44 lines
1.9 KiB
Bash
44 lines
1.9 KiB
Bash
#!/usr/bin/env bash
|
|
# Resolve a successfully validated preprod commit with the exact production tree.
|
|
set -euo pipefail
|
|
: "${GITHUB_SHA:?}" "${REGISTRY:?}" "${GITHUB_OUTPUT:?}"
|
|
[[ "${GITHUB_REF:-}" == refs/heads/main ]] || { echo '::error::Production must run from main.'; exit 1; }
|
|
production_tree=$(git rev-parse "$GITHUB_SHA^{tree}")
|
|
if [[ -n "${REQUESTED_SHA:-}" ]]; then
|
|
[[ "$REQUESTED_SHA" =~ ^[0-9a-fA-F]{7,40}$ ]] || { echo '::error::Invalid commit SHA.'; exit 1; }
|
|
candidates=$(git rev-parse --verify "$REQUESTED_SHA^{commit}")
|
|
else
|
|
# A normal merge creates a new SHA: its second parent is preprod.
|
|
candidates=$(git rev-list --no-walk "$GITHUB_SHA" $(git show -s --format=%P "$GITHUB_SHA"))
|
|
fi
|
|
for candidate in $candidates; do
|
|
git merge-base --is-ancestor "$candidate" "$GITHUB_SHA" || continue
|
|
[[ "$(git rev-parse "$candidate^{tree}")" == "$production_tree" ]] || continue
|
|
valid=true
|
|
digests=()
|
|
for service in backend log-exporter; do
|
|
# Only the preprod deployment job publishes these markers after health checks.
|
|
image="$REGISTRY/xpeditis-$service:validated-preprod-$candidate"
|
|
if ! manifest=$(docker buildx imagetools inspect "$image"); then
|
|
valid=false
|
|
break
|
|
fi
|
|
digest=$(awk '/^Digest:/ {print $2; exit}' <<< "$manifest")
|
|
if [[ ! "$digest" =~ ^sha256:[0-9a-f]{64}$ ]]; then
|
|
echo 'Invalid manifest digest returned by the registry.' >&2
|
|
exit 1
|
|
fi
|
|
digests+=("$digest")
|
|
done
|
|
if [[ "$valid" == true ]]; then
|
|
echo "short=${candidate:0:7}" >> "$GITHUB_OUTPUT"
|
|
echo "commit=$candidate" >> "$GITHUB_OUTPUT"
|
|
echo "backend_digest=${digests[0]}" >> "$GITHUB_OUTPUT"
|
|
echo "log_exporter_digest=${digests[1]}" >> "$GITHUB_OUTPUT"
|
|
echo "Validated preprod commit: $candidate (identical source tree to production)"
|
|
exit 0
|
|
fi
|
|
done
|
|
echo '::error::No validated preprod image pair matches this production tree. Merge preprod without squash/rebase, or provide its validated SHA.'
|
|
exit 1
|