View Issue Details

IDProjectCategoryView StatusLast Update
0011840Talerdeployment and operationspublic2026-10-01 15:11
Reportervecirex Assigned Tovecirex  
PrioritynormalSeverityfeatureReproducibilityhave not tried
Status closedResolutionfixed 
Summary0011840: deploy taler-merchant (1.6.23) on my.taler-ops.ch
Description# Pre-deployment Sign-off

Scope:
- Upgrade production merchant backend on my.taler-ops.ch (lifeline)
- Package: taler-merchant 1.6.23-0+trixie from suite trixie
- Same apt window as WebUI 1.6.33~dev7 -> 1.6.43 (related WebUI ticket)
- Situation: backend still on 1.6.22 / protocol 38:0:26; desired action: land 1.6.23 with migrate + post-checks, joint with WebUI 1.6.43

Relevant hosts:
- my.taler-ops.ch (lifeline)

Relevant tags / packages:
- From: build_version 1.6.22, protocol version 38:0:26; package 1.6.22-0+trixie
- Target: APT trixie taler-merchant=1.6.23-0+trixie
- Git: merchant tag v1.6.23
- Related: WebUI ticket for 1.6.43 (joint deploy); pattern cf. 0011803 / 0011804

Known critical bugs:
- (none listed; add related Mantis IDs if any)

Tests (commands + expected):

Baseline (before install):
curl -fsS https://my.taler-ops.ch/config | jq -r '.name,.build_version,.version'
# expect (pre-joint): taler-merchant / 1.6.22 / 38:0:26

dpkg-query -W taler-merchant taler-merchant-webui
# expect: taler-merchant 1.6.22-... ; webui 1.6.33~dev7-... (record exact)

systemctl is-active taler-merchant-httpd taler-merchant-httpd.target
# expect: active / active

- live-harness tests (before): ok:___ / info:___ / fail:___

Actions / install / migrate (operator-owned):
- Record DB steps before restart (confirm with package notes for 1.6.23)
dpkg-query -W taler-merchant
# expect after install: 1.6.23-0+trixie

systemctl is-active taler-merchant-httpd
# expect: active

journalctl -u taler-merchant-httpd -n 100 --no-pager
# expect: no restart loop; no fatal migration error


Post-install checks:
curl -fsS https://my.taler-ops.ch/config | jq -r '.name,.build_version,.version'
# expect: taler-merchant / 1.6.23 / 42:0:30 (record if differs)

dpkg-query -W taler-merchant-webui
# expect: 1.6.43-0+trixie (joint apt)

curl -fsS -o /dev/null -w '%{http_code}\n' https://my.taler-ops.ch/webui/
# expect: 200

curl -fsS -o /dev/null -w '%{http_code}\n' https://my.taler-ops.ch/terms
# expect: not 5xx (soft smoke)

- Soft smoke (ops-manual): units active; `/config` JSON; `/terms` reachable
- Private API smoke (with token): GET instances list
  expect: HTTP 200; known instances present
- Diff-driven (v1.6.22 -> v1.6.23):
  - password change requires current password + optional MFA
  - login token returned after password reset
  - MFA challenge bound to instance
  - template pay duration applied to orders
  - templates return merchant + compatible exchanges
  - mixed payments path present (smoke only if enabled)
  - KYC failure persistence / notifications (if KYC used on this host)
  expect: each exercised check returns success / expected error shape; no 500
- live-harness tests (after): ok:___ / info:___ / fail:___
  expect: fail not worse than before

Special considerations:
- Database migrations: yes -- review and apply as operator before declaring done
- Configuration changes: review MFA / password-change related options if introduced
- API changes: auth/MFA and template response fields (see git `v1.6.22..v1.6.23`)
- Protocol version recorded live as 42:0:30 after this bump
- Mixed payments: initial version -- limited coverage is ok if unused in prod yet
- hotfix: no
- I would suggest pasting journal + instances smoke into the post-deployment report once run

Other accepted risks:
- Mixed payments and KYC edge paths may be only partially tested on prod
- Protocol version changed; clients should tolerate the recorded new version

Sign-off:
- $NAME, $DATE

# Post-deployment report

Timeline:
- apt ~2026-10-01 14:03 CEST (joint with webui 1.6.43); httpd ActiveEnter ~14:04:46 CEST; dump `/var/opt/mytops-snapshots/taler-merchant.dump` ~14:07

Post-deployment checks:
- (paste: `dpkg-query`; `/config`; journal snippet; soft-smoke; instances; live-harness after)

Issues addressed:
- (if any)

Other issues:
- (if any)
Tagsmytops, quality, srv-lifeline

Activities

vecirex

2026-10-01 15:06

administrator   ~0030059

Post-deployment report (lifeline / my.taler-ops.ch)

Landed:
- taler-merchant 1.6.22-0+trixie -> 1.6.23-0+trixie (joint apt with WebUI 1.6.43; related 0011839)
- Soft smoke after: /config build_version 1.6.23 / version 42:0:30; httpd + target active; /webui 200

Incident after upgrade.sh:
- PostgreSQL was not running after upgrade.sh
- Fix: systemctl restart postgresql
- After restart: merchant units / checks recovered as above

Sign-off: post-deploy ok after postgresql restart (vecirex)

Resolution: fixed (ready to close)

Issue History

Date Modified Username Field Change
2026-10-01 15:04 vecirex New Issue
2026-10-01 15:04 vecirex Status new => assigned
2026-10-01 15:04 vecirex Assigned To => vecirex
2026-10-01 15:04 vecirex Tag Attached: mytops
2026-10-01 15:04 vecirex Tag Attached: quality
2026-10-01 15:04 vecirex Tag Attached: srv-lifeline
2026-10-01 15:06 vecirex Note Added: 0030059
2026-10-01 15:11 vecirex Status assigned => closed
2026-10-01 15:11 vecirex Resolution open => fixed