Files
EpicNext-Cms/scripts/ci-preflight.sh
T
openhands fdb7af7ef5
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 33s
CI / tests-unit (push) Failing after 2m4s
CI / tests-integration (push) Successful in 2m6s
CI / tests-ui (push) Successful in 2m43s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
fix(deploy): unblock every rebuild on BuildKit's host-network refusal
Docker 29.1.3 ships BuildKit v0.26, which refuses to grant a build host
networking unless each caller passes --allow=network.host. All three rebuild
paths asked for it, and `docker compose build` has no flag to grant it, so a
rebuild failed immediately with "additional privileges requested". The live
container was never replaced, which is exactly the reported symptom: the site
kept serving the previous release after a rebuild.

Nothing in the build actually needs host networking. It uses the network only
for apk, pnpm and next/font/google — all outbound internet, which the default
bridge provides. Verified by building both the full runner image and the
migrations stage with --no-cache after dropping the flag.

Runtime `network_mode: host` stays: blue/green needs per-release host ports
(3002/3003) and nginx reaches each slot over 127.0.0.1.

The second gap is how a rebuild could still ship the wrong code. ci-deploy.sh
stamped every image with HEAD's revision label, and verify-deployed-release.mjs
only re-checks that same label, so a dirty working tree produced an image that
claimed to be release $sha while containing uncommitted code. docker-update.sh
already refused this; ci-deploy.sh now does too, before any build work.
2026-10-10 13:07:13 +02:00

44 lines
1.4 KiB
Bash

#!/usr/bin/env bash
# Build and browser-test a branch candidate using only disposable services.
set -Eeuo pipefail
umask 077
sha="$(git rev-parse HEAD)"
[[ "$sha" =~ ^[0-9a-f]{40}$ ]] || { echo "Invalid preflight commit" >&2; exit 1; }
temporary="$(mktemp -d "${TMPDIR:-/tmp}/cms-preflight.XXXXXXXXXX")"
suffix="${temporary##*.}"
image="epicnext-cms:preflight-$sha-$suffix"
build_attempted=0
finish() {
local status=$?
trap - EXIT
if [ "$build_attempted" -eq 1 ]; then
# Remove this run's tag only. Never prune, force-remove or touch release tags.
if ! docker image rm "$image"; then
if [ "$status" -eq 0 ]; then status=1; fi
fi
fi
# The private directory contains no files; never recursively delete a path.
if ! rmdir -- "$temporary"; then
if [ "$status" -eq 0 ]; then status=1; fi
fi
if [ "$status" -eq 0 ]; then echo "Branch preflight verified: $sha"; fi
exit "$status"
}
trap finish EXIT
trap 'exit 130' INT
trap 'exit 143' TERM
[[ "$temporary" = /* && -d "$temporary" && ! -L "$temporary" && "$suffix" =~ ^[a-zA-Z0-9]{10}$ ]] || {
echo "Invalid private preflight directory" >&2
exit 1
}
pnpm install --frozen-lockfile
pnpm exec playwright install chromium
export NEWS_E2E_IMAGE="$image"
export NEWS_E2E_RELEASE="$sha"
build_attempted=1
DOCKER_BUILDKIT=1 docker build --progress=plain \
--build-arg NEXT_DEPLOYMENT_ID="$sha" -t "$image" .
NEWS_E2E_IMAGE="$image" NEWS_E2E_RELEASE="$sha" node --import tsx e2e/news-real/run.ts