Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 33s
CI / tests-unit (push) Failing after 2m4s
CI / tests-integration (push) Successful in 2m6s
CI / tests-ui (push) Successful in 2m43s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Docker 29.1.3 ships BuildKit v0.26, which refuses to grant a build host networking unless each caller passes --allow=network.host. All three rebuild paths asked for it, and `docker compose build` has no flag to grant it, so a rebuild failed immediately with "additional privileges requested". The live container was never replaced, which is exactly the reported symptom: the site kept serving the previous release after a rebuild. Nothing in the build actually needs host networking. It uses the network only for apk, pnpm and next/font/google — all outbound internet, which the default bridge provides. Verified by building both the full runner image and the migrations stage with --no-cache after dropping the flag. Runtime `network_mode: host` stays: blue/green needs per-release host ports (3002/3003) and nginx reaches each slot over 127.0.0.1. The second gap is how a rebuild could still ship the wrong code. ci-deploy.sh stamped every image with HEAD's revision label, and verify-deployed-release.mjs only re-checks that same label, so a dirty working tree produced an image that claimed to be release $sha while containing uncommitted code. docker-update.sh already refused this; ci-deploy.sh now does too, before any build work.
44 lines
1.4 KiB
Bash
44 lines
1.4 KiB
Bash
#!/usr/bin/env bash
|
|
# Build and browser-test a branch candidate using only disposable services.
|
|
set -Eeuo pipefail
|
|
umask 077
|
|
|
|
sha="$(git rev-parse HEAD)"
|
|
[[ "$sha" =~ ^[0-9a-f]{40}$ ]] || { echo "Invalid preflight commit" >&2; exit 1; }
|
|
temporary="$(mktemp -d "${TMPDIR:-/tmp}/cms-preflight.XXXXXXXXXX")"
|
|
suffix="${temporary##*.}"
|
|
image="epicnext-cms:preflight-$sha-$suffix"
|
|
build_attempted=0
|
|
|
|
finish() {
|
|
local status=$?
|
|
trap - EXIT
|
|
if [ "$build_attempted" -eq 1 ]; then
|
|
# Remove this run's tag only. Never prune, force-remove or touch release tags.
|
|
if ! docker image rm "$image"; then
|
|
if [ "$status" -eq 0 ]; then status=1; fi
|
|
fi
|
|
fi
|
|
# The private directory contains no files; never recursively delete a path.
|
|
if ! rmdir -- "$temporary"; then
|
|
if [ "$status" -eq 0 ]; then status=1; fi
|
|
fi
|
|
if [ "$status" -eq 0 ]; then echo "Branch preflight verified: $sha"; fi
|
|
exit "$status"
|
|
}
|
|
trap finish EXIT
|
|
trap 'exit 130' INT
|
|
trap 'exit 143' TERM
|
|
[[ "$temporary" = /* && -d "$temporary" && ! -L "$temporary" && "$suffix" =~ ^[a-zA-Z0-9]{10}$ ]] || {
|
|
echo "Invalid private preflight directory" >&2
|
|
exit 1
|
|
}
|
|
|
|
pnpm install --frozen-lockfile
|
|
pnpm exec playwright install chromium
|
|
export NEWS_E2E_IMAGE="$image"
|
|
export NEWS_E2E_RELEASE="$sha"
|
|
build_attempted=1
|
|
DOCKER_BUILDKIT=1 docker build --progress=plain \
|
|
--build-arg NEXT_DEPLOYMENT_ID="$sha" -t "$image" .
|
|
NEWS_E2E_IMAGE="$image" NEWS_E2E_RELEASE="$sha" node --import tsx e2e/news-real/run.ts |