feat(ci): tested-tree fast path, image_tag reuse, timestamped Dokku output #13
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/promotion-fast-path"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Three backward-compatible additions to the shared workflows. All new inputs are optional, and the defaults keep today's behaviour for every
@mainconsumer.detect-changes.yml+ newtested-tree.yml)fast_path_branch(default empty = off),fast_path_deploy_branch(main),fast_path_jobs,fast_path_workflow(ci.yml),fast_path_depth(30).tested_tree,verified_sha.mainit checks two things. First,HEAD^{tree}must equal the tree of a recent first-parentdevcommit. Second, every named job must have its latest attempt atsuccessin that commit'spushrun ondev./actions/tasks, not commit statuses. Forgejo posts a skipped job's commit status assuccess, so statuses cannot prove a job ran.github.tokenfirst, then the optional caller-passed secretfast_path_token.false. The step hascontinue-on-error, so it can never fail a caller's run.tested-tree.ymlcarries the same step for repos that keep their own change filter (both FDA repos do). The two copies must stay byte-identical, and a test enforces it.dokku-image-deploy.ymlimage_taggithub.sha: build, push and deploy as before.docker manifest inspectthen checks every image at that tag, with three tries. If one is missing, the job fails with a clear error before any SSH. Otherwise it deploys that tag.alternate-tagslabel) is checked against the deployed tag, so reuse mode still verifies exactly what runs.git:from-imageoutput now streams live throughteeinto a temp file, with every line prefixedHH:MM:SS(UTC).pipefail. Tests run both ways.ps:rebuildis streamed the same way and still fails the step on error.ps:inspectare also stamped.forgejo-cihas nomoreutils/ts, so it uses awhile read+date -uloop.README.mdis new and documents the fast path andimage_tag.CLAUDE.mdgets a pointer to it.Why
John approved this on 2026-09-29. Every FDA change runs three times (PR, dev push, main push). The main run repeats the dev run's tests and rebuilds the image dev already built. Current main runs take 4.5 min (API) and 6 min (site).
Validation
uv run --with pyyaml==6.0.3 python -m unittest discover -s tests: 33 tests pass. There are 13 new fast-path tests and 8 new deploy tests.actions/checkout's, withcurlmocked.ps:rebuildfailure propagation, and identity checked against the reused tag.bash -e(nopipefail).main360b148 it returnedtested_tree=true verified_sha=19173d3….main13895d1 it returnedtrue, 30766f3…. In that run, a bogus first token got a 401 and the fallback token was used.mainmerge tree equals itsdevparent's tree.actionlint1.7.12 with shellcheck: no new findings. The 10 remaining are pre-existing and unchanged apart from line shifts.yamllint(relaxed, line-length off): clean.ruff checkandruff formatpass ontests/.Expected timings (dry-run reasoning)
The Dokku phase is now the floor. Site run #107 (retire wait already 10 s) spent 3m20s inside
git:from-image, 09:08:13 to 09:11:32, with a cached 2 s build. The academy's streamedgit:synclog from run #67 shows where the time goes:The 2.5 min (site) and 2 min (API) targets are not reachable from the pipeline side alone. Reaching them means cutting host-side Dokku time: the double network/nginx pass, container start, and possibly contabo CPU steal. The new timestamps will show exactly where that time goes on the first run after merge.
Spec Drift Callouts
detect-changes.yml. Both have inline change filters with different, deliberate semantics: the site excludes.claude/; the academy countstests/fixtures/*.mdas code. So the fast path also ships astested-tree.yml, and consumers readneeds.fast-path.outputs.*, notneeds.detect-changes.outputs.*.detect-changes.ymlstill carries the same inputs for fleet repos that use it./actions/tasks. Statuses report skipped jobs assuccess.feat/image-identity-markeris unrelated and already merged (7526610, July). It is the/etc/ci-image-idmarker in the CI image. The identity check that mattered is the deploy's running-sha assertion, which now compares againstimage_tag.forgejo-cihad no README. I created one.forgejo-ci/CLAUDE.mdsays "push directly to main". This change went through a PR as instructed. The runner facts in that file (capacities, registry IP) are stale; I did not touch them.github.tokenmay read/actions/tasks. Consumers passCI_FORGEJO_TOKENas the fallback, and its scope is also unverified. If both are refused, the log saystask API not readableand the run takes the normal path.Rollout order
tested-tree.ymlandimage_tag, which only exist once this is onmain, so do not merge them before this one.Not verifiable without a live run
github.tokenand/orCI_FORGEJO_TOKENcan read/actions/tasks(the fallback is the slow path).docker manifest inspectagainstregistry-directwith publisher credentials inside a job container.has_code, which works).🤖 Generated with Claude Code
https://claude.ai/code/session_01CS99mH2YQv9t6iPuAbr21S