deploy: detect changes against live containers, not git #306

Merged
mysticalsoap merged 1 commit from fix/deploy-live-detection into trunk 2026-09-21 00:40:43 -04:00
Owner

Problem

just deploy decided what changed by diffing HEAD@{1}..HEAD and mapping paths to stacks. That answers "what did the pull touch", not "what does live differ from the tree", and the two diverge in both directions: a stack brought up from its branch before the merge is listed again (every PR merged from the live tree), and a build: image that went stale under a plain just up (which never rebuilds) is never listed. After #304 the dry run wanted infra and filebrowser for a merge live already ran, while knock and metadata had been running code two PRs old since #272 and #294 without anyone knowing.

Fix

Detection asks compose. Per stack: docker compose build -q (a cache hit unless sources changed, and the only way a rebuilt image becomes visible), then docker compose --dry-run up -d and read the Create/Recreate lines. That is compose's own comparison of each container's config hash and image id with the tree, so it is right for the cases a reimplementation gets wrong: services sharing another container's network namespace get a different stamped hash than config --hash prints, which the first draft of this change tripped over. --dry-run now names the containers behind each stack. The COPY-source parser and the reflog diff are gone. Maintenance.md row updated.

Verification

  • Synced tree after #302–#304: old detector listed infra and filebrowser (false positives from the reflog). New one lists infra, monitoring, media and web, each with the containers whose image is older than the current build, and nothing for filebrowser. docker compose --dry-run up -d per stack agrees line for line; a second build of knock and metadata produced identical image ids, so those are cache hits and the listed drift is real.
  • The intermediate hash-comparison draft flagged haproxy, mousehole and qbittorrent (all network_mode: service:) while compose recreates none of them; the shipped version doesn't.
  • Full dry run across all twelve stacks takes about fifteen seconds.
## Problem `just deploy` decided what changed by diffing `HEAD@{1}..HEAD` and mapping paths to stacks. That answers "what did the pull touch", not "what does live differ from the tree", and the two diverge in both directions: a stack brought up from its branch before the merge is listed again (every PR merged from the live tree), and a `build:` image that went stale under a plain `just up` (which never rebuilds) is never listed. After #304 the dry run wanted infra and filebrowser for a merge live already ran, while knock and metadata had been running code two PRs old since #272 and #294 without anyone knowing. ## Fix Detection asks compose. Per stack: `docker compose build -q` (a cache hit unless sources changed, and the only way a rebuilt image becomes visible), then `docker compose --dry-run up -d` and read the `Create`/`Recreate` lines. That is compose's own comparison of each container's config hash and image id with the tree, so it is right for the cases a reimplementation gets wrong: services sharing another container's network namespace get a different stamped hash than `config --hash` prints, which the first draft of this change tripped over. `--dry-run` now names the containers behind each stack. The COPY-source parser and the reflog diff are gone. Maintenance.md row updated. ## Verification - Synced tree after #302–#304: old detector listed infra and filebrowser (false positives from the reflog). New one lists infra, monitoring, media and web, each with the containers whose image is older than the current build, and nothing for filebrowser. `docker compose --dry-run up -d` per stack agrees line for line; a second build of knock and metadata produced identical image ids, so those are cache hits and the listed drift is real. - The intermediate hash-comparison draft flagged `haproxy`, `mousehole` and `qbittorrent` (all `network_mode: service:`) while compose recreates none of them; the shipped version doesn't. - Full dry run across all twelve stacks takes about fifteen seconds.
deploy: detect changes against live containers, not git
All checks were successful
validate / validate (pull_request) Successful in 25s
e0382216d5
Diffing HEAD@{1}..HEAD answers what the pull touched, not what live
differs from the tree: a stack brought up from its branch before the
merge gets listed again, and a build: image gone stale under a plain
`just up` never does. Compose already compares each container's config
hash and image id with the tree on every `up`, so detection is its dry
run, after building so a rebuilt image exists to compare. Not a
reimplementation of the hash: services sharing another container's
network namespace are stamped with a different hash than `config
--hash` prints.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
mysticalsoap deleted branch fix/deploy-live-detection 2026-09-21 00:40:44 -04:00
Sign in to join this conversation.
No description provided.