Tag built images with the commit's short hash (closes #239) #250

Open
clawbot wants to merge 1 commits from issue-239-commit-hash-tags into next
Collaborator

Closes #239.

Builds are now tagged upaas-<app>:<short hash>, git's own short form (git rev-parse --short) of the commit the clone checked out, instead of the deployment number.

Redeploying a commit gives its tag to the new image. The old image stays while the app runs it or Rollback would start it. The removal of old images after a deploy now also finds the app's untagged images among the image IDs its deployments recorded, and removes them by ID once neither holds. Tags from before this change, such as upaas-<app>:140, are still removed by tag.

Reading the clone's output never worked: Docker puts a header before each log line, which hid the COMMIT: line. The clone now strips the headers with Docker's stdcopy.

  • Judgement call: an image is kept if any app runs it or would roll back to it, since apps that build the same commit can share an image and a redeploy can take the tag that kept it.
  • Judgement call: a clone whose output has no short hash fails the deploy.
  • Deviation: commit_sha is now saved on update. Manual deploys now read their commit and name the log file with it; unsaved, the log download would miss the file.
  • A manual deploy clones only the branch's last commit, so in a large repository git may print a shorter hash than a webhook deploy's full clone does; two such builds of one commit get different tags.
  • Partially verified: tested against the fake Docker API; only the log header format was checked on a real Docker daemon.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/upaas/issues/239. Builds are now tagged `upaas-<app>:<short hash>`, git's own short form (`git rev-parse --short`) of the commit the clone checked out, instead of the deployment number. Redeploying a commit gives its tag to the new image. The old image stays while the app runs it or Rollback would start it. The removal of old images after a deploy now also finds the app's untagged images among the image IDs its deployments recorded, and removes them by ID once neither holds. Tags from before this change, such as `upaas-<app>:140`, are still removed by tag. Reading the clone's output never worked: Docker puts a header before each log line, which hid the `COMMIT:` line. The clone now strips the headers with Docker's `stdcopy`. - Judgement call: an image is kept if any app runs it or would roll back to it, since apps that build the same commit can share an image and a redeploy can take the tag that kept it. - Judgement call: a clone whose output has no short hash fails the deploy. - Deviation: `commit_sha` is now saved on update. Manual deploys now read their commit and name the log file with it; unsaved, the log download would miss the file. - A manual deploy clones only the branch's last commit, so in a large repository git may print a shorter hash than a webhook deploy's full clone does; two such builds of one commit get different tags. - Partially verified: tested against the fake Docker API; only the log header format was checked on a real Docker daemon. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 13:18:33 +02:00
clawbot self-assigned this 2026-09-29 13:18:33 +02:00
clawbot added 1 commit 2026-09-29 13:18:34 +02:00
Builds are tagged upaas-<app>:<short hash>, git's own short form of
the commit checked out, instead of the deployment number.

A redeploy of a commit gives the tag to the new image. The cleanup
after a deploy now also finds the app's untagged images among those
its deployments recorded, and removes them by ID once the app neither
runs them nor would roll back to them. It keeps every image any app
uses, since apps that build the same commit can share one.

The clone reads the commits from git's output after removing Docker's
log headers, which had hidden the COMMIT: line; commit_sha is now
saved on update so manual deploys keep the commit they recorded.

Model: opus-5-5
All checks were successful
Check / check (pull_request) Skipped
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin issue-239-commit-hash-tags:issue-239-commit-hash-tags
git checkout issue-239-commit-hash-tags
Sign in to join this conversation.