environment and database notes¶
See the production environment reference for required settings, database roles, registration policy, and process sizing.
- All environments use PostgreSQL.
- PostgreSQL version target is
18. - Use Rails credentials and environment variables for secrets. Never commit them.
- Existing databases created before 0.5 need the pre-0.5 database upgrade bootstrap before running 0.5 migrations.
- Leave
DATABASE_ROLEunset for migrations in existing shared-login deployments. The web process uses the same database login and may setDATABASE_ROLE=med_tracker_appfor runtime row-level security. Owner-role switching is deferred until there is an explicit ownership-adoption and rollback design for existing databases.
External API credentials¶
See optional integration configuration for the complete service inventory and privacy boundaries.
NHS dm+d medicine search¶
The medicine search feature requires a system-to-system account from the NHS England Terminology Server. See NHS dm+d Integration for the full setup guide including how to request credentials.
| Variable | Required | Description |
|---|---|---|
NHS_DMD_CLIENT_ID |
Yes | OAuth2 client ID from NHS |
NHS_DMD_CLIENT_SECRET |
Yes | OAuth2 client secret from NHS |
If either variable is absent, the medicine search feature is disabled and does not make NHS API calls.
Bootstrap the first administrator¶
Kubernetes operators should use the dedicated runbook for complete seeding procedures:
Use the runbook for both Kubernetes Jobs. It includes the required runtime settings, household selector, supported invitation roles, verification, and cleanup steps.
Quick flow selection:
| Goal | Command | Notes |
|---|---|---|
| Create first administrator account | rails med_tracker:bootstrap_admin |
One-off account creation with ADMIN_* vars |
| Invite initial care-team users | rails db:seed |
Reads /app/db/seeds/users.yml, idempotent skips |
After the first admin exists, self-registration without invitations is blocked.
Rebuild environments¶
Development rebuild (destructive to dev volumes):
task dev:rebuild
Test rebuild (destructive to test volumes):
task test:rebuild