# Tenant Rollout Runbook: Executive Summary Actions Seeder

**Seeder:** `database/seeders/ExecutiveSummaryActionsSeeder.php`  
**Target Menu:** `DASHBOARD` (`code = 'DASHBOARD'`)  
**Action Codes:**
- `FINANCE_SUMMARY` (Ringkasan Keuangan)
- `STUDENT_SUMMARY` (Ringkasan Siswa & PPDB)
- `STAFF_SUMMARY` (Ringkasan Kepegawaian)

**Target Roles (Tolerant):** `ZIAD`, `KETUA_YAYASAN`, `KEPSEK`

---

## Architecture Context
In ZIAD, tenancy is deployment-level: each school/tenant runs its own database and container deployment (~37-51 tenants). Database names typically follow the `ziad_<tenant>` convention or are isolated per container. Role casing and existence vary across tenants (e.g., some tenants may lack `KETUA_YAYASAN` or `KEPSEK`). The seeder is idempotent and skips missing roles without aborting.

---

## Rollout Steps

### Step 1: Canary Single-Tenant Verification
Run and verify on a single canary/staging tenant first:

```bash
# Run seeder on canary
php artisan db:seed --class=ExecutiveSummaryActionsSeeder
```

Verify that the 3 actions exist under the `DASHBOARD` menu and are mapped in `role_action`:
```bash
php artisan tinker --execute="
\$dashId = App\Models\Menu::where('code', 'DASHBOARD')->value('id');
echo 'Actions count: ' . App\Models\Action::where('menu_id', \$dashId)->whereIn('code', ['FINANCE_SUMMARY', 'STUDENT_SUMMARY', 'STAFF_SUMMARY'])->count() . PHP_EOL;
echo 'Role attachments: ' . DB::table('role_action')->whereIn('action_id', App\Models\Action::where('menu_id', \$dashId)->whereIn('code', ['FINANCE_SUMMARY', 'STUDENT_SUMMARY', 'STAFF_SUMMARY'])->pluck('id'))->count() . PHP_EOL;
"
```

### Step 2: Multi-Tenant Batch Rollout

Depending on the environment configuration, choose one of the following methods:

#### Method A: Multi-Container Rollout (Docker Swarm / Compose per tenant)
```bash
for container in $(docker ps --filter "name=ziad_php" --format "{{.Names}}"); do
  echo "==> Seeding container: $container"
  docker exec "$container" php artisan db:seed --class=ExecutiveSummaryActionsSeeder --force
done
```

#### Method B: Shared MySQL Multi-Database Loop
```bash
for db in $(mysql -u "$DB_USERNAME" -p"$DB_PASSWORD" -h "$DB_HOST" -e "SHOW DATABASES LIKE 'ziad_%';" -s --skip-column-names); do
  echo "==> Seeding database: $db"
  DB_DATABASE="$db" php artisan db:seed --class=ExecutiveSummaryActionsSeeder --force
done
```

#### Method C: Deployment Orchestration (Deploy Script / ziad-monitoring)
If deploying via central deployment runner (e.g. `ziad-monitoring/clients.csv` and `automation/production/deploy.sh`):
```bash
# Add or run ExecutiveSummaryActionsSeeder in the tenant batch migration/seeder phase
./automation/production/deploy.sh --all-tenants --seed=ExecutiveSummaryActionsSeeder
```

---

## Step 3: Post-Rollout Sanity Check
Check sample tenants to ensure no errors occurred and actions are active:

```bash
php artisan tinker --execute="echo App\Models\Action::whereIn('code', ['FINANCE_SUMMARY','STUDENT_SUMMARY','STAFF_SUMMARY'])->get(['id','code','name']);"
```
