Tag built images with the commit short hash instead of the deployment number #239

Open
opened 2026-09-29 11:24:43 +02:00 by clawbot · 2 comments
Collaborator

sneak, 2026-09-29 in chat (verbatim):

upaas should use the commit short hash as the docker build tag instead of an incrementing integer

Today buildImage tags each build upaas-<app>:<deployment ID> (internal/service/deploy/deploy.go, fmt.Sprintf("upaas-%s:%d", app.Name, deployment.ID)), e.g. upaas-webhook:140. The deployed commit is known by then (the clone step records it).

Definition of done:

  • Each build is tagged upaas-<app>:<short hash>, the short hash being git's own short form of the commit that was checked out and built (git rev-parse --short).
  • Redeploying a commit that already has an image works, and leaves no untagged image behind: the old image with that tag is removed by the existing cleanup unless the running container or rollback still needs it.
  • Rollback and the removal of unused images keep working with the new tags; their tests are updated and still meaningful.
  • The deploy log and anything that shows the image tag show the new one.

Model: opus-5-5

sneak, 2026-09-29 in chat (verbatim): > upaas should use the commit short hash as the docker build tag instead of an incrementing integer Today `buildImage` tags each build `upaas-<app>:<deployment ID>` (`internal/service/deploy/deploy.go`, `fmt.Sprintf("upaas-%s:%d", app.Name, deployment.ID)`), e.g. `upaas-webhook:140`. The deployed commit is known by then (the clone step records it). Definition of done: - Each build is tagged `upaas-<app>:<short hash>`, the short hash being git's own short form of the commit that was checked out and built (`git rev-parse --short`). - Redeploying a commit that already has an image works, and leaves no untagged image behind: the old image with that tag is removed by the existing cleanup unless the running container or rollback still needs it. - Rollback and the removal of unused images keep working with the new tags; their tests are updated and still meaningful. - The deploy log and anything that shows the image tag show the new one. Model: opus-5-5
clawbot self-assigned this 2026-09-29 11:24:43 +02:00
Author
Collaborator

Plan. This waits for #234 to reach next, since both change buildImage in internal/service/deploy/deploy.go.

  • The tag is upaas-<app>:<short hash>. Take the short hash from git in the clone step, next to where it already reads the full commit (CloneResult in internal/docker/client.go), as git rev-parse --short HEAD. Git lengthens the short form when it would be ambiguous, so do not cut the full hash to 7 characters.
  • Redeploying the same commit moves the tag to the new build. The image that loses the tag must not be left untagged and unmanaged. removeUnusedImages only sees tagged images, so an untagged one is never removed. If it is neither the running image nor the rollback image, remove it. If it is one of those, it must stay removable once it is no longer needed. Pick the plainest way and say which in the PR.
  • Rollback and old-image removal work by image ID and by listing upaas-<app>:*, so tags from before the change (upaas-<app>:140) are still removed. Update the comments that describe the tag as upaas-<app>:<deployment>, and the tests that assume numeric tags. Add a test for redeploying the same commit.
  • The deploy log and anything else that shows the tag show the new one.

Model: opus-5-5

Plan. This waits for https://git.eeqj.de/sneak/upaas/issues/234 to reach `next`, since both change `buildImage` in `internal/service/deploy/deploy.go`. - The tag is `upaas-<app>:<short hash>`. Take the short hash from git in the clone step, next to where it already reads the full commit (`CloneResult` in `internal/docker/client.go`), as `git rev-parse --short HEAD`. Git lengthens the short form when it would be ambiguous, so do not cut the full hash to 7 characters. - Redeploying the same commit moves the tag to the new build. The image that loses the tag must not be left untagged and unmanaged. `removeUnusedImages` only sees tagged images, so an untagged one is never removed. If it is neither the running image nor the rollback image, remove it. If it is one of those, it must stay removable once it is no longer needed. Pick the plainest way and say which in the PR. - Rollback and old-image removal work by image ID and by listing `upaas-<app>:*`, so tags from before the change (`upaas-<app>:140`) are still removed. Update the comments that describe the tag as `upaas-<app>:<deployment>`, and the tests that assume numeric tags. Add a test for redeploying the same commit. - The deploy log and anything else that shows the tag show the new one. Model: opus-5-5
Author
Collaborator

Built in #250. On a redeploy of the same commit, the image that loses the tag is kept while the app runs it or would roll back to it, then removed by its ID, found among the image IDs the app's deployments recorded.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/upaas/pulls/250. On a redeploy of the same commit, the image that loses the tag is kept while the app runs it or would roll back to it, then removed by its ID, found among the image IDs the app's deployments recorded. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/upaas#239