Web frontend and supporting services for lance.blue
headquarters plan proxy-split.md
2.2 kB


id: proxy-split title: Deploying the API does not drop every live match status: open repos: [headquarters, infra] dependsOn: [] exitCriterion: > An api deploy happens during a live match and nobody playing notices. #

proxy-split #

The proxy works and has worked in production since match-launch, which started it early inside the api binary — but that is where it still lives. Every api deploy therefore drops every live match, which means the service can only be deployed when nobody is playing.

What it needs #

The proxy is the auth boundary for a match: it hands each caller their own /match/{id}/<did>/ and refuses any identity that is not the session's. Moving it is therefore also a security-sensitive change, and security-review should see the result.

More than one instance of anything also wants managed-store first, though that is not this epic's reason to exist — deploys dropping live matches is.

Done #