Files
stack/packages/mosaic/framework/skills/mosaic-deploy/SKILL.md
T
fargo d2eeb64433 skills: sanitize operator-identity tokens from folded ops skills
Four folded skills carried operator identity tokens that the sanitization
gate (verify-sanitized.sh) forbids in the public framework package:

- kickstart: template path pointed at a private brain checkout; now uses the
  framework-shipped $MOSAIC_HOME/templates/docs/TASKS.md.template
- mosaic-deploy: dropped one estate-specific stack-name row from the example
  table
- mosaic-portainer, mosaic-woodpecker: credentials now name the framework
  credentials store (load_credentials <service>) instead of a private
  checkout path

Estate-specific values can live in a skills-local override, which the linker
applies with precedence over canonical skills.
2026-08-19 14:34:00 -05:00

2.4 KiB

name, description
name description
mosaic-deploy Full end-to-end deploy flow for Mosaic Stack projects: push branch → open PR → wait for CI → merge → redeploy Portainer stack. Use when deploying a feature branch to production or staging, or when asked to ship a completed feature. Orchestrates mosaic-gitea, mosaic-woodpecker, and mosaic-portainer skills.

mosaic-deploy

End-to-end deployment flow for Mosaic Stack projects.

Full Deploy Sequence

push branch → open PR → CI passes → merge → portainer redeploy

Step 1: Push branch and open PR

cd ~/src/<repo>-worktrees/<task-slug>
git push -u origin <branch>
~/.config/mosaic/tools/git/pr-create.sh -t "feat: ..." -b "..." -i <issue#>
# Note the PR number from output

Step 2: Wait for CI

~/.config/mosaic/tools/git/pr-ci-wait.sh -n <pr#>

If CI fails, check:

source ~/.config/mosaic/tools/_lib/credentials.sh && load_credentials woodpecker
~/.config/mosaic/tools/woodpecker/pipeline-status.sh -r <org>/<repo>

Step 3: Merge

cd ~/src/<repo>
~/.config/mosaic/tools/git/pr-merge.sh -n <pr#> -d

For branch-protected repos (force merge):

GITEA_TOKEN=$(cat ~/.config/mosaic/credentials/gitea.env | grep TOKEN | cut -d= -f2)
curl -X POST "https://git.mosaicstack.dev/api/v1/repos/<org>/<repo>/pulls/<pr#>/merge" \
  -H "Authorization: token $GITEA_TOKEN" -H "Content-Type: application/json" \
  -d '{"Do":"squash","force_merge":true}'

Step 4: Redeploy Portainer stack

source ~/.config/mosaic/tools/_lib/credentials.sh && load_credentials portainer
~/.config/mosaic/tools/portainer/stack-redeploy.sh -n <stack-name> -p

Check deployment:

~/.config/mosaic/tools/portainer/stack-status.sh -n <stack-name>
~/.config/mosaic/tools/portainer/stack-logs.sh -n <stack-name> -l 50

Stack Name Map

Project Stack Name
mosaic-stack mosaic-stack
sage-phr sage-phr
openbrain openbrain
firefly firefly

Notes

  • Workers open PRs but never merge — orchestrator or Merge Guard handles step 3+
  • Docker Swarm image pinning: if -p doesn't pull a new image, SSH to w-docker0 (10.1.1.45) and run docker pull <image> manually, then redeploy
  • Worktrees: all coding work in ~/src/<repo>-worktrees/<task-slug>, never in main checkout
  • Always clean up worktree after push: git worktree remove ~/src/<repo>-worktrees/<task-slug>