deploy: detect changes against live containers, not git #306
No reviewers
Labels
No labels
audit-work
bug
docs
general-admin
major-upgrade
needs-vps-sync
new-service
on-hold
outside-work
post-podman
renovate
upstream
vps
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
mysticalsoap/docker!306
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/deploy-live-detection"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
just deploydecided what changed by diffingHEAD@{1}..HEADand mapping paths to stacks. That answers "what did the pull touch", not "what does live differ from the tree", and the two diverge in both directions: a stack brought up from its branch before the merge is listed again (every PR merged from the live tree), and abuild:image that went stale under a plainjust up(which never rebuilds) is never listed. After #304 the dry run wanted infra and filebrowser for a merge live already ran, while knock and metadata had been running code two PRs old since #272 and #294 without anyone knowing.Fix
Detection asks compose. Per stack:
docker compose build -q(a cache hit unless sources changed, and the only way a rebuilt image becomes visible), thendocker compose --dry-run up -dand read theCreate/Recreatelines. That is compose's own comparison of each container's config hash and image id with the tree, so it is right for the cases a reimplementation gets wrong: services sharing another container's network namespace get a different stamped hash thanconfig --hashprints, which the first draft of this change tripped over.--dry-runnow names the containers behind each stack. The COPY-source parser and the reflog diff are gone. Maintenance.md row updated.Verification
docker compose --dry-run up -dper stack agrees line for line; a second build of knock and metadata produced identical image ids, so those are cache hits and the listed drift is real.haproxy,mouseholeandqbittorrent(allnetwork_mode: service:) while compose recreates none of them; the shipped version doesn't.Diffing HEAD@{1}..HEAD answers what the pull touched, not what live differs from the tree: a stack brought up from its branch before the merge gets listed again, and a build: image gone stale under a plain `just up` never does. Compose already compares each container's config hash and image id with the tree on every `up`, so detection is its dry run, after building so a rebuilt image exists to compare. Not a reimplementation of the hash: services sharing another container's network namespace are stamped with a different hash than `config --hash` prints. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>