Northflank releases and private performance tests
The vendune-main-release Northflank workflow listens to pushes to main only.
GitHub branch protection requires the complete verify check, an up-to-date
branch and pull requests; enforcement applies to administrators as well.
The workflow queues releases, builds the exact triggering SHA, waits for a
PostgreSQL native backup, deploys that exact image to vendune-migrate, waits
for its successful migration-only run, then deploys the same image to Core and
waits for readiness. Core's direct CD and the builder's direct CI stay disabled.
A failed backup, build or migration prevents the service deployment.
vendune-migrate runs /app/vendune with BOOTSTRAP_MODE=migrate, without
operator credentials or demo seeding. It inherits only the existing private
PostgreSQL URI from vendune-runtime. Migration ledger/checksums and the database
migration lock remain authoritative. Do not edit a released migration: add a new
one. Use expand/contract schema changes while the previous version is serving.
A database backup is not automatic rollback: restore is an operator decision,
and backward-incompatible changes require a staged rollout. Release backups are
additional to the daily seven-day retention schedule; manage their retention as
catalog size grows.
The manual vendune-benchmark job builds deploy/Dockerfile.benchmark. It has
no public port or schedule. Runtime-only database linkage must never be granted
to a build. Set BENCHMARK_ENVIRONMENT=vendune-northflank-test and
BASE_URL=http://vendune-core:8787. The bounded job creates fresh synthetic tenant
IDs and retains their fixtures for diagnosis. It never modifies another tenant.
No authentication secrets, customer sessions or connection strings are logged.
scripts/cloud_benchmark.py reuses the validated sampler from benchmark.py.
It tests 1 shop × 1,000 products, 1 × 100,000, 100 × 1,000 and 1,000 × 100.
Each case measures localized catalog pages, product details, selective and broad
keyword search, at concurrency 1/8/32, twice. Broad search is capped at 64 requests
per sample to bound expensive common-term cases; other samples default to 300.
A fixed-arrival catalog sample
includes client queue time. Cart reads and one simulated persisted checkout are
also validated. Output uses RESULT_JSON, DATABASE_JSON, METADATA_JSON and
COMPLETE_JSON lines for result extraction from Northflank job logs.
These are warm-cache private HTTP measurements on the actual small deployment. They do not measure external TLS/CDN, storefront rendering, SaaS signup, vector index capacity, paid embeddings/LLM calls or real payment traffic. Shared CPU and short samples vary; report per-round values and errors, not an extrapolated shop limit. The tenant fixtures exercise distribution in the current single island; no automatic island allocator or shop relocation controller is implemented yet.
Common translated terms use ordered, deduplicated candidate IDs before loading full product rows. Effective field fallback, channel/category filters and cursor boundaries still apply before the page limit. Candidate scans can still grow with the number of matching translations; this is not a constant-work search claim.
Public Studio origin
Set both COMMERCE_PUBLIC_ORIGIN and PUBLIC_BASE_URL on the runtime service to
https://app.vendune.ai, then update/restart the service. Keep these runtime-only;
no database credential belongs in the builder. The origin guard intentionally
ignores Host/forwarded headers and accepts only the configured Studio origin.
Do not weaken it to repair a 403. No-Origin clients still use ordinary auth checks.
On 6 October 2026 the deployed fa09350 release (including API-explorer autofill
correction) was verified in Northflank. Updating the old internal code.run origin
restored public browser MCP: allowed origin 200, foreign origin 403. An authenticated
merchant created fresh synthetic shops; on the current loaded Studio the new shop
retained its session immediately. Products, eight discoverable standard apps and
MCP tools/list worked. Reload tabs opened before the release to load its new bundle.
The subsequent 75bd24a checkout release completed its backup, migration and
readiness workflow. Its public one-page checkout saved synthetic order
RAC-7cdc9432 with structured address, standard shipping and explicitly simulated
payment (EUR 79.80). No real payment was made.
This check does not certify actual payments or production SaaS security.