Sync next2 into next: the four fixes from the fsn1app1 deploy rehearsal #222

Merged
clawbot merged 4 commits from next2 into next 2026-09-24 12:15:04 +02:00
Collaborator

Moves next forward to next2, so the next-to-main PR #207 carries these four fixes before sneak deploys upaas on fsn1app1 (#181). He said on 24 September that landing more reviewed work on next while 207 is open is fine.

next2 is next plus exactly these four commits, each reviewed and merged through its own PR, so this is a fast-forward with no new code:

  • #218: deploy logs stay findable after the upaas container is recreated (closes 214)
  • #217: the git clone container's anonymous volume is removed with it (closes 215)
  • #219: images from earlier deploys are removed after a successful deploy (closes 216)
  • #221: apps are built with BuildKit so build stages stop piling up (closes 220)

Model: opus-5-5

Moves `next` forward to `next2`, so the next-to-main PR https://git.eeqj.de/sneak/upaas/pulls/207 carries these four fixes before sneak deploys upaas on fsn1app1 (https://git.eeqj.de/sneak/upaas/issues/181). He said on 24 September that landing more reviewed work on `next` while 207 is open is fine. `next2` is `next` plus exactly these four commits, each reviewed and merged through its own PR, so this is a fast-forward with no new code: - https://git.eeqj.de/sneak/upaas/pulls/218: deploy logs stay findable after the upaas container is recreated (closes 214) - https://git.eeqj.de/sneak/upaas/pulls/217: the git clone container's anonymous volume is removed with it (closes 215) - https://git.eeqj.de/sneak/upaas/pulls/219: images from earlier deploys are removed after a successful deploy (closes 216) - https://git.eeqj.de/sneak/upaas/pulls/221: apps are built with BuildKit so build stages stop piling up (closes 220) Model: opus-5-5
clawbot added 4 commits 2026-09-24 12:14:28 +02:00
Deployment logs were stored under a directory named after the container's hostname, and the path was worked out again from the current hostname on download. Docker gives a recreated container a new hostname, so every older log download returned 404. New logs now go to `logs/<appname>/` with no hostname in the path. Logs written by older versions under an old hostname directory are still found by looking one directory deeper, inside the same confined log root. Tests cover both the hostname-free path and downloading an old-layout log.

Model: opus-5-5
The pinned `alpine/git` image declares a volume at `/git`, so every clone container got an anonymous volume, and the container was removed without its volumes, leaving one volume behind per deploy. The clone container is now removed together with its volumes, whether the clone succeeds, fails or is cancelled; the removal uses a context that outlives cancellation. Tests cover success, failure and cancellation against a fake Docker API, and a manual check against real Docker is recorded on the PR. The old app container's own anonymous volumes are still kept on redeploy, since deleting them could discard app data.

Model: opus-5-5
Every deploy built and tagged a new image and nothing removed the old ones, so disk use grew with each push. After a successful deploy, upaas now removes the app's old `upaas-<app>:<N>` tags by name, without force, keeping the current image and the previous one that rollback starts. Docker deletes an image only when no other tag or container still uses it, so an image shared with another app stays. A failed removal is a warning in the deployment log, not a failed deploy. The post-deploy step is one function, tested against a fake Docker API.

Judgement call: untagged images from other stages of a multi-stage build stay; they are the build cache.
On the first deploy after upgrading, all older images of that app are removed at once.

Model: opus-5-5
Multi-stage app builds left an untagged image for every build stage after each deploy, and nothing could safely remove them. upaas now asks Docker for a BuildKit build, which keeps stages in Docker's build cache instead of as images; Docker limits and cleans that cache itself. The final image is still tagged `upaas-<app>:<N>`, so old-image cleanup is unchanged. BuildKit's progress messages are decoded and written to the deployment log as plain text.

Deviation: adds `github.com/moby/buildkit` v0.16.0 (matching the pinned Docker client), added with `go get` since no make target adds dependencies.
Judgement call: the cache limit is on by default only from Docker Engine 28.2; older engines need the `daemon.json` setting the README now names.

Model: opus-5-5
clawbot merged commit a57efeed12 into next 2026-09-24 12:15:04 +02:00
Sign in to join this conversation.