#!/usr/bin/env bash # Resolve a successfully validated preprod commit with the exact production tree. set -euo pipefail : "${GITHUB_SHA:?}" "${REGISTRY:?}" "${GITHUB_OUTPUT:?}" [[ "${GITHUB_REF:-}" == refs/heads/main ]] || { echo '::error::Production must run from main.'; exit 1; } production_tree=$(git rev-parse "$GITHUB_SHA^{tree}") if [[ -n "${REQUESTED_SHA:-}" ]]; then [[ "$REQUESTED_SHA" =~ ^[0-9a-fA-F]{7,40}$ ]] || { echo '::error::Invalid commit SHA.'; exit 1; } candidates=$(git rev-parse --verify "$REQUESTED_SHA^{commit}") else # A normal merge creates a new SHA: its second parent is preprod. candidates=$(git rev-list --no-walk "$GITHUB_SHA" $(git show -s --format=%P "$GITHUB_SHA")) fi for candidate in $candidates; do git merge-base --is-ancestor "$candidate" "$GITHUB_SHA" || continue [[ "$(git rev-parse "$candidate^{tree}")" == "$production_tree" ]] || continue valid=true digests=() for service in backend log-exporter; do # Only the preprod deployment job publishes these markers after health checks. image="$REGISTRY/xpeditis-$service:validated-preprod-$candidate" if ! manifest=$(docker buildx imagetools inspect "$image"); then valid=false break fi digest=$(awk '/^Digest:/ {print $2; exit}' <<< "$manifest") if [[ ! "$digest" =~ ^sha256:[0-9a-f]{64}$ ]]; then echo 'Invalid manifest digest returned by the registry.' >&2 exit 1 fi digests+=("$digest") done if [[ "$valid" == true ]]; then echo "short=${candidate:0:7}" >> "$GITHUB_OUTPUT" echo "commit=$candidate" >> "$GITHUB_OUTPUT" echo "backend_digest=${digests[0]}" >> "$GITHUB_OUTPUT" echo "log_exporter_digest=${digests[1]}" >> "$GITHUB_OUTPUT" echo "Validated preprod commit: $candidate (identical source tree to production)" exit 0 fi done echo '::error::No validated preprod image pair matches this production tree. Merge preprod without squash/rebase, or provide its validated SHA.' exit 1