xpeditis2.0/scripts/ci/resolve-release.sh
2026-09-23 08:57:58 +02:00

44 lines
1.9 KiB
Bash

#!/usr/bin/env bash
# Resolve a successfully validated preprod commit with the exact production tree.
set -euo pipefail
: "${GITHUB_SHA:?}" "${REGISTRY:?}" "${GITHUB_OUTPUT:?}"
[[ "${GITHUB_REF:-}" == refs/heads/main ]] || { echo '::error::Production must run from main.'; exit 1; }
production_tree=$(git rev-parse "$GITHUB_SHA^{tree}")
if [[ -n "${REQUESTED_SHA:-}" ]]; then
[[ "$REQUESTED_SHA" =~ ^[0-9a-fA-F]{7,40}$ ]] || { echo '::error::Invalid commit SHA.'; exit 1; }
candidates=$(git rev-parse --verify "$REQUESTED_SHA^{commit}")
else
# A normal merge creates a new SHA: its second parent is preprod.
candidates=$(git rev-list --no-walk "$GITHUB_SHA" $(git show -s --format=%P "$GITHUB_SHA"))
fi
for candidate in $candidates; do
git merge-base --is-ancestor "$candidate" "$GITHUB_SHA" || continue
[[ "$(git rev-parse "$candidate^{tree}")" == "$production_tree" ]] || continue
valid=true
digests=()
for service in backend log-exporter; do
# Only the preprod deployment job publishes these markers after health checks.
image="$REGISTRY/xpeditis-$service:validated-preprod-$candidate"
if ! manifest=$(docker buildx imagetools inspect "$image"); then
valid=false
break
fi
digest=$(awk '/^Digest:/ {print $2; exit}' <<< "$manifest")
if [[ ! "$digest" =~ ^sha256:[0-9a-f]{64}$ ]]; then
echo 'Invalid manifest digest returned by the registry.' >&2
exit 1
fi
digests+=("$digest")
done
if [[ "$valid" == true ]]; then
echo "short=${candidate:0:7}" >> "$GITHUB_OUTPUT"
echo "commit=$candidate" >> "$GITHUB_OUTPUT"
echo "backend_digest=${digests[0]}" >> "$GITHUB_OUTPUT"
echo "log_exporter_digest=${digests[1]}" >> "$GITHUB_OUTPUT"
echo "Validated preprod commit: $candidate (identical source tree to production)"
exit 0
fi
done
echo '::error::No validated preprod image pair matches this production tree. Merge preprod without squash/rebase, or provide its validated SHA.'
exit 1