[{"data":1,"prerenderedAt":825},["ShallowReactive",2],{"navigation":3,"doc-/infra-and-deploy":217,"docs-all-paths":770},[4,19,39,63,87,111,127,195,211],{"title":5,"path":6,"stem":7,"children":8},"Welcome","/welcome","01.welcome",[9,11,15],{"title":5,"path":6,"stem":10},"01.welcome/index",{"title":12,"path":13,"stem":14},"Astar とは（5分）","/welcome/product-in-5-min","01.welcome/01.product-in-5-min",{"title":16,"path":17,"stem":18},"事業文脈","/welcome/business-context","01.welcome/02.business-context",{"title":20,"path":21,"stem":22,"children":23},"Getting Started","/getting-started","02.getting-started",[24,27,31,35],{"title":25,"path":21,"stem":26},"はじめかた","02.getting-started/index",{"title":28,"path":29,"stem":30},"リポジトリ取得と環境構築","/getting-started/repo-setup","02.getting-started/01.repo-setup",{"title":32,"path":33,"stem":34},"日々の開発ループ","/getting-started/dev-loop","02.getting-started/02.dev-loop",{"title":36,"path":37,"stem":38},"検証の 4 層","/getting-started/verification-tiers","02.getting-started/03.verification-tiers",{"title":40,"path":41,"stem":42,"children":43},"Architecture","/architecture","03.architecture",[44,47,51,55,59],{"title":45,"path":41,"stem":46},"アーキテクチャ","03.architecture/index",{"title":48,"path":49,"stem":50},"マルチテナンシーと RLS","/architecture/multi-tenancy-rls","03.architecture/01.multi-tenancy-rls",{"title":52,"path":53,"stem":54},"認可モデル","/architecture/authorization","03.architecture/02.authorization",{"title":56,"path":57,"stem":58},"AI サブシステム","/architecture/ai-subsystem","03.architecture/03.ai-subsystem",{"title":60,"path":61,"stem":62},"データモデル","/architecture/data-model","03.architecture/04.data-model",{"title":64,"path":65,"stem":66,"children":67},"Backend","/backend","04.backend",[68,71,75,79,83],{"title":69,"path":65,"stem":70},"バックエンド","04.backend/index",{"title":72,"path":73,"stem":74},"層構造","/backend/layering","04.backend/01.layering",{"title":76,"path":77,"stem":78},"規約","/backend/conventions","04.backend/02.conventions",{"title":80,"path":81,"stem":82},"テスト","/backend/testing","04.backend/03.testing",{"title":84,"path":85,"stem":86},"マイグレーション","/backend/migrations","04.backend/04.migrations",{"title":88,"path":89,"stem":90,"children":91},"Frontend","/frontend","05.frontend",[92,95,99,103,107],{"title":93,"path":89,"stem":94},"フロントエンド","05.frontend/index",{"title":96,"path":97,"stem":98},"モジュール内部構造","/frontend/module-anatomy","05.frontend/01.module-anatomy",{"title":100,"path":101,"stem":102},"API アクセスの一本道","/frontend/api-access-chain","05.frontend/02.api-access-chain",{"title":104,"path":105,"stem":106},"i18n","/frontend/i18n","05.frontend/03.i18n",{"title":108,"path":109,"stem":110},"デザインシステム","/frontend/design-system","05.frontend/04.design-system",{"title":112,"path":113,"stem":114,"children":115},"Go Agent And Cli","/go-agent-and-cli","06.go-agent-and-cli",[116,119,123],{"title":117,"path":113,"stem":118},"Go agent と CLI","06.go-agent-and-cli/index",{"title":120,"path":121,"stem":122},"Go agent","/go-agent-and-cli/go-agent","06.go-agent-and-cli/01.go-agent",{"title":124,"path":125,"stem":126},"CLI","/go-agent-and-cli/cli","06.go-agent-and-cli/02.cli",{"title":128,"path":129,"stem":130,"children":131},"Modules","/modules","07.modules",[132,135,139,143,147,151,155,159,163,167,171,175,179,183,187,191],{"title":133,"path":129,"stem":134},"モジュール","07.modules/index",{"title":136,"path":137,"stem":138},"テーブル","/modules/table","07.modules/01.table",{"title":140,"path":141,"stem":142},"ドキュメントツリー","/modules/document","07.modules/02.document",{"title":144,"path":145,"stem":146},"AIチャット","/modules/ai","07.modules/03.ai",{"title":148,"path":149,"stem":150},"認証・権限","/modules/auth","07.modules/04.auth",{"title":152,"path":153,"stem":154},"AI取込","/modules/organize","07.modules/05.organize",{"title":156,"path":157,"stem":158},"ストレージ","/modules/storage","07.modules/06.storage",{"title":160,"path":161,"stem":162},"NAS同期","/modules/sync","07.modules/07.sync",{"title":164,"path":165,"stem":166},"ワークスペース","/modules/workspace","07.modules/08.workspace",{"title":168,"path":169,"stem":170},"テナントとメンバーシップ","/modules/tenant-membership","07.modules/09.tenant-membership",{"title":172,"path":173,"stem":174},"検索","/modules/search","07.modules/10.search",{"title":176,"path":177,"stem":178},"表示ビュー","/modules/display","07.modules/11.display",{"title":180,"path":181,"stem":182},"テンプレート","/modules/template","07.modules/12.template",{"title":184,"path":185,"stem":186},"メール","/modules/mail","07.modules/13.mail",{"title":188,"path":189,"stem":190},"電話","/modules/phone","07.modules/14.phone",{"title":192,"path":193,"stem":194},"リアルタイム","/modules/realtime","07.modules/15.realtime",{"title":196,"path":197,"stem":198,"children":199},"Infra And Deploy","/infra-and-deploy","08.infra-and-deploy",[200,203,207],{"title":201,"path":197,"stem":202},"インフラとデプロイ","08.infra-and-deploy/index",{"title":204,"path":205,"stem":206},"環境の種類","/infra-and-deploy/environments","08.infra-and-deploy/01.environments",{"title":208,"path":209,"stem":210},"セルフホスト構成","/infra-and-deploy/self-host","08.infra-and-deploy/02.self-host",{"title":212,"path":213,"stem":214,"children":215},"docs-map","/docs-map","09.docs-map/index",[216],{"title":212,"path":213,"stem":214},{"id":218,"title":201,"body":219,"description":764,"extension":765,"meta":766,"navigation":767,"path":197,"seo":768,"stem":202,"__hash__":769},"docs/08.infra-and-deploy/index.md",{"type":220,"value":221,"toc":754},"minimark",[222,225,237,244,248,265,408,413,420,470,477,481,491,529,574,591,594,613,670,690,694,708,718,743],[223,224,201],"h1",{"id":201},[226,227,228,229,233,234,236],"p",{},"このセクションは、本番環境がどう組み立てられているか、変更がどう本番に届くかを把握するためのものです。ローカル開発の起動方法は ",[230,231,232],"a",{"href":33},"はじめに / dev-loop"," を、環境ごとの違いは次ページの ",[230,235,204],{"href":205}," を参照してください。",[238,239,241],"callout",{"type":240},"warning",[226,242,243],{},"本番の Terraform state・Cloud SQL・顧客データには触れません。インフラ変更は PR → CI 経由が唯一の適用経路です（下記「Terraform — IaC」参照）。",[245,246,247],"h2",{"id":247},"本番トポロジーの全体像",[226,249,250,251,255,256,260,261,264],{},"Astar Management のプロダクション環境は ",[252,253,254],"strong",{},"GCP + Cloudflare"," のハイブリッド構成です。「バックエンドは Cloud Run」という直感は誤りで、コスト最適化のため 2026-03-17 に GCE VM へ移行済みです（",[257,258,259],"code",{},"infrastructure/terraform/cloud-run-backend.tf"," は ",[257,262,263],{},"removed"," ブロックのみが残る記録用ファイル）。",[266,267,268,284],"table",{},[269,270,271],"thead",{},[272,273,274,278,281],"tr",{},[275,276,277],"th",{},"コンポーネント",[275,279,280],{},"実体",[275,282,283],{},"経路",[285,286,287,307,335,349,360,371,389],"tbody",{},[272,288,289,297,304],{},[290,291,292,293,296],"td",{},"フロントエンド (",[257,294,295],{},"app.astarworks.com",")",[290,298,299,300,303],{},"Cloudflare Pages（",[257,301,302],{},"astar-frontend"," プロジェクト、Nuxt を静的+Worker としてビルド）",[290,305,306],{},"Cloudflare が直接配信",[272,308,309,315,332],{},[290,310,311,312,296],{},"バックエンド API (",[257,313,314],{},"api.astarworks.com",[290,316,317,318,321,322,321,325,321,328,331],{},"GCE VM（Ubuntu 24.04、Docker Compose: ",[257,319,320],{},"backend"," + ",[257,323,324],{},"cloud-sql-proxy",[257,326,327],{},"cloudflared",[257,329,330],{},"autoheal","）",[290,333,334],{},"Cloudflare Tunnel 経由（外部 IP なし、ボディ上限 100MB）",[272,336,337,343,346],{},[290,338,339,340,296],{},"Office 編集 (",[257,341,342],{},"collabora.astarworks.com",[290,344,345],{},"専用 GCE VM（Collabora Online / WOPI client）",[290,347,348],{},"Cloudflare Tunnel 経由（backend VM とは別 VM。backend VM の OOM 履歴を踏まえ分離）",[272,350,351,354,357],{},[290,352,353],{},"DB",[290,355,356],{},"Cloud SQL for PostgreSQL",[290,358,359],{},"GCE VM から Cloud SQL Auth Proxy 経由",[272,361,362,365,368],{},[290,363,364],{},"補助サービス（下記）",[290,366,367],{},"Cloud Run（3 サービス、すべて private）",[290,369,370],{},"backend VM のサービスアカウントのみ invoke 可能",[272,372,373,376,386],{},[290,374,375],{},"バイナリ配布・ドキュメントストレージ",[290,377,378,379,382,383,331],{},"Cloudflare R2（",[257,380,381],{},"astar-downloads"," / ",[257,384,385],{},"astar-documents",[290,387,388],{},"—",[272,390,391,394,406],{},[290,392,393],{},"サンドボックス実行系",[290,395,396,397,382,400,382,403,331],{},"Cloudflare Workers（",[257,398,399],{},"downloads-redirect",[257,401,402],{},"usercontent",[257,404,405],{},"coderun",[290,407,388],{},[409,410,412],"h3",{"id":411},"cloud-run-上の補助サービス","Cloud Run 上の補助サービス",[226,414,415,416,419],{},"バックエンド本体は GCE VM ですが、重い/バースト的な処理は Cloud Run の個別サービスに切り出されています（いずれも ",[257,417,418],{},"backend_vm"," サービスアカウントのみが invoke できる private サービス）。",[421,422,423,436,456],"ul",{},[424,425,426,431,432,435],"li",{},[252,427,428],{},[257,429,430],{},"astar-doc-export"," — Playwright(headless Chromium) による HTML → PDF/PNG レンダリング。UI 側のブラウザ export が主経路で、サーバーサイドレンダリングが必要な場合のフォールバック。",[257,433,434],{},"min_instance_count = 0","（scale-to-zero）。",[424,437,438,443,444,447,448,451,452,455],{},[252,439,440],{},[257,441,442],{},"astar-doc-converter"," — LibreOffice による旧 Office 形式 (",[257,445,446],{},".doc","/",[257,449,450],{},".xls",") の変換・プレビュー生成。レイテンシに敏感なユーザー向けパスのため ",[257,453,454],{},"min_instance_count = 1","（常時ウォーム）。",[424,457,458,463,464,447,466,469],{},[252,459,460],{},[257,461,462],{},"astar-kreuzberg"," — ドキュメント OCR / Markdown 抽出サイドカー。2026-07-06 の障害（backend VM の 8GB がメモリ超過し ",[257,465,327],{},[257,467,468],{},"sshd"," が OOM kill → トンネル断）を受けて VM から分離。",[226,471,472,473,476],{},"理由と構成の詳細はそれぞれの ",[257,474,475],{},"infrastructure/terraform/cloud-run-*.tf"," の冒頭コメントに書かれています。",[245,478,480],{"id":479},"terraform-iac","Terraform — IaC",[226,482,483,486,487,490],{},[257,484,485],{},"infrastructure/terraform/"," が GCP + Cloudflare のインフラを ",[252,488,489],{},"形状","（メモリ・CPU・スケーリング・ネットワーク・IAM・シークレットの入れ物）としてコード管理します。",[238,492,493],{"type":240},[226,494,495,501,502,505,506,509,510,513,514,517,518,521,522,525,526,528],{},[252,496,497,500],{},[257,498,499],{},"terraform apply"," を CLI から手動実行しない。"," 適用は ",[257,503,504],{},".github/workflows/iac.yml"," が CI 駆動で行います（",[257,507,508],{},"infrastructure/terraform/**"," か ",[257,511,512],{},"infrastructure/workers/**"," に変更が入った PR で ",[257,515,516],{},"terraform plan"," → PR コメント、",[257,519,520],{},"main"," へのマージで ",[257,523,524],{},"terraform apply -auto-approve","）。ローカルでは ",[257,527,516],{}," で差分確認までに留めます。",[421,530,531,538,553],{},[424,532,533,534,537],{},"Terraform が管理するもの: インフラの形状、シークレットの",[252,535,536],{},"シェル","（名前・レプリケーション・アクセス権のみ）、GCP API 有効化、Workload Identity Federation",[424,539,540,541,544,545,548,549,552],{},"Terraform が管理しない/できないもの: Cloud Run の",[252,542,543],{},"イメージ","とシークレットの",[252,546,547],{},"値","（",[257,550,551],{},"release.yml"," が担当）、Auth0 / SendGrid / Sentry など外部 SaaS",[424,554,555,556,559,560,562,563,382,565,382,567,569,570,573],{},"同じ ",[257,557,558],{},"iac.yml"," が ",[257,561,520],{}," マージ時に Cloudflare Workers 3 本（",[257,564,399],{},[257,566,402],{},[257,568,405],{},"）も ",[257,571,572],{},"wrangler deploy"," する",[226,575,576,579,580,583,584,587,588,590],{},[257,577,578],{},"infrastructure/terraform/README.md"," はディレクトリ構成の索引として書かれていますが、個別ファイルの現状（例: どのサービスが Cloud Run か GCE か）は ",[257,581,582],{},"README.md"," の記述より実際の ",[257,585,586],{},".tf"," ファイルの方が新しい場合があります。疑わしいときは ",[257,589,586],{}," の冒頭コメントを直接読んでください。",[245,592,593],{"id":593},"リリースパイプライン",[226,595,596,597,604,605,608,609,612],{},"リリースは ",[252,598,599,600,603],{},"git tag (",[257,601,602],{},"vX.Y.Z",") の push"," で始まります。手動で ",[257,606,607],{},"gcloud"," や ",[257,610,611],{},"docker push"," を叩く経路はありません。",[614,615,616,625,631],"ol",{},[424,617,618,621,622,624],{},[257,619,620],{},"/release"," skill がローカルの最新 ",[257,623,602],{}," タグから次バージョンを計算し、隔離 worktree で frontend build+typecheck・Tauri desktop build・Go agent cross-compile・backend Flyway migration をすべて検証",[424,626,627,628,630],{},"全ゲート PASS で ",[257,629,602],{}," タグを作成 → 明示確認の上で push",[424,632,633,634,637,638],{},"push が ",[257,635,636],{},".github/workflows/release.yml"," を起動:\n",[421,639,640,646,649,658,664],{},[424,641,642,645],{},[257,643,644],{},"validate-and-sync-secrets"," — 1Password から必要なシークレットを解決し GCP Secret Manager へ同期（下記参照）。ここが fail-fast ゲート",[424,647,648],{},"各種ビルド（Tauri desktop / Go agent binary / CLI binary / agent Docker image / doc-export / doc-converter / backend / frontend）",[424,650,651,654,655],{},[257,652,653],{},"build-and-deploy-frontend"," — Nuxt を Cloudflare Pages 向けにビルドし ",[257,656,657],{},"wrangler pages deploy",[424,659,660,663],{},[257,661,662],{},"deploy"," — Cloud SQL Auth Proxy 経由で Flyway migration を CI 上で実行 → GCE VM に SSH でデプロイスクリプトを転送・実行",[424,665,666,669],{},[257,667,668],{},"create-release"," — GitHub Release 作成",[238,671,673],{"type":672},"info",[226,674,675,676,682,683,686,687,689],{},"リリースの基点は ",[252,677,678,679,681],{},"直前の ",[257,680,602],{}," タグの系列","であり、",[257,684,685],{},"origin/main"," ブランチの最新コミットではありません。ローカル ",[257,688,520],{}," が origin より進んでいても push 前の判断は別問題として扱われます。",[245,691,693],{"id":692},"シークレットの-ssot","シークレットの SSoT",[226,695,696,697,703,704,707],{},"Astar の全バックエンドシークレットは ",[252,698,699,702],{},[257,700,701],{},"infrastructure/secrets/secrets.json"," の 1 ファイル","で宣言されています（値そのものは含まれません — 1Password への ",[257,705,706],{},"op://…"," ポインタのみ）。",[709,710,715],"pre",{"className":711,"code":713,"language":714},[712],"language-text","1Password (Astar Prod) → resolve (release.yml の validate-and-sync-secrets job)\n                        → job-scoped $GITHUB_ENV\n                        → GCP Secret Manager（シェルは Terraform が事前作成）\n                        → deploy.sh が fetch → backend 環境変数\n","text",[257,716,713],{"__ignoreMap":717},"",[226,719,720,721,382,723,726,727,730,731,734,735,738,739,742],{},"以前は Terraform / ",[257,722,551],{},[257,724,725],{},"deploy.sh"," の 3 ファイルを手で同期する必要があり、1 つでも漏れると ",[257,728,729],{},"NOT_FOUND"," でリリースが途中で壊れていました。今は ",[257,732,733],{},"secrets.json"," を編集するだけで済み、",[257,736,737],{},"infrastructure/scripts/check-secret-wiring.sh"," が配線漏れを事前検知します。詳細は ",[257,740,741],{},"infrastructure/secrets/README.md","。",[238,744,745],{"type":240},[226,746,747,748,750,751,753],{},"シークレットの",[252,749,547],{},"を画面出力させたり、",[257,752,733],{}," に直接書き込んだりしない。値の実体は常に 1Password 側のみ。",{"title":717,"searchDepth":755,"depth":755,"links":756},2,[757,761,762,763],{"id":247,"depth":755,"text":247,"children":758},[759],{"id":411,"depth":760,"text":412},3,{"id":479,"depth":755,"text":480},{"id":593,"depth":755,"text":593},{"id":692,"depth":755,"text":693},"Astar Management の本番インフラ全体像 — GCP / Cloudflare の構成、IaC (Terraform) の運用ルール、リリースパイプラインの流れ。","md",{},{"title":201},{"title":201,"description":764},"uCQMZJztEk9eRDxqTYZE8Dfa07NNYNhz82wr7u6UDpI",[771,773,774,776,777,778,779,780,781,782,783,784,786,787,788,789,790,792,793,794,795,796,798,800,802,803,804,805,806,807,808,809,810,811,812,813,814,815,816,817,818,820,821,822,823],{"path":13,"title":772},"Astar とは何か（5分で）",{"path":17,"title":16},{"path":6,"title":775},"ようこそ",{"path":29,"title":28},{"path":33,"title":32},{"path":37,"title":36},{"path":21,"title":25},{"path":49,"title":48},{"path":53,"title":52},{"path":57,"title":56},{"path":61,"title":60},{"path":41,"title":785},"システムアーキテクチャ",{"path":73,"title":72},{"path":77,"title":76},{"path":81,"title":80},{"path":85,"title":84},{"path":65,"title":791},"バックエンドガイド",{"path":97,"title":96},{"path":101,"title":100},{"path":105,"title":104},{"path":109,"title":108},{"path":89,"title":797},"フロントエンドガイド",{"path":121,"title":799},"Go agent — NAS 同期エージェント",{"path":125,"title":801},"astar CLI",{"path":113,"title":117},{"path":137,"title":136},{"path":141,"title":140},{"path":145,"title":144},{"path":149,"title":148},{"path":153,"title":152},{"path":157,"title":156},{"path":161,"title":160},{"path":165,"title":164},{"path":169,"title":168},{"path":173,"title":172},{"path":177,"title":176},{"path":181,"title":180},{"path":185,"title":184},{"path":189,"title":188},{"path":193,"title":192},{"path":129,"title":819},"モジュール索引",{"path":205,"title":204},{"path":209,"title":208},{"path":197,"title":201},{"path":213,"title":824},"docs/ 地図",1785452454153]