Production installation runbook
Install Chronacta v1.0.0 on a clean Linux VM for production.
Prerequisites
Section titled “Prerequisites”| Requirement | Version |
|---|---|
| OS | Linux amd64 (Ubuntu 22.04+ or equivalent) |
| Go (build from source) | 1.25+ per go.mod |
| Open ports | gRPC 2113, metrics 9090; optional admin 8080, REST 8081, WS 8082 |
| TLS certificates | Required in production profile |
| IdP | OIDC issuer URL (optional but recommended) |
1. Clone release tag
Section titled “1. Clone release tag”git clone https://gitverse.ru/AndreyI/chronacta.gitcd chronactagit checkout v1.0.0Or download release artifacts from dist/ after make release VERSION=v1.0.0.
Verify checksums:
cd distsha256sum -c SHA256SUMS# optional: gpg --verify SHA256SUMS.asc SHA256SUMS2. Build and verify (from source)
Section titled “2. Build and verify (from source)”make proto test-race vet build./bin/chronacta-server --version3. Layout
Section titled “3. Layout”sudo useradd -r -s /bin/false chronactasudo mkdir -p /var/lib/chronacta/data /var/lib/chronacta/backups /etc/chronactasudo chown -R chronacta:chronacta /var/lib/chronacta4. Production environment
Section titled “4. Production environment”Create /etc/chronacta/env:
# CoreCHRONACTA_PROFILE=productionCHRONACTA_DATA_DIR=/var/lib/chronacta/dataCHRONACTA_SCHEMA_DIR=/var/lib/chronacta/data/schemasCHRONACTA_BACKUP_DIR=/var/lib/chronacta/backups
# NetworkCHRONACTA_GRPC_PORT=2113CHRONACTA_METRICS_ENABLED=trueCHRONACTA_METRICS_ADDRESS=127.0.0.1:9090
# Security (required in production)CHRONACTA_AUTH_ENABLED=trueCHRONACTA_AUTH_STORE=/var/lib/chronacta/data/auth/users.jsonCHRONACTA_TLS_ENABLED=trueCHRONACTA_TLS_CERT_FILE=/etc/chronacta/tls/server.crtCHRONACTA_TLS_KEY_FILE=/etc/chronacta/tls/server.key
# HA (if cluster)CHRONACTA_CLUSTER_REPLICATION_TOKEN=<generate-long-random-token>
# Gateways (optional)CHRONACTA_REST_ENABLED=trueCHRONACTA_REST_ADDRESS=127.0.0.1:8081CHRONACTA_WS_ENABLED=trueCHRONACTA_WS_ADDRESS=127.0.0.1:8082CHRONACTA_WS_ALLOWED_ORIGINS=https://app.example.com
# OIDC (optional)CHRONACTA_OIDC_ENABLED=trueCHRONACTA_OIDC_ISSUER_URL=https://idp.example.com/CHRONACTA_OIDC_CLIENT_ID=chronacta
# ObservabilityCHRONACTA_OTEL_ENABLED=trueCHRONACTA_OTEL_ENDPOINT=otel-collector:4317Generate TLS (example with internal CA) or use cert-manager / reverse proxy termination.
5. Bootstrap admin
Section titled “5. Bootstrap admin”sudo -u chronacta env $(cat /etc/chronacta/env | xargs) \ ./bin/chronacta auth bootstrap -username admin -password '<initial-secret>'Rotate password after first login. Prefer OIDC for day-to-day access.
6. systemd unit
Section titled “6. systemd unit”/etc/systemd/system/chronacta.service:
[Unit]Description=Chronacta serverAfter=network.target
[Service]Type=simpleUser=chronactaEnvironmentFile=/etc/chronacta/envWorkingDirectory=/opt/chronactaExecStart=/opt/chronacta/bin/chronacta-serverRestart=on-failureRestartSec=5LimitNOFILE=65535
[Install]WantedBy=multi-user.targetsudo systemctl daemon-reloadsudo systemctl enable --now chronacta7. Smoke test
Section titled “7. Smoke test”./bin/chronacta health./bin/chronacta verifycurl -s http://127.0.0.1:9090/readyzcurl -s http://127.0.0.1:9090/metrics | headAppend/read test (with TLS and auth flags as configured):
./bin/chronacta login -username admin -password '<secret>'./bin/chronacta append -stream smoke -type Created -data '{"ok":true}' -expected-version -2./bin/chronacta read -stream smoke -from 18. Monitoring
Section titled “8. Monitoring”- Scrape
http://127.0.0.1:9090/metricswith Prometheus. - Import grafana/chronacta-overview.json.
- Load prometheus/chronacta-alerts.yaml.
9. Backup before go-live
Section titled “9. Backup before go-live”./bin/chronacta backup create -output /var/lib/chronacta/backups/pre-ga.tar.gzDocument RPO/RTO per backup.md and replication.md.
10. Upgrade path
Section titled “10. Upgrade path”Follow upgrade-guide.md and ha-rolling-upgrade.md for cluster nodes.
Verification
Section titled “Verification”The installation is complete when steps 1–7 finish without manual code patches.

