# Deployment Guide

Status: PARTIAL

## Local Runtime

```sh
cp .env.example .env
docker compose up --build -d
docker compose exec php composer install --no-interaction --prefer-dist
docker compose exec php sh scripts/migrate.sh
docker compose exec php sh scripts/runtime-verify.sh
```

If port `8080` is already in use during local development:

```sh
PHP_HTTP_PORT=8081 APP_BASE_URL=http://localhost:8081 docker compose up --build -d
```

## Services

- Apache/PHP: `http://localhost:8080`
- Realtime gateway: `http://localhost:8787`
- MySQL: `localhost:3306`
- Redis: `localhost:6379`

## Required Secrets

- `ADMIN_SETUP_TOKEN`
- `SPIN_TOKEN_SECRET`
- `REALTIME_CLIENT_TOKEN`
- `REALTIME_INTERNAL_TOKEN`
- `DB_PASSWORD`
- production TLS certificate/private key

Secrets must be provisioned through environment or secret management, not committed to source.

## Production Notes

- Terminate HTTPS at a trusted proxy or Apache TLS virtual host.
- Enable HSTS only after HTTPS is confirmed.
- Store media on a backed-up protected volume or object store.
- Run migrations before releasing new application code when compatible.
- Keep realtime gateway publication internal-only.
- Keep AirBridge as discovery only.

## Backup

- MySQL logical backup before migrations.
- Media storage snapshot before deployment.
- Redis is transient; do not treat it as durable history.
- Store release artifact checksum and migration version.
