Focused matrix and cleanup checks pass. Native Superset error/recovery acceptance and final semantic freeze remain open; this is not release GO.
Isolated release laboratory
This Compose project runs actual Apache Superset DEV, PREPROD and PROD instances, PostgreSQL, local Gitea, and ss-tools with Chromium. Ports bind only to localhost. Production settings and external Superset instances are not used.
python3 scripts/full-flow-env.py /tmp/ss-tools-full-flow.env
docker compose --env-file /tmp/ss-tools-full-flow.env -f docker-compose.full-flow.yml up -d --build
docker compose --env-file /tmp/ss-tools-full-flow.env -f docker-compose.full-flow.yml exec -T gitea sh /fixture/gitea-init.sh
python3 scripts/full-flow-git.py /tmp/ss-tools-full-flow.env
docker compose --env-file /tmp/ss-tools-full-flow.env -f docker-compose.full-flow.yml up -d --no-deps backend
python3 scripts/full-flow-ready.py /tmp/ss-tools-full-flow.env
The env generator refuses to overwrite existing secrets. Keep the env file outside the repository. Initial image downloads/builds and three metadata migrations can take several minutes. To inspect startup, use docker compose --env-file /tmp/ss-tools-full-flow.env -f docker-compose.full-flow.yml logs --tail=60.
| Service | Host URL | Backend/container URL |
|---|---|---|
| ss-tools frontend | http://127.0.0.1:18102 | http://frontend |
| ss-tools backend | http://127.0.0.1:18103 | http://backend:8000 |
| Superset DEV | http://127.0.0.1:18111 | http://superset-dev:8088 |
| Superset PREPROD | http://127.0.0.1:18112 | http://superset-preprod:8088 |
| Superset PROD | http://127.0.0.1:18113 | http://superset-prod:8088 |
| Gitea | http://127.0.0.1:18300 | http://gitea:3000 |
Superset users admin, analyst, reviewer, and ss-tools admin use FIXTURE_PASSWORD from the isolated env file. Superset user accounts have fixture Admin permissions so imports/exports and human review can be exercised. Superset metadata databases are separate. Shared datasource fixtures.public.sales has 90 September 2026 records, revenue 49950 and orders 90. Regional revenue: North 16350, South 16650, West 16950. Dashboard /superset/dashboard/sales/ contains revenue, regional table, daily revenue and native region/date/time-grain controls. Restart preserves existing assets. Changes in shared datasource affect all three stages intentionally.
No ss-tools release, deployment, approval or baseline evidence is fabricated. The verifier must create environments and Git links through the real API, import/export dashboards through Superset, validate PREPROD deployment, publish a release, and capture/publish baseline evidence. Backend URLs must use the container service names; localhost points to the backend container itself.
Superset is pinned to apache/superset:5.0.0-dev: official documentation identifies this tag as including PostgreSQL drivers. Bootstrap uses the native models shown in upstream 5.0.0 example code. Gitea is pinned to 1.24.6-rootless.
# Stop, retaining isolated volumes:
docker compose --env-file /tmp/ss-tools-full-flow.env -f docker-compose.full-flow.yml down
# Delete only this laboratory's data when intentionally resetting:
docker compose --env-file /tmp/ss-tools-full-flow.env -f docker-compose.full-flow.yml down -v
The local Gitea publication PAT has write:repository and write:user scopes so the flow can create actual stage repositories. Explicit rotation: python3 scripts/full-flow-git.py /tmp/ss-tools-full-flow.env --rotate-token, then recreate backend and update ss-tools Git configuration through the real API. Gitea advertises internal clone URLs at http://gitea:3000/; access its UI/API from the host at localhost:18300.
Catalog persistence uses a separate baseline-repositories volume at /app/backend/git_repos (037 resolves paths relative to backend CWD). Git repositories/artifact storage remain under /app/storage. When adding this mount to an already populated container, stop backend, copy its existing /app/backend/git_repos privately, create the replacement container without starting it, restore exact directory contents into the new volume, and start backend. Preserve hashes of existing publication bytes during this migration.