Skip to main content

Shield Deployment

SDD Classification: L4-Operational Authority: Platform Team Review Cycle: Monthly
This document covers Shield service deployment including Docker configuration, Kubernetes manifests, environment variables, health checks, and operational procedures.

Deployment Architecture


Docker Configuration

Dockerfile

Docker Compose (Development)


Kubernetes Deployment

Deployment Manifest

Service Manifest

Ingress Configuration

Horizontal Pod Autoscaler


Environment Variables

Required Variables

Optional Variables

OAuth Provider Variables

SAML Variables


Health Endpoints

Basic Health Check

Response (200 OK):

Readiness Check

Response (200 OK):
Response (503 Service Unavailable):

Health Check Implementation


Database Migrations

Running Migrations

Migration Job Manifest

Migration Safety


Monitoring & Observability

Prometheus Metrics

Grafana Dashboard

Key panels for Shield monitoring:

Alerting Rules


Operational Procedures

Deployment Checklist

  1. Pre-deployment:
    • Run migrations in staging
    • Verify health checks pass
    • Review resource limits
    • Check secrets are configured
  2. Deployment:
    • Apply migration job
    • Deploy new image
    • Monitor rollout progress
    • Verify pod health
  3. Post-deployment:
    • Check error rates
    • Verify auth flows work
    • Monitor latency metrics
    • Test OAuth/SAML if changed

Rollback Procedure

Scaling


Secrets Management

Kubernetes Secrets

Key Rotation


Backup & Recovery

Database Backup

Recovery Time Objectives



Document Status: Complete Version: 2.0