Tag built images with the commit's short hash (closes #239)
Check / check (pull_request) Skipped
Check / check (pull_request) Skipped
Builds are tagged upaas-<app>:<short hash>, git's own short form of the commit checked out, instead of the deployment number. A redeploy of a commit gives the tag to the new image. The cleanup after a deploy now also finds the app's untagged images among those its deployments recorded, and removes them by ID once the app neither runs them nor would roll back to them. It keeps every image any app uses, since apps that build the same commit can share one. The clone reads the commits from git's output after removing Docker's log headers, which had hidden the COMMIT: line; commit_sha is now saved on update so manual deploys keep the commit they recorded. Model: opus-5-5
This commit is contained in:
+87
-19
@@ -25,6 +25,7 @@ import (
|
||||
"github.com/docker/docker/client"
|
||||
"github.com/docker/docker/pkg/archive"
|
||||
"github.com/docker/docker/pkg/jsonmessage"
|
||||
"github.com/docker/docker/pkg/stdcopy"
|
||||
"github.com/docker/go-connections/nat"
|
||||
controlapi "github.com/moby/buildkit/api/services/control"
|
||||
buildkitclient "github.com/moby/buildkit/client"
|
||||
@@ -491,6 +492,7 @@ type cloneConfig struct {
|
||||
type CloneResult struct {
|
||||
Output string // Combined stdout/stderr from git clone
|
||||
CommitSHA string // The HEAD commit SHA after clone/checkout
|
||||
ShortSHA string // git's short form of CommitSHA (git rev-parse --short)
|
||||
}
|
||||
|
||||
// CloneRepo clones a git repository using SSH and optionally checks out a
|
||||
@@ -553,7 +555,7 @@ func (c *Client) RemoveImage(ctx context.Context, imageID ImageID) error {
|
||||
}
|
||||
|
||||
// ListImageTags returns the tags in the given repository, such as
|
||||
// "upaas-myapp:12" in "upaas-myapp", each with the ID of its image.
|
||||
// "upaas-myapp:1a2b3c4" in "upaas-myapp", each with the ID of its image.
|
||||
// Tags the same image has in other repositories are left out.
|
||||
func (c *Client) ListImageTags(
|
||||
ctx context.Context,
|
||||
@@ -583,19 +585,44 @@ func (c *Client) ListImageTags(
|
||||
return tags, nil
|
||||
}
|
||||
|
||||
// RemoveImageTag removes a tag such as "upaas-myapp:12", without force.
|
||||
// Docker then deletes the image, and the untagged images it was built on,
|
||||
// only if no other tag and no container still uses it.
|
||||
func (c *Client) RemoveImageTag(ctx context.Context, tag string) error {
|
||||
// ListUntaggedImages returns the IDs of the images that have no tag, such
|
||||
// as one whose tag a later build gave to the image it built.
|
||||
func (c *Client) ListUntaggedImages(ctx context.Context) ([]ImageID, error) {
|
||||
if c.docker == nil {
|
||||
return nil, ErrNotConnected
|
||||
}
|
||||
|
||||
images, err := c.docker.ImageList(ctx, image.ListOptions{
|
||||
Filters: filters.NewArgs(filters.Arg("dangling", "true")),
|
||||
})
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("failed to list untagged images: %w", err)
|
||||
}
|
||||
|
||||
imageIDs := make([]ImageID, 0, len(images))
|
||||
|
||||
for _, img := range images {
|
||||
imageIDs = append(imageIDs, ImageID(img.ID))
|
||||
}
|
||||
|
||||
return imageIDs, nil
|
||||
}
|
||||
|
||||
// RemoveImageTag removes the tag name, such as "upaas-myapp:1a2b3c4",
|
||||
// without force. Docker then deletes the image, and the untagged images it
|
||||
// was built on, only if no other tag and no container still uses it. If name
|
||||
// is instead the ID of an untagged image, it removes that image unless a
|
||||
// container uses it.
|
||||
func (c *Client) RemoveImageTag(ctx context.Context, name string) error {
|
||||
if c.docker == nil {
|
||||
return ErrNotConnected
|
||||
}
|
||||
|
||||
_, err := c.docker.ImageRemove(ctx, tag, image.RemoveOptions{
|
||||
_, err := c.docker.ImageRemove(ctx, name, image.RemoveOptions{
|
||||
PruneChildren: true,
|
||||
})
|
||||
if err != nil && !client.IsErrNotFound(err) {
|
||||
return fmt.Errorf("failed to remove image tag %s: %w", tag, err)
|
||||
return fmt.Errorf("failed to remove image %s: %w", name, err)
|
||||
}
|
||||
|
||||
return nil
|
||||
@@ -850,11 +877,13 @@ func (c *Client) createGitContainer(
|
||||
// Clone without depth limit so we can checkout any commit, then checkout specific SHA
|
||||
script = `git clone --branch "$CLONE_BRANCH" "$CLONE_URL" /repo` +
|
||||
` && cd /repo && git checkout "$CLONE_SHA"` +
|
||||
` && echo COMMIT:$(git rev-parse HEAD)`
|
||||
` && echo COMMIT:$(git rev-parse HEAD)` +
|
||||
` && echo SHORT_SHA:$(git rev-parse --short HEAD)`
|
||||
} else {
|
||||
// Shallow clone of branch HEAD, then output commit SHA
|
||||
script = `git clone --depth 1 --branch "$CLONE_BRANCH" "$CLONE_URL" /repo` +
|
||||
` && cd /repo && echo COMMIT:$(git rev-parse HEAD)`
|
||||
` && cd /repo && echo COMMIT:$(git rev-parse HEAD)` +
|
||||
` && echo SHORT_SHA:$(git rev-parse --short HEAD)`
|
||||
}
|
||||
|
||||
env := []string{
|
||||
@@ -921,7 +950,7 @@ func (c *Client) runGitClone(
|
||||
return nil, fmt.Errorf("error waiting for git container: %w", err)
|
||||
case status := <-statusCh:
|
||||
// Always capture logs for the result
|
||||
logs, _ := c.ContainerLogs(ctx, containerID, "100")
|
||||
logs := c.gitContainerOutput(ctx, containerID)
|
||||
|
||||
if status.StatusCode != 0 {
|
||||
return nil, fmt.Errorf(
|
||||
@@ -932,23 +961,62 @@ func (c *Client) runGitClone(
|
||||
)
|
||||
}
|
||||
|
||||
// Parse commit SHA from output (looks for "COMMIT:<sha>" line)
|
||||
commitSHA := parseCommitSHA(logs)
|
||||
// Parse the commit from the "COMMIT:" and "SHORT_SHA:" lines.
|
||||
result := &CloneResult{
|
||||
Output: logs,
|
||||
CommitSHA: parseCommitSHA(logs, commitMarker),
|
||||
ShortSHA: parseCommitSHA(logs, shortSHAMarker),
|
||||
}
|
||||
|
||||
return &CloneResult{Output: logs, CommitSHA: commitSHA}, nil
|
||||
// The short hash names the image the deploy builds.
|
||||
if result.ShortSHA == "" {
|
||||
return nil, fmt.Errorf("%w: no short commit hash in its output: %s",
|
||||
ErrGitCloneFailed, logs)
|
||||
}
|
||||
|
||||
return result, nil
|
||||
}
|
||||
}
|
||||
|
||||
// commitMarker is the prefix used to identify commit SHA in clone output.
|
||||
const commitMarker = "COMMIT:"
|
||||
// gitContainerOutput returns the last 100 lines the git container wrote.
|
||||
// Docker puts a header before each line a container without a terminal
|
||||
// writes; stdcopy removes them so that the lines can be parsed.
|
||||
func (c *Client) gitContainerOutput(
|
||||
ctx context.Context,
|
||||
containerID ContainerID,
|
||||
) string {
|
||||
reader, err := c.docker.ContainerLogs(ctx, containerID.String(), container.LogsOptions{
|
||||
ShowStdout: true,
|
||||
ShowStderr: true,
|
||||
Tail: "100",
|
||||
})
|
||||
if err != nil {
|
||||
return ""
|
||||
}
|
||||
|
||||
// parseCommitSHA extracts the commit SHA from git clone output.
|
||||
// It looks for a line starting with "COMMIT:" and returns the SHA after it.
|
||||
func parseCommitSHA(output string) string {
|
||||
defer func() { _ = reader.Close() }()
|
||||
|
||||
var output strings.Builder
|
||||
|
||||
_, _ = stdcopy.StdCopy(&output, &output, reader)
|
||||
|
||||
return output.String()
|
||||
}
|
||||
|
||||
// Prefixes of the lines in the clone output that carry the commit checked
|
||||
// out, in full and in git's short form.
|
||||
const (
|
||||
commitMarker = "COMMIT:"
|
||||
shortSHAMarker = "SHORT_SHA:"
|
||||
)
|
||||
|
||||
// parseCommitSHA extracts a commit SHA from git clone output.
|
||||
// It looks for a line starting with marker and returns the SHA after it.
|
||||
func parseCommitSHA(output, marker string) string {
|
||||
for line := range strings.SplitSeq(output, "\n") {
|
||||
line = strings.TrimSpace(line)
|
||||
|
||||
sha, found := strings.CutPrefix(line, commitMarker)
|
||||
sha, found := strings.CutPrefix(line, marker)
|
||||
if found {
|
||||
return strings.TrimSpace(sha)
|
||||
}
|
||||
|
||||
@@ -6,6 +6,7 @@ import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"io"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
@@ -16,6 +17,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/docker/docker/client"
|
||||
"github.com/docker/docker/pkg/stdcopy"
|
||||
controlapi "github.com/moby/buildkit/api/services/control"
|
||||
)
|
||||
|
||||
@@ -203,6 +205,8 @@ func TestPerformCloneRemovesContainerVolumes(t *testing.T) {
|
||||
<-r.Context().Done()
|
||||
case strings.HasSuffix(r.URL.Path, "/wait"):
|
||||
_, _ = fmt.Fprintf(w, `{"StatusCode":%d}`, tt.exitCode)
|
||||
case strings.HasSuffix(r.URL.Path, "/logs"):
|
||||
writeCloneOutput(w)
|
||||
default:
|
||||
_, _ = w.Write([]byte(`{}`))
|
||||
}
|
||||
@@ -244,6 +248,62 @@ func TestPerformCloneRemovesContainerVolumes(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// cloneCommit is the commit the fake clones in these tests check out.
|
||||
const cloneCommit = "1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b"
|
||||
|
||||
// writeCloneOutput writes the output of a git clone of cloneCommit as
|
||||
// Docker sends a container's log: each line after a header.
|
||||
func writeCloneOutput(w io.Writer) {
|
||||
stdout := stdcopy.NewStdWriter(w, stdcopy.Stdout)
|
||||
stderr := stdcopy.NewStdWriter(w, stdcopy.Stderr)
|
||||
|
||||
_, _ = stderr.Write([]byte("Cloning into '/repo'...\n"))
|
||||
_, _ = stdout.Write([]byte("COMMIT:" + cloneCommit + "\n"))
|
||||
_, _ = stdout.Write([]byte("SHORT_SHA:1a2b3c4\n"))
|
||||
}
|
||||
|
||||
// TestCloneRepoReadsCommit runs a clone against a fake Docker API and
|
||||
// checks that the commit checked out is read from the clone's output, in
|
||||
// full and in git's short form.
|
||||
func TestCloneRepoReadsCommit(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
srv := httptest.NewServer(http.HandlerFunc(
|
||||
func(w http.ResponseWriter, r *http.Request) {
|
||||
switch {
|
||||
case strings.HasSuffix(r.URL.Path, "/containers/create"):
|
||||
_, _ = w.Write([]byte(`{"Id":"gitcontainer"}`))
|
||||
case strings.HasSuffix(r.URL.Path, "/logs"):
|
||||
writeCloneOutput(w)
|
||||
default:
|
||||
_, _ = w.Write([]byte(`{}`))
|
||||
}
|
||||
},
|
||||
))
|
||||
t.Cleanup(srv.Close)
|
||||
|
||||
dockerAPI, err := client.NewClientWithOpts(
|
||||
client.WithHost("tcp://" + srv.Listener.Addr().String()),
|
||||
)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
c := &Client{docker: dockerAPI, log: slog.Default()}
|
||||
|
||||
result, err := c.CloneRepo(
|
||||
t.Context(), "git@example.com:repo.git", mainBranch, "", "fake-key",
|
||||
t.TempDir(), t.TempDir(),
|
||||
)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
if result.CommitSHA != cloneCommit || result.ShortSHA != "1a2b3c4" {
|
||||
t.Errorf("got commit %q, short %q", result.CommitSHA, result.ShortSHA)
|
||||
}
|
||||
}
|
||||
|
||||
// TestPerformBuildUsesBuildKit runs a build against a fake Docker API and
|
||||
// checks that it asks for BuildKit and that BuildKit's progress reaches the
|
||||
// build log as plain text.
|
||||
|
||||
Reference in New Issue
Block a user