mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 21:37:50 +08:00
fix(all): various fixes (#537)
This commit is contained in:
@@ -23,6 +23,12 @@ jobs:
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
# Advisory only — this runs against origin/main at PR time, so a branch
|
||||
# that goes stale after a migration re-date on main slips past it; the
|
||||
# deploy workflow's gate is the authoritative check.
|
||||
- name: Migration ordering vs main
|
||||
run: .mise/tasks/yucca-api/check-migration-order origin/main
|
||||
|
||||
- name: Setup Mise
|
||||
uses: immich-app/devtools/actions/use-mise@cd24790a7f5f6439ac32cc94f5523cb2de8bfa8c # use-mise-action-v1.1.0
|
||||
env:
|
||||
|
||||
@@ -20,11 +20,27 @@ env:
|
||||
BUILD_TAG: 0.0.${{ github.run_number }}
|
||||
|
||||
jobs:
|
||||
# A migration that sorts before one already executed makes every yucca-api /
|
||||
# yucca-admin-api pod crashloop at boot (Kysely refuses the whole set), and
|
||||
# the stale-branch case escapes PR CI — checks don't re-run when main moves
|
||||
# (incident: #492 merged after #510's re-date). Gate the build on HEAD^ so a
|
||||
# bad merge stops here instead of rolling out.
|
||||
migration-order:
|
||||
name: Migration ordering gate
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
with:
|
||||
persist-credentials: false
|
||||
fetch-depth: 2
|
||||
- run: .mise/tasks/yucca-api/check-migration-order HEAD^
|
||||
|
||||
# ── Build + push every app image (the ONLY delivery action CI performs) ──
|
||||
# Release commits build like any other — they're the stamped tree the release
|
||||
# tag points at, and they additionally push v<version> image tags (below).
|
||||
build:
|
||||
name: Build ${{ matrix.app.name }}
|
||||
needs: migration-order
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
Executable
+25
@@ -0,0 +1,25 @@
|
||||
#!/usr/bin/env bash
|
||||
#MISE description="Fail if a new migration sorts before one already present on the base ref"
|
||||
set -euo pipefail
|
||||
|
||||
base="${1:-origin/main}"
|
||||
dir=packages/yucca-api/src/schema/migrations
|
||||
|
||||
if ! git rev-parse -q --verify "$base^{commit}" >/dev/null 2>&1; then
|
||||
git fetch -q --depth=1 origin main
|
||||
fi
|
||||
|
||||
base_files=$(git ls-tree -r --name-only "$base" -- "$dir" | sed 's|.*/||' | sort)
|
||||
head_files=$(ls "$dir" | sort)
|
||||
|
||||
last_common=$(comm -12 <(echo "$base_files") <(echo "$head_files") | tail -1)
|
||||
new_files=$(comm -13 <(echo "$base_files") <(echo "$head_files"))
|
||||
if [ -z "$new_files" ] || [ -z "$last_common" ]; then exit 0; fi
|
||||
|
||||
bad=$(awk -v m="$last_common" '$0 <= m' <<<"$new_files")
|
||||
if [ -n "$bad" ]; then
|
||||
echo "migration(s) sort before $last_common, which $base already has (Kysely will refuse to run):" >&2
|
||||
sed 's/^/ /' <<<"$bad" >&2
|
||||
echo "re-date them after $last_common (see PRs #510, #535)." >&2
|
||||
exit 1
|
||||
fi
|
||||
@@ -80,7 +80,7 @@ data:
|
||||
|
||||
# From header for invite/transactional email (must match a Postmark-verified
|
||||
# sender signature).
|
||||
EMAIL_FROM_ADDRESS: "FUTO Backups <noreply@backups.futo.cloud>"
|
||||
EMAIL_FROM_ADDRESS: "FUTO Backups <noreply@futo.cloud>"
|
||||
|
||||
# ─── OpenEBS (shared apps/base/openebs, see the father openebs wrapper) ──
|
||||
# Mayastor ON: openebs-replicated (repl=2) on the r-mayastor partitions.
|
||||
|
||||
@@ -42,10 +42,9 @@ export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_staging/CUSTOMER_ZITADE
|
||||
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
|
||||
export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
|
||||
|
||||
# Postmark server token for invite/transactional email. Mint the 1P item, then
|
||||
# uncomment; while commented the TF var defaults to "" and admin-api logs and
|
||||
# skips sends (docs/email.md).
|
||||
# export TF_VAR_yucca_postmark_server_token="op://yucca_tf_staging/POSTMARK_SERVER_TOKEN/password"
|
||||
# Postmark server token for invite/transactional email (docs/email.md); one
|
||||
# server token in yucca_tf serves staging + prod.
|
||||
export TF_VAR_yucca_postmark_server_token="op://yucca_tf/POSTMARK_API_TOKEN/password"
|
||||
|
||||
# michael RGW (S3) creds — the `svc-yucca-restic` user created by the ceph
|
||||
# Ansible (sietch / dev Ceph); duplicated into yucca_tf_staging for the SA.
|
||||
|
||||
+3
-4
@@ -63,10 +63,9 @@ export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_prod/CUSTOMER_ZITADEL_O
|
||||
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
|
||||
export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
|
||||
|
||||
# Postmark server token for invite/transactional email. Mint the 1P item, then
|
||||
# uncomment; while commented the TF var defaults to "" and admin-api logs and
|
||||
# skips sends (docs/email.md).
|
||||
# export TF_VAR_yucca_postmark_server_token="op://yucca_tf_prod/POSTMARK_SERVER_TOKEN/password"
|
||||
# Postmark server token for invite/transactional email (docs/email.md); one
|
||||
# server token in yucca_tf serves staging + prod.
|
||||
export TF_VAR_yucca_postmark_server_token="op://yucca_tf/POSTMARK_API_TOKEN/password"
|
||||
|
||||
# michael → spice RGW (svc-yucca-restic, out-of-band contract items).
|
||||
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"
|
||||
|
||||
Reference in New Issue
Block a user