Skip to content

Cutover and retire (VPS → konstant)

Operate Change / Retire guidance for moving production off ai-sandbox onto konstant-server (or Vercel where the pattern applies).

Status (as of harvest 2026-07-30): Dual-run evaluation. Production public edge remains on Hetzner VPS. Per-app prod migration paused until parallel-evaluation sign-off.


Policy

  1. Hetzner stays warm until each production hostname is flipped and stable.
  2. Do not run the production Cloudflare tunnel connector token on konstant while the VPS still owns that tunnel.
  3. No nameserver flip is required for the lab/eval phase — use *-konstant.hectorsanchez.eu, Funnel, or interim staging URLs.
  4. Software must not select host.vps-legacy for new work.

Phase prerequisites (before prod flips)

  1. hectorsanchez.eu (or relevant zones) ready on Cloudflare when proxied CNAMEs are required.
  2. Eval hostnames on Cloudflare proxied CNAME via cloudflare-tunnel (--dns-mode cloudflare when zone ready).
  3. Retire any VPS-side konstant-staging-proxy once Funnel/konstant path is authoritative for eval.
  4. Until then, Funnel (or documented interim TLS) is the VPS-independent check for Conductor/MCP.

Per-hostname flip

  1. App healthy on konstant (or Vercel) via eval URL + smoke.
  2. Ensure tunnel hostname: cloudflare-tunnel ensure-hostname (secrets via secret-gate).
  3. Smoke public URL.
  4. Flip production DNS/tunnel route; stop serving on VPS (keep files for rollback).
  5. Record evidence on the Operate workstream / Initiative decision log.

Rollback window

  • Keep VPS powered ≥ 7 days after last hostname flip.
  • Rollback: point DNS/tunnel back to VPS / re-enable VPS unit.

Decommission Hetzner (only when all prod hostnames flipped)

  1. Confirm no public DNS/tunnel points at VPS.
  2. Final backup of /srv, /opt/apps, Platform Control SQLite (and any other state called out on the workstream).
  3. Snapshot or destroy the server in Hetzner console.
  4. Revoke unused SSH keys / tokens via Bitwarden inventory (secret-gate; Hector updates vault).
  5. GitHub-archive remaining VPS-only repos if not already archived.
  6. Mark Operate workstream Retire complete; update hosts status.

Change-style inventory

Use Operate stage Change with change-style.migrate-host for cutover work. Incidents on either host use Incident → return to Run unless Retire is the exit.