Compare commits
1
Commits
next
..
bead5134c2
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bead5134c2 |
+6
-3
@@ -1,8 +1,11 @@
|
||||
# .git is sent so that `make build` in the Dockerfile can stamp the commit into
|
||||
# upaas. List no tracked file here: git would see it as deleted in the build and
|
||||
# the version would end in -dirty.
|
||||
.git
|
||||
.env
|
||||
bin/
|
||||
.editorconfig
|
||||
.vscode/
|
||||
.idea/
|
||||
*.test
|
||||
LICENSE
|
||||
CONVENTIONS.md
|
||||
REPO_POLICIES.md
|
||||
README.md
|
||||
|
||||
@@ -31,7 +31,6 @@ RUN go mod download
|
||||
COPY . .
|
||||
|
||||
RUN make test
|
||||
# Takes the version from `git describe` on the .git copied in above.
|
||||
RUN make build
|
||||
|
||||
# Runtime stage
|
||||
|
||||
@@ -191,24 +191,17 @@ This ensures the main branch always contains clean, tested, working code.
|
||||
|
||||
Environment variables:
|
||||
|
||||
| Variable | Description | Default |
|
||||
| ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------- |
|
||||
| `PORT` | HTTP listen port. `UPAAS_PORT` is also read and wins when both are set. | 8080 |
|
||||
| `UPAAS_DATA_DIR` | Directory for the SQLite database, session key, builds and deployment logs. Deploys need it to be an absolute path unless `UPAAS_HOST_DATA_DIR` is set. | `./data` (the Docker image sets `/var/lib/upaas`) |
|
||||
| `UPAAS_HOST_DATA_DIR` | Host path of `UPAAS_DATA_DIR`, needed when upaas runs in a container so the bind mounts it passes to Docker point at the right host directory. When set, it must be absolute, or upaas refuses to start. | the value of `UPAAS_DATA_DIR` |
|
||||
| `UPAAS_DOCKER_HOST` | Docker daemon address | unix:///var/run/docker.sock |
|
||||
| `UPAAS_PLAINTEXT_HTTP` | Set when µPaaS is reached over plain HTTP (no TLS-terminating proxy in front) so CSRF origin checks use `http://`. Leave unset behind a TLS-terminating reverse proxy. | false |
|
||||
| `UPAAS_DEBUG` | Enable debug logging. Also sends the session cookie without the `Secure` flag. | false |
|
||||
| `UPAAS_SENTRY_DSN` | Read but not used: upaas sends nothing to Sentry | "" |
|
||||
| `UPAAS_METRICS_USERNAME` | When set, `/metrics` is served behind basic auth with this username. When unset, there is no `/metrics`. | "" |
|
||||
| `UPAAS_METRICS_PASSWORD` | Basic auth password for `/metrics` | "" |
|
||||
| `UPAAS_MAINTENANCE_MODE` | Only shown as `maintenanceMode` in the `/health` response; it blocks nothing | false |
|
||||
| `UPAAS_SESSION_SECRET` | Key that signs the session and CSRF cookies. When unset, a random key is generated once and kept in `$UPAAS_DATA_DIR/session.key`. | "" |
|
||||
| `UPAAS_CORS_ORIGINS` | Comma-separated origins allowed to make cross-origin requests with cookies. When unset, no CORS headers are sent. | "" |
|
||||
|
||||
The Docker client also reads the standard `DOCKER_API_VERSION`,
|
||||
`DOCKER_CERT_PATH` and `DOCKER_TLS_VERIFY` variables; `UPAAS_DOCKER_HOST`, which
|
||||
has a default, always overrides `DOCKER_HOST`.
|
||||
| Variable | Description | Default |
|
||||
| ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------- |
|
||||
| `PORT` | HTTP listen port | 8080 |
|
||||
| `UPAAS_DATA_DIR` | Data directory for SQLite and keys | `./data` (local dev only — use absolute path for Docker) |
|
||||
| `UPAAS_HOST_DATA_DIR` | Host path for DATA_DIR (when running in container) | _(none — must be set to an absolute path)_ |
|
||||
| `UPAAS_DOCKER_HOST` | Docker socket path | unix:///var/run/docker.sock |
|
||||
| `UPAAS_PLAINTEXT_HTTP` | Set when µPaaS is reached over plain HTTP (no TLS-terminating proxy in front) so CSRF origin checks use `http://`. Leave unset behind a TLS-terminating reverse proxy. | false |
|
||||
| `DEBUG` | Enable debug logging | false |
|
||||
| `SENTRY_DSN` | Sentry error reporting DSN | "" |
|
||||
| `METRICS_USERNAME` | Basic auth for /metrics | "" |
|
||||
| `METRICS_PASSWORD` | Basic auth for /metrics | "" |
|
||||
|
||||
## Running with Docker
|
||||
|
||||
@@ -226,10 +219,6 @@ This recipe serves plain HTTP, so `UPAAS_PLAINTEXT_HTTP=true` is required for
|
||||
setup and every other form to pass the CSRF origin check. Behind a
|
||||
TLS-terminating reverse proxy, drop that line.
|
||||
|
||||
The image shows the commit it was built from (the `git describe` output) in the
|
||||
page footer, the startup log and `/health`. Build it from a git clone: without
|
||||
the `.git` directory it shows `dev`.
|
||||
|
||||
### Deploying with Docker Compose
|
||||
|
||||
[`docker-compose.yml`](docker-compose.yml) builds the image from this repo and
|
||||
@@ -240,20 +229,15 @@ settings from a `.env` file next to it, which needs at least:
|
||||
HOST_DATA_DIR=/srv/upaas/data
|
||||
```
|
||||
|
||||
Other settings from [Configuration](#configuration) go in the same file, except
|
||||
`PORT`, `UPAAS_PORT` and `UPAAS_DATA_DIR`: the compose file sets both port
|
||||
settings to 8080 and `UPAAS_DATA_DIR` to `/var/lib/upaas`, overriding `.env`, to
|
||||
match its port mapping, healthcheck and data directory mount. Then run
|
||||
`docker compose up -d` from the repo root; `docker compose ps` shows the
|
||||
container as healthy once `/health` answers. To update, run `git pull` and then
|
||||
`docker compose up -d --build`: without `--build`, Compose keeps running the
|
||||
image built from the old checkout.
|
||||
Other settings from [Configuration](#configuration) go in the same file. Then
|
||||
run `docker compose up -d` from the repo root; `docker compose ps` shows the
|
||||
container as healthy once `/health` answers.
|
||||
|
||||
**Important**: `HOST_DATA_DIR` **must** be an **absolute path** on the host. It
|
||||
is bind-mounted into the container and passed as `UPAAS_HOST_DATA_DIR` so that
|
||||
Docker bind mounts during builds resolve correctly, because the Docker daemon
|
||||
resolves paths on the host, not in the container. upaas refuses to start when
|
||||
`UPAAS_HOST_DATA_DIR` is a relative path such as `./data`.
|
||||
Docker bind mounts during builds resolve correctly. Relative paths (e.g.
|
||||
`./data`) will break container builds because the Docker daemon resolves paths
|
||||
relative to the host, not the container.
|
||||
|
||||
The port is published on `127.0.0.1:8080` only, for a TLS-terminating reverse
|
||||
proxy in front of it. Leave `UPAAS_PLAINTEXT_HTTP` unset behind that proxy.
|
||||
@@ -263,11 +247,6 @@ Docker's build cache rather than as untagged images. Docker Engine 28.2 and
|
||||
later keeps that cache under a size limit by default; on older engines, set
|
||||
`"builder": {"gc": {"enabled": true}}` in the host's `daemon.json`.
|
||||
|
||||
Building with BuildKit needs Docker Engine 18.09 or later; on an older engine,
|
||||
upaas fails the deploy instead of building. A Dockerfile that uses
|
||||
`RUN --network` needs Docker Engine 23.0 or later unless its `# syntax=` line
|
||||
names Dockerfile frontend 1.3 or later, such as `docker/dockerfile:1`.
|
||||
|
||||
Session secrets are automatically generated on first startup and persisted to
|
||||
`$UPAAS_DATA_DIR/session.key`.
|
||||
|
||||
|
||||
@@ -20,52 +20,10 @@ regress.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29: The app page is 50% wider on large screens (84rem instead of
|
||||
56rem), its build log and container log boxes are twice as tall, the build log
|
||||
sits between the webhook URL and the environment variables, and the container
|
||||
log sits above the deploy key (#246).
|
||||
|
||||
- 2026-09-29: A failed build now fails the deploy with the build's own error
|
||||
instead of a later "failed to inspect image", and the deployment log shows the
|
||||
end of the build output before that error. upaas refuses to build on a Docker
|
||||
Engine older than 18.09, which cannot build with BuildKit. The README's
|
||||
Compose section says to update with `docker compose up -d --build` and names
|
||||
the Docker Engine versions builds need (#234).
|
||||
|
||||
- 2026-09-29: An image built from the `Dockerfile` now shows the commit it was
|
||||
built from (the `git describe` output) in the footer and `/health` instead of
|
||||
`dev`: `.dockerignore` no longer leaves out `.git`, nor any tracked file,
|
||||
which git would count as deleted and mark `-dirty`. upaas now also logs its
|
||||
version at startup; the logger's `Identify()` was never called (#236).
|
||||
|
||||
- 2026-09-29: The app page shows the app's branch as a label in its title, next
|
||||
to the status badge, instead of after the repository under it (#240).
|
||||
|
||||
- 2026-09-29: An app's deployments page now lists only its 10 most recent
|
||||
deployments, newest first, instead of 50 (#238).
|
||||
|
||||
- 2026-09-29: `docker-compose.yml` now sets `UPAAS_PORT` to 8080 as well as
|
||||
`PORT`, since upaas reads `UPAAS_PORT` first and a `UPAAS_PORT` in `.env` made
|
||||
it listen away from the port mapping and healthcheck; the README's Compose
|
||||
section names both (#230).
|
||||
|
||||
- 2026-09-29: The README Configuration table now lists every setting upaas
|
||||
reads, adding `UPAAS_MAINTENANCE_MODE`, `UPAAS_SESSION_SECRET` and
|
||||
`UPAAS_CORS_ORIGINS`, and gives the real default and effect of each:
|
||||
`UPAAS_PORT` wins over `PORT`, `UPAAS_HOST_DATA_DIR` falls back to
|
||||
`UPAAS_DATA_DIR`, `UPAAS_DEBUG` drops the session cookie's `Secure` flag, and
|
||||
`UPAAS_SENTRY_DSN` is not used (#229).
|
||||
|
||||
- 2026-09-28: The README Configuration table now names `UPAAS_DEBUG`,
|
||||
`UPAAS_SENTRY_DSN`, `UPAAS_METRICS_USERNAME` and `UPAAS_METRICS_PASSWORD`, the
|
||||
names upaas actually reads (the unprefixed names it listed were ignored), and
|
||||
the `UPAAS_HOST_DATA_DIR` row refers to `UPAAS_DATA_DIR` (#224).
|
||||
|
||||
- 2026-09-28: Added `docker-compose.yml` for deploying upaas: settings from
|
||||
`.env`, the port published on `127.0.0.1` only for a TLS proxy in front, and a
|
||||
healthcheck against `/health`; the README's plain-HTTP Compose example is
|
||||
replaced by a short deploy section. upaas now refuses to start when
|
||||
`UPAAS_HOST_DATA_DIR` is set to a relative path (#223).
|
||||
replaced by a short deploy section (#223).
|
||||
|
||||
- 2026-09-23: Apps are now built with BuildKit, so the stages of a multi-stage
|
||||
build stay in Docker's size-limited build cache instead of piling up as
|
||||
|
||||
+1
-3
@@ -52,8 +52,6 @@ func main() {
|
||||
handlers.New,
|
||||
server.New,
|
||||
),
|
||||
fx.Invoke(func(log *logger.Logger, _ *server.Server) {
|
||||
log.Identify()
|
||||
}),
|
||||
fx.Invoke(func(*server.Server) {}),
|
||||
).Run()
|
||||
}
|
||||
|
||||
@@ -7,14 +7,6 @@ services:
|
||||
# Every line of .env is passed to upaas as an environment variable.
|
||||
env_file: .env
|
||||
environment:
|
||||
# Override any PORT or UPAAS_PORT in .env, so upaas listens where the
|
||||
# port mapping and healthcheck below expect it. Both are set because
|
||||
# upaas reads UPAAS_PORT first.
|
||||
PORT: "8080"
|
||||
UPAAS_PORT: "8080"
|
||||
# Overrides any UPAAS_DATA_DIR in .env, so the database stays on the
|
||||
# HOST_DATA_DIR mount below instead of inside the container.
|
||||
UPAAS_DATA_DIR: /var/lib/upaas
|
||||
# The Docker daemon resolves app bind mounts on the host, so upaas must
|
||||
# know the host path of its data directory.
|
||||
UPAAS_HOST_DATA_DIR: ${HOST_DATA_DIR:?set HOST_DATA_DIR in .env to an absolute host path}
|
||||
|
||||
@@ -32,12 +32,6 @@ const (
|
||||
filePermissions = 0o600
|
||||
)
|
||||
|
||||
// errHostDataDirNotAbsolute is returned when UPAAS_HOST_DATA_DIR is set to a
|
||||
// relative path, which the Docker daemon cannot resolve for app bind mounts.
|
||||
var errHostDataDirNotAbsolute = errors.New(
|
||||
"UPAAS_HOST_DATA_DIR must be an absolute path",
|
||||
)
|
||||
|
||||
// Params contains dependencies for Config.
|
||||
type Params struct {
|
||||
fx.In
|
||||
@@ -130,10 +124,6 @@ func buildConfig(log *slog.Logger, params *Params) (*Config, error) {
|
||||
dataDir := viper.GetString("DATA_DIR")
|
||||
hostDataDir := viper.GetString("HOST_DATA_DIR")
|
||||
|
||||
if hostDataDir != "" && !filepath.IsAbs(hostDataDir) {
|
||||
return nil, fmt.Errorf("%w, got %q", errHostDataDirNotAbsolute, hostDataDir)
|
||||
}
|
||||
|
||||
if hostDataDir == "" {
|
||||
hostDataDir = dataDir
|
||||
}
|
||||
|
||||
@@ -1,33 +0,0 @@
|
||||
package config //nolint:testpackage // tests unexported buildConfig
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"log/slog"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestBuildConfigRejectsRelativeHostDataDir(t *testing.T) {
|
||||
t.Setenv("UPAAS_HOST_DATA_DIR", "./data")
|
||||
setupViper("upaas")
|
||||
|
||||
_, err := buildConfig(slog.Default(), &Params{})
|
||||
if !errors.Is(err, errHostDataDirNotAbsolute) {
|
||||
t.Fatalf("expected errHostDataDirNotAbsolute, got %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestBuildConfigHostDataDirDefaultsToDataDir(t *testing.T) {
|
||||
t.Setenv("UPAAS_DATA_DIR", "./data")
|
||||
t.Setenv("UPAAS_HOST_DATA_DIR", "")
|
||||
t.Setenv("UPAAS_SESSION_SECRET", "test-secret")
|
||||
setupViper("upaas")
|
||||
|
||||
cfg, err := buildConfig(slog.Default(), &Params{})
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected error: %v", err)
|
||||
}
|
||||
|
||||
if cfg.HostDataDir != "./data" {
|
||||
t.Errorf("expected HostDataDir ./data, got %q", cfg.HostDataDir)
|
||||
}
|
||||
}
|
||||
@@ -21,7 +21,6 @@ import (
|
||||
"github.com/docker/docker/api/types/image"
|
||||
"github.com/docker/docker/api/types/mount"
|
||||
"github.com/docker/docker/api/types/network"
|
||||
"github.com/docker/docker/api/types/versions"
|
||||
"github.com/docker/docker/client"
|
||||
"github.com/docker/docker/pkg/archive"
|
||||
"github.com/docker/docker/pkg/jsonmessage"
|
||||
@@ -62,15 +61,6 @@ var ErrInvalidBranch = errors.New("invalid branch name")
|
||||
// ErrInvalidCommitSHA is returned when a commit SHA is not a valid hex string.
|
||||
var ErrInvalidCommitSHA = errors.New("invalid commit SHA")
|
||||
|
||||
// ErrBuildKitUnavailable is returned when the Docker daemon is too old to
|
||||
// build with BuildKit.
|
||||
var ErrBuildKitUnavailable = errors.New("BuildKit is unavailable on the Docker daemon")
|
||||
|
||||
// minBuildKitAPIVersion is the API version of Docker Engine 18.09, the first
|
||||
// that builds with BuildKit when asked to without experimental mode. Older
|
||||
// daemons refuse the request or silently use the legacy builder.
|
||||
const minBuildKitAPIVersion = "1.39"
|
||||
|
||||
// validBranchRe matches safe git branch names.
|
||||
var validBranchRe = regexp.MustCompile(`^[a-zA-Z0-9._/\-]+$`)
|
||||
|
||||
@@ -605,20 +595,6 @@ func (c *Client) performBuild(
|
||||
ctx context.Context,
|
||||
opts BuildImageOptions,
|
||||
) (ImageID, error) {
|
||||
server, err := c.docker.ServerVersion(ctx)
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("failed to get Docker version: %w", err)
|
||||
}
|
||||
|
||||
if versions.LessThan(server.APIVersion, minBuildKitAPIVersion) {
|
||||
return "", fmt.Errorf(
|
||||
"%w: Docker Engine %s (API %s) is older than 18.09 (API %s); "+
|
||||
"upgrade Docker Engine",
|
||||
ErrBuildKitUnavailable, server.Version, server.APIVersion,
|
||||
minBuildKitAPIVersion,
|
||||
)
|
||||
}
|
||||
|
||||
// Create tar archive of build context
|
||||
tarArchive, err := archive.TarWithOptions(opts.ContextDir, &archive.TarOptions{})
|
||||
if err != nil {
|
||||
@@ -684,8 +660,7 @@ const scannerMaxBufferSize = 1024 * 1024 // 1MB
|
||||
// newline-delimited JSON. BuildKit's progress arrives encoded in
|
||||
// "moby.buildkit.trace" messages; these are decoded and written as plain
|
||||
// text, as "docker build --progress=plain" shows it. Other lines, such as
|
||||
// build errors, are written unchanged. Docker ends a failed build with a line
|
||||
// carrying the error; it is returned once the output is written.
|
||||
// build errors, are written unchanged.
|
||||
func (c *Client) streamBuildOutput(
|
||||
ctx context.Context,
|
||||
body io.Reader,
|
||||
@@ -715,8 +690,6 @@ func (c *Client) streamBuildOutput(
|
||||
buf := make([]byte, 0, scannerInitialBufferSize)
|
||||
scanner.Buffer(buf, scannerMaxBufferSize)
|
||||
|
||||
var buildErr error
|
||||
|
||||
for scanner.Scan() {
|
||||
line := scanner.Bytes()
|
||||
|
||||
@@ -735,10 +708,6 @@ func (c *Client) streamBuildOutput(
|
||||
continue
|
||||
}
|
||||
|
||||
if err == nil && msg.Error != nil {
|
||||
buildErr = msg.Error
|
||||
}
|
||||
|
||||
// One write per line, so it is not split by the display's output.
|
||||
_, _ = fmt.Fprintf(out, "%s\n", line)
|
||||
}
|
||||
@@ -751,7 +720,7 @@ func (c *Client) streamBuildOutput(
|
||||
return fmt.Errorf("failed to read build output: %w", scanErr)
|
||||
}
|
||||
|
||||
return buildErr
|
||||
return nil
|
||||
}
|
||||
|
||||
func (c *Client) performClone(
|
||||
|
||||
@@ -271,8 +271,6 @@ func TestPerformBuildUsesBuildKit(t *testing.T) {
|
||||
srv := httptest.NewServer(http.HandlerFunc(
|
||||
func(w http.ResponseWriter, r *http.Request) {
|
||||
switch {
|
||||
case strings.HasSuffix(r.URL.Path, "/version"):
|
||||
_, _ = w.Write([]byte(`{"Version":"27.3.1","ApiVersion":"1.47"}`))
|
||||
case strings.HasSuffix(r.URL.Path, "/build"):
|
||||
if r.URL.Query().Get("version") != "2" {
|
||||
http.Error(w, "not a BuildKit build", http.StatusBadRequest)
|
||||
@@ -316,82 +314,3 @@ func TestPerformBuildUsesBuildKit(t *testing.T) {
|
||||
t.Errorf("build log is missing the build step:\n%s", buildLog.String())
|
||||
}
|
||||
}
|
||||
|
||||
// TestPerformBuildFails runs builds that fail against a fake Docker API and
|
||||
// checks that each returns its own error and that no image is inspected
|
||||
// afterwards.
|
||||
func TestPerformBuildFails(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
engine string // Docker Engine version the fake daemon reports
|
||||
apiVersion string // API version the fake daemon reports
|
||||
buildOutput string
|
||||
wantErr string
|
||||
}{
|
||||
{
|
||||
name: "build step fails",
|
||||
engine: "27.3.1",
|
||||
apiVersion: "1.47",
|
||||
buildOutput: `{"stream":"Step 1/1 : RUN false\n"}` + "\n" +
|
||||
`{"errorDetail":{"message":"exit code: 1"},"error":"exit code: 1"}`,
|
||||
wantErr: "exit code: 1",
|
||||
},
|
||||
{
|
||||
name: "daemon too old for BuildKit",
|
||||
engine: "18.06.3-ce",
|
||||
apiVersion: "1.38",
|
||||
wantErr: "BuildKit is unavailable on the Docker daemon: " +
|
||||
"Docker Engine 18.06.3-ce (API 1.38) is older than 18.09 (API 1.39); " +
|
||||
"upgrade Docker Engine",
|
||||
},
|
||||
{
|
||||
// The build step's own error shows the build went ahead.
|
||||
name: "daemon at API 1.39 builds",
|
||||
engine: "18.09.9",
|
||||
apiVersion: "1.39",
|
||||
buildOutput: `{"stream":"Step 1/1 : RUN false\n"}` + "\n" +
|
||||
`{"errorDetail":{"message":"exit code: 1"},"error":"exit code: 1"}`,
|
||||
wantErr: "exit code: 1",
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
srv := httptest.NewServer(http.HandlerFunc(
|
||||
func(w http.ResponseWriter, r *http.Request) {
|
||||
switch {
|
||||
case strings.HasSuffix(r.URL.Path, "/version"):
|
||||
_, _ = fmt.Fprintf(w, `{"Version":%q,"ApiVersion":%q}`,
|
||||
tt.engine, tt.apiVersion)
|
||||
case strings.HasSuffix(r.URL.Path, "/build"):
|
||||
_, _ = w.Write([]byte(tt.buildOutput))
|
||||
default:
|
||||
t.Errorf("unexpected request to %s", r.URL.Path)
|
||||
}
|
||||
},
|
||||
))
|
||||
t.Cleanup(srv.Close)
|
||||
|
||||
dockerAPI, err := client.NewClientWithOpts(
|
||||
client.WithHost("tcp://" + srv.Listener.Addr().String()),
|
||||
)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
c := &Client{docker: dockerAPI, log: slog.Default()}
|
||||
|
||||
_, err = c.performBuild(t.Context(), BuildImageOptions{
|
||||
ContextDir: t.TempDir(),
|
||||
Tags: []string{"upaas-test:1"},
|
||||
})
|
||||
if err == nil || err.Error() != tt.wantErr {
|
||||
t.Errorf("got error %v, want %q", err, tt.wantErr)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
@@ -28,7 +28,7 @@ const (
|
||||
// recentDeploymentsLimit is the number of recent deployments to show.
|
||||
recentDeploymentsLimit = 5
|
||||
// deploymentsHistoryLimit is the number of deployments to show in history.
|
||||
deploymentsHistoryLimit = 10
|
||||
deploymentsHistoryLimit = 50
|
||||
)
|
||||
|
||||
// redirectToApp issues a SeeOther redirect to the page for the given
|
||||
|
||||
@@ -1,46 +0,0 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
"sneak.berlin/go/upaas/internal/service/app"
|
||||
)
|
||||
|
||||
// TestAppPageTitleShowsBranch checks that an app's branch can be read from
|
||||
// the app page title, next to the status badge, without opening the edit page.
|
||||
func TestAppPageTitleShowsBranch(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
testCtx := setupTestHandlers(t)
|
||||
|
||||
createdApp, err := testCtx.appSvc.CreateApp(t.Context(), app.CreateAppInput{
|
||||
Name: "branch-shown-app",
|
||||
RepoURL: "git@example.com:user/branch-shown-app.git",
|
||||
Branch: "staging",
|
||||
})
|
||||
require.NoError(t, err)
|
||||
|
||||
request := httptest.NewRequestWithContext(
|
||||
t.Context(), http.MethodGet, "/apps/"+createdApp.ID, nil,
|
||||
)
|
||||
request = addChiURLParams(request, map[string]string{"id": createdApp.ID})
|
||||
recorder := httptest.NewRecorder()
|
||||
|
||||
testCtx.handlers.HandleAppDetail().ServeHTTP(recorder, request)
|
||||
|
||||
require.Equal(t, http.StatusOK, recorder.Code)
|
||||
|
||||
// The title row runs from the app name heading to the end of its div.
|
||||
_, afterHeading, found := strings.Cut(recorder.Body.String(), "<h1")
|
||||
require.True(t, found, "app page has no heading")
|
||||
|
||||
titleRow, _, _ := strings.Cut(afterHeading, "</div>")
|
||||
assert.Contains(t, titleRow, `x-text="statusLabel"`)
|
||||
assert.Contains(t, titleRow, ">staging</span>")
|
||||
}
|
||||
@@ -1,76 +0,0 @@
|
||||
package handlers_test
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
"sneak.berlin/go/upaas/internal/service/app"
|
||||
)
|
||||
|
||||
// TestAppPageLayout checks the app page's width, the order of its sections,
|
||||
// and the height of its two log boxes.
|
||||
func TestAppPageLayout(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
testCtx := setupTestHandlers(t)
|
||||
|
||||
createdApp, err := testCtx.appSvc.CreateApp(t.Context(), app.CreateAppInput{
|
||||
Name: "layout-app",
|
||||
RepoURL: "git@example.com:user/layout-app.git",
|
||||
})
|
||||
require.NoError(t, err)
|
||||
|
||||
request := httptest.NewRequestWithContext(
|
||||
t.Context(), http.MethodGet, "/apps/"+createdApp.ID, nil,
|
||||
)
|
||||
request = addChiURLParams(request, map[string]string{"id": createdApp.ID})
|
||||
recorder := httptest.NewRecorder()
|
||||
|
||||
testCtx.handlers.HandleAppDetail().ServeHTTP(recorder, request)
|
||||
|
||||
require.Equal(t, http.StatusOK, recorder.Code)
|
||||
|
||||
body := recorder.Body.String()
|
||||
|
||||
_, afterMain, found := strings.Cut(body, "<main")
|
||||
require.True(t, found, "app page has no main element")
|
||||
|
||||
mainTag, _, _ := strings.Cut(afterMain, ">")
|
||||
assert.Contains(t, mainTag, "max-width: 84rem;")
|
||||
|
||||
sectionTitles := []string{
|
||||
"Container Logs",
|
||||
"Deploy Key",
|
||||
"Webhook URL",
|
||||
"Last Deployment Build Logs",
|
||||
"Environment Variables",
|
||||
"Docker Labels",
|
||||
"Volume Mounts",
|
||||
"Port Mappings",
|
||||
"Recent Deployments",
|
||||
"Danger Zone",
|
||||
}
|
||||
|
||||
previousIndex := -1
|
||||
|
||||
for _, title := range sectionTitles {
|
||||
index := strings.Index(body, ">"+title+"</h2>")
|
||||
require.NotEqual(t, -1, index, "app page has no %q section", title)
|
||||
assert.Greater(t, index, previousIndex, "%q section is out of order", title)
|
||||
|
||||
previousIndex = index
|
||||
}
|
||||
|
||||
for _, logBox := range []string{"containerLogsWrapper", "buildLogsWrapper"} {
|
||||
_, afterRef, found := strings.Cut(body, `x-ref="`+logBox+`"`)
|
||||
require.True(t, found, "app page has no %s", logBox)
|
||||
|
||||
logBoxTag, _, _ := strings.Cut(afterRef, ">")
|
||||
assert.Contains(t, logBoxTag, "max-height: 800px;", logBox)
|
||||
}
|
||||
}
|
||||
@@ -8,7 +8,6 @@ import (
|
||||
"strconv"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/go-chi/chi/v5"
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -1149,73 +1148,6 @@ func TestHandleCancelDeployReturns404ForUnknownApp(t *testing.T) {
|
||||
assert.Equal(t, http.StatusNotFound, recorder.Code)
|
||||
}
|
||||
|
||||
// TestHandleAppDeploymentsShowsTenNewest verifies the deployments page
|
||||
// lists only the 10 most recent deployments, newest first.
|
||||
func TestHandleAppDeploymentsShowsTenNewest(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
testCtx := setupTestHandlers(t)
|
||||
createdApp := createTestApp(t, testCtx, "deployments-page-app")
|
||||
|
||||
// Create 12 deployments, each started one minute after the one before.
|
||||
firstStart := time.Date(2026, 1, 1, 0, 0, 0, 0, time.UTC)
|
||||
|
||||
ids := make([]int64, 0, 12)
|
||||
|
||||
for idx := range 12 {
|
||||
deployment := models.NewDeployment(testCtx.database)
|
||||
deployment.AppID = createdApp.ID
|
||||
deployment.Status = models.DeploymentStatusSuccess
|
||||
require.NoError(t, deployment.Save(context.Background()))
|
||||
|
||||
_, err := testCtx.database.Exec(
|
||||
context.Background(),
|
||||
"UPDATE deployments SET started_at = ? WHERE id = ?",
|
||||
firstStart.Add(time.Duration(idx)*time.Minute),
|
||||
deployment.ID,
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
ids = append(ids, deployment.ID)
|
||||
}
|
||||
|
||||
request := httptest.NewRequestWithContext(
|
||||
t.Context(),
|
||||
http.MethodGet,
|
||||
"/apps/"+createdApp.ID+"/deployments",
|
||||
nil,
|
||||
)
|
||||
request = addChiURLParams(request, map[string]string{"id": createdApp.ID})
|
||||
recorder := httptest.NewRecorder()
|
||||
|
||||
handler := testCtx.handlers.HandleAppDeployments()
|
||||
handler.ServeHTTP(recorder, request)
|
||||
|
||||
require.Equal(t, http.StatusOK, recorder.Code)
|
||||
|
||||
body := recorder.Body.String()
|
||||
card := func(id int64) string {
|
||||
return `data-deployment-id="` + strconv.FormatInt(id, 10) + `"`
|
||||
}
|
||||
|
||||
assert.Equal(t, 10, strings.Count(body, `data-deployment-id="`))
|
||||
|
||||
// The two oldest are left out.
|
||||
assert.NotContains(t, body, card(ids[0]))
|
||||
assert.NotContains(t, body, card(ids[1]))
|
||||
|
||||
// The ten newest are shown, newest first.
|
||||
previous := -1
|
||||
|
||||
for idx := len(ids) - 1; idx >= 2; idx-- {
|
||||
position := strings.Index(body, card(ids[idx]))
|
||||
require.Greater(t, position, previous,
|
||||
"deployment %d missing or out of order", ids[idx])
|
||||
|
||||
previous = position
|
||||
}
|
||||
}
|
||||
|
||||
func TestHandleWebhookReturns404ForUnknownSecret(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
@@ -923,6 +923,7 @@ func (svc *Service) buildImage(
|
||||
|
||||
// Create log writer that flushes build output to deployment logs every second
|
||||
logWriter := newDeploymentLogWriter(ctx, deployment)
|
||||
defer logWriter.Close()
|
||||
|
||||
// BuildImage creates a tar archive from the local filesystem,
|
||||
// so it needs the container path where files exist, not the host path.
|
||||
@@ -932,10 +933,6 @@ func (svc *Service) buildImage(
|
||||
Tags: []string{imageTag},
|
||||
LogWriter: logWriter,
|
||||
})
|
||||
|
||||
// Write the rest of the build output to the log before the result.
|
||||
logWriter.Close()
|
||||
|
||||
if err != nil {
|
||||
svc.notify.NotifyBuildFailed(ctx, app, deployment, err)
|
||||
svc.failDeployment(
|
||||
|
||||
@@ -1,91 +0,0 @@
|
||||
package deploy_test
|
||||
|
||||
import (
|
||||
"context"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"go.uber.org/fx/fxtest"
|
||||
|
||||
"sneak.berlin/go/upaas/internal/config"
|
||||
"sneak.berlin/go/upaas/internal/database"
|
||||
"sneak.berlin/go/upaas/internal/docker"
|
||||
"sneak.berlin/go/upaas/internal/logger"
|
||||
"sneak.berlin/go/upaas/internal/models"
|
||||
"sneak.berlin/go/upaas/internal/service/deploy"
|
||||
)
|
||||
|
||||
// TestBuildImageLogsBuildErrorBeforeDeployError runs a build that fails
|
||||
// against a fake Docker API and checks that the deploy fails with the
|
||||
// build's own error, which the deployment log shows before the deploy's.
|
||||
func TestBuildImageLogsBuildErrorBeforeDeployError(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
srv := httptest.NewServer(http.HandlerFunc(
|
||||
func(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
|
||||
switch {
|
||||
case strings.HasSuffix(r.URL.Path, "/containers/create"):
|
||||
_, _ = w.Write([]byte(`{"Id":"gitcontainer"}`))
|
||||
case strings.HasSuffix(r.URL.Path, "/version"):
|
||||
_, _ = w.Write([]byte(`{"Version":"27.3.1","ApiVersion":"1.47"}`))
|
||||
case strings.HasSuffix(r.URL.Path, "/build"):
|
||||
_, _ = w.Write([]byte(`{"stream":"Step 1/1 : RUN false\n"}` + "\n" +
|
||||
`{"errorDetail":{"message":"exit code: 1"},"error":"exit code: 1"}`))
|
||||
default:
|
||||
// The steps of the git clone, which succeeds.
|
||||
_, _ = w.Write([]byte(`{}`))
|
||||
}
|
||||
},
|
||||
))
|
||||
t.Cleanup(srv.Close)
|
||||
|
||||
log := slog.New(slog.NewTextHandler(os.Stderr, nil))
|
||||
lifecycle := fxtest.NewLifecycle(t)
|
||||
|
||||
dockerClient, err := docker.New(lifecycle, docker.Params{
|
||||
Logger: logger.NewForTest(log),
|
||||
Config: &config.Config{DockerHost: "tcp://" + srv.Listener.Addr().String()},
|
||||
})
|
||||
require.NoError(t, err)
|
||||
|
||||
lifecycle.RequireStart()
|
||||
t.Cleanup(lifecycle.RequireStop)
|
||||
|
||||
db := database.NewTestDatabase(t)
|
||||
ctx := context.Background()
|
||||
|
||||
app := models.NewApp(db)
|
||||
app.ID = "buildapp-id"
|
||||
app.Name = "buildapp"
|
||||
app.Branch = "main"
|
||||
require.NoError(t, app.Save(ctx))
|
||||
|
||||
deployment := models.NewDeployment(db)
|
||||
deployment.AppID = app.ID
|
||||
require.NoError(t, deployment.Save(ctx))
|
||||
|
||||
dataDir := t.TempDir()
|
||||
cfg := &config.Config{DataDir: dataDir, HostDataDir: dataDir}
|
||||
|
||||
// The service has no notify service: the app has no ntfy topic and no
|
||||
// Slack webhook, so the build failure notification sends nothing.
|
||||
svc := deploy.NewTestServiceWithConfig(log, cfg, dockerClient)
|
||||
|
||||
_, err = svc.BuildImage(ctx, app, deployment)
|
||||
require.EqualError(t, err, "failed to build image: exit code: 1")
|
||||
|
||||
logs := deployment.Logs.String
|
||||
buildError := strings.Index(logs, "ERROR: exit code: 1")
|
||||
deployError := strings.Index(logs, "ERROR: failed to build image: exit code: 1")
|
||||
|
||||
require.NotEqual(t, -1, buildError, logs)
|
||||
assert.Less(t, buildError, deployError, logs)
|
||||
}
|
||||
@@ -100,15 +100,6 @@ func (svc *Service) RecordDeployedImage(
|
||||
return svc.recordDeployedImage(ctx, app, deployment, imageID)
|
||||
}
|
||||
|
||||
// BuildImage exposes buildImage for testing.
|
||||
func (svc *Service) BuildImage(
|
||||
ctx context.Context,
|
||||
app *models.App,
|
||||
deployment *models.Deployment,
|
||||
) (docker.ImageID, error) {
|
||||
return svc.buildImage(ctx, app, deployment)
|
||||
}
|
||||
|
||||
// BuildContainerOptionsExported exposes buildContainerOptions for testing.
|
||||
func (svc *Service) BuildContainerOptionsExported(
|
||||
ctx context.Context,
|
||||
|
||||
+43
-44
@@ -5,7 +5,7 @@
|
||||
{{define "content"}}
|
||||
{{template "nav" .}}
|
||||
|
||||
<main class="mx-auto px-4 py-8" style="max-width: 84rem;" x-data="appDetail({
|
||||
<main class="max-w-4xl mx-auto px-4 py-8" x-data="appDetail({
|
||||
appId: '{{.App.ID}}',
|
||||
initialDeploymentId: {{if .LatestDeployment}}{{.LatestDeployment.ID}}{{else}}null{{end}},
|
||||
initialStatus: '{{.App.Status}}',
|
||||
@@ -26,12 +26,11 @@
|
||||
<!-- Header -->
|
||||
<div class="flex flex-col sm:flex-row sm:items-center sm:justify-between gap-4 mb-8">
|
||||
<div>
|
||||
<div class="flex flex-wrap items-center gap-3">
|
||||
<div class="flex items-center gap-3">
|
||||
<h1 class="text-2xl font-medium text-gray-900">{{.App.Name}}</h1>
|
||||
<span x-bind:class="statusBadgeClass" x-text="statusLabel"></span>
|
||||
<span class="badge-neutral font-mono break-all" title="Branch">{{.App.Branch}}</span>
|
||||
</div>
|
||||
<p class="text-gray-500 font-mono text-sm mt-1">{{.App.RepoURL}}</p>
|
||||
<p class="text-gray-500 font-mono text-sm mt-1">{{.App.RepoURL}}@{{.App.Branch}}</p>
|
||||
</div>
|
||||
<div class="flex gap-3">
|
||||
<a href="/apps/{{.App.ID}}/edit" class="btn-secondary">Edit</a>
|
||||
@@ -54,26 +53,6 @@
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Container Logs -->
|
||||
<div class="card p-6 mb-6">
|
||||
<div class="flex items-center justify-between mb-4">
|
||||
<h2 class="section-title">Container Logs</h2>
|
||||
<span x-bind:class="containerStatusBadgeClass" x-text="containerStatusLabel"></span>
|
||||
</div>
|
||||
<div class="relative">
|
||||
<div x-ref="containerLogsWrapper" class="bg-gray-900 rounded-lg p-4 overflow-y-auto" style="max-height: 800px;">
|
||||
<pre class="text-gray-100 text-xs font-mono whitespace-pre-wrap break-words m-0" x-text="containerLogs"></pre>
|
||||
</div>
|
||||
<button
|
||||
x-show="!_containerAutoScroll"
|
||||
x-transition
|
||||
@click="_containerAutoScroll = true; Alpine.store('utils').scrollToBottom($refs.containerLogsWrapper)"
|
||||
class="absolute bottom-2 right-4 bg-primary-600 hover:bg-primary-700 text-white text-xs px-3 py-1 rounded-full shadow-lg opacity-90 hover:opacity-100 transition"
|
||||
title="Scroll to bottom"
|
||||
>↓ Follow</button>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Deploy Key -->
|
||||
<div class="card p-6 mb-6">
|
||||
<h2 class="section-title mb-4">Deploy Key</h2>
|
||||
@@ -121,26 +100,6 @@
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Last Deployment Build Logs -->
|
||||
<div class="card p-6 mb-6" x-show="showBuildLogs" x-cloak>
|
||||
<div class="flex items-center justify-between mb-4">
|
||||
<h2 class="section-title">Last Deployment Build Logs</h2>
|
||||
<span x-bind:class="buildStatusBadgeClass" x-text="buildStatusLabel"></span>
|
||||
</div>
|
||||
<div class="relative">
|
||||
<div x-ref="buildLogsWrapper" class="bg-gray-900 rounded-lg p-4 overflow-y-auto" style="max-height: 800px;">
|
||||
<pre class="text-gray-100 text-xs font-mono whitespace-pre-wrap break-words m-0" x-text="buildLogs"></pre>
|
||||
</div>
|
||||
<button
|
||||
x-show="!_buildAutoScroll"
|
||||
x-transition
|
||||
@click="_buildAutoScroll = true; Alpine.store('utils').scrollToBottom($refs.buildLogsWrapper)"
|
||||
class="absolute bottom-2 right-4 bg-primary-600 hover:bg-primary-700 text-white text-xs px-3 py-1 rounded-full shadow-lg opacity-90 hover:opacity-100 transition"
|
||||
title="Scroll to bottom"
|
||||
>↓ Follow</button>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Environment Variables -->
|
||||
<div class="card p-6 mb-6" x-data="envVarEditor('{{.App.ID}}')">
|
||||
<h2 class="section-title mb-4">Environment Variables</h2>
|
||||
@@ -394,6 +353,26 @@
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<!-- Container Logs -->
|
||||
<div class="card p-6 mb-6">
|
||||
<div class="flex items-center justify-between mb-4">
|
||||
<h2 class="section-title">Container Logs</h2>
|
||||
<span x-bind:class="containerStatusBadgeClass" x-text="containerStatusLabel"></span>
|
||||
</div>
|
||||
<div class="relative">
|
||||
<div x-ref="containerLogsWrapper" class="bg-gray-900 rounded-lg p-4 overflow-y-auto" style="max-height: 400px;">
|
||||
<pre class="text-gray-100 text-xs font-mono whitespace-pre-wrap break-words m-0" x-text="containerLogs"></pre>
|
||||
</div>
|
||||
<button
|
||||
x-show="!_containerAutoScroll"
|
||||
x-transition
|
||||
@click="_containerAutoScroll = true; Alpine.store('utils').scrollToBottom($refs.containerLogsWrapper)"
|
||||
class="absolute bottom-2 right-4 bg-primary-600 hover:bg-primary-700 text-white text-xs px-3 py-1 rounded-full shadow-lg opacity-90 hover:opacity-100 transition"
|
||||
title="Scroll to bottom"
|
||||
>↓ Follow</button>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Recent Deployments -->
|
||||
<div class="card p-6 mb-6">
|
||||
<div class="flex items-center justify-between mb-4">
|
||||
@@ -433,6 +412,26 @@
|
||||
</template>
|
||||
</div>
|
||||
|
||||
<!-- Last Deployment Build Logs -->
|
||||
<div class="card p-6 mb-6" x-show="showBuildLogs" x-cloak>
|
||||
<div class="flex items-center justify-between mb-4">
|
||||
<h2 class="section-title">Last Deployment Build Logs</h2>
|
||||
<span x-bind:class="buildStatusBadgeClass" x-text="buildStatusLabel"></span>
|
||||
</div>
|
||||
<div class="relative">
|
||||
<div x-ref="buildLogsWrapper" class="bg-gray-900 rounded-lg p-4 overflow-y-auto" style="max-height: 400px;">
|
||||
<pre class="text-gray-100 text-xs font-mono whitespace-pre-wrap break-words m-0" x-text="buildLogs"></pre>
|
||||
</div>
|
||||
<button
|
||||
x-show="!_buildAutoScroll"
|
||||
x-transition
|
||||
@click="_buildAutoScroll = true; Alpine.store('utils').scrollToBottom($refs.buildLogsWrapper)"
|
||||
class="absolute bottom-2 right-4 bg-primary-600 hover:bg-primary-700 text-white text-xs px-3 py-1 rounded-full shadow-lg opacity-90 hover:opacity-100 transition"
|
||||
title="Scroll to bottom"
|
||||
>↓ Follow</button>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Danger Zone -->
|
||||
<div class="card border-2 border-error-500/20 bg-error-50/50 p-6">
|
||||
<h2 class="text-lg font-medium text-error-700 mb-4">Danger Zone</h2>
|
||||
|
||||
Reference in New Issue
Block a user