Chapter 16: Capstone — Ship It End-to-End
16.6 Deploy path A — VM + image (SSH or Ansible)
- Lab VM reachable by SSH (from the AWS course habit — stop when idle).
- Docker installed on the VM (link AWS/Docker guides; do not invent versions).
- Secrets for registry login live in GitHub Secrets or Ansible Vault — not in Git.
docker pull your/badge-api:sha-…- Stop old container; run new one with
-pand env from a server-local file (not committed). curl http://127.0.0.1:<port>/healthon the VM.- Record the live tag in RUNBOOK.md.
What you see: one known image tag running; health green; previous tag named for rollback.