fix(all): various fixes (#537)

This commit is contained in:
Antoine Lecompte
2026-08-24 13:51:25 +00:00
committed by GitHub
parent db235b2b58
commit c78ddee105
6 changed files with 54 additions and 9 deletions
+6
View File
@@ -23,6 +23,12 @@ jobs:
with:
persist-credentials: false
# Advisory only — this runs against origin/main at PR time, so a branch
# that goes stale after a migration re-date on main slips past it; the
# deploy workflow's gate is the authoritative check.
- name: Migration ordering vs main
run: .mise/tasks/yucca-api/check-migration-order origin/main
- name: Setup Mise
uses: immich-app/devtools/actions/use-mise@cd24790a7f5f6439ac32cc94f5523cb2de8bfa8c # use-mise-action-v1.1.0
env:
+16
View File
@@ -20,11 +20,27 @@ env:
BUILD_TAG: 0.0.${{ github.run_number }}
jobs:
# A migration that sorts before one already executed makes every yucca-api /
# yucca-admin-api pod crashloop at boot (Kysely refuses the whole set), and
# the stale-branch case escapes PR CI — checks don't re-run when main moves
# (incident: #492 merged after #510's re-date). Gate the build on HEAD^ so a
# bad merge stops here instead of rolling out.
migration-order:
name: Migration ordering gate
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
fetch-depth: 2
- run: .mise/tasks/yucca-api/check-migration-order HEAD^
# ── Build + push every app image (the ONLY delivery action CI performs) ──
# Release commits build like any other — they're the stamped tree the release
# tag points at, and they additionally push v<version> image tags (below).
build:
name: Build ${{ matrix.app.name }}
needs: migration-order
runs-on: ubuntu-latest
permissions:
contents: read
+25
View File
@@ -0,0 +1,25 @@
#!/usr/bin/env bash
#MISE description="Fail if a new migration sorts before one already present on the base ref"
set -euo pipefail
base="${1:-origin/main}"
dir=packages/yucca-api/src/schema/migrations
if ! git rev-parse -q --verify "$base^{commit}" >/dev/null 2>&1; then
git fetch -q --depth=1 origin main
fi
base_files=$(git ls-tree -r --name-only "$base" -- "$dir" | sed 's|.*/||' | sort)
head_files=$(ls "$dir" | sort)
last_common=$(comm -12 <(echo "$base_files") <(echo "$head_files") | tail -1)
new_files=$(comm -13 <(echo "$base_files") <(echo "$head_files"))
if [ -z "$new_files" ] || [ -z "$last_common" ]; then exit 0; fi
bad=$(awk -v m="$last_common" '$0 <= m' <<<"$new_files")
if [ -n "$bad" ]; then
echo "migration(s) sort before $last_common, which $base already has (Kysely will refuse to run):" >&2
sed 's/^/ /' <<<"$bad" >&2
echo "re-date them after $last_common (see PRs #510, #535)." >&2
exit 1
fi
@@ -80,7 +80,7 @@ data:
# From header for invite/transactional email (must match a Postmark-verified
# sender signature).
EMAIL_FROM_ADDRESS: "FUTO Backups <noreply@backups.futo.cloud>"
EMAIL_FROM_ADDRESS: "FUTO Backups <noreply@futo.cloud>"
# ─── OpenEBS (shared apps/base/openebs, see the father openebs wrapper) ──
# Mayastor ON: openebs-replicated (repl=2) on the r-mayastor partitions.
+3 -4
View File
@@ -42,10 +42,9 @@ export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_staging/CUSTOMER_ZITADE
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
# Postmark server token for invite/transactional email. Mint the 1P item, then
# uncomment; while commented the TF var defaults to "" and admin-api logs and
# skips sends (docs/email.md).
# export TF_VAR_yucca_postmark_server_token="op://yucca_tf_staging/POSTMARK_SERVER_TOKEN/password"
# Postmark server token for invite/transactional email (docs/email.md); one
# server token in yucca_tf serves staging + prod.
export TF_VAR_yucca_postmark_server_token="op://yucca_tf/POSTMARK_API_TOKEN/password"
# michael RGW (S3) creds — the `svc-yucca-restic` user created by the ceph
# Ansible (sietch / dev Ceph); duplicated into yucca_tf_staging for the SA.
+3 -4
View File
@@ -63,10 +63,9 @@ export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_prod/CUSTOMER_ZITADEL_O
export TF_VAR_yucca_oidc_admin_client_id="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_ID_YUCCA_INTERNAL_TOOLING/password"
export TF_VAR_yucca_oidc_admin_client_secret="op://shared_tf/FUTO_ZITADEL_OAUTH_CLIENT_SECRET_YUCCA_INTERNAL_TOOLING/password"
# Postmark server token for invite/transactional email. Mint the 1P item, then
# uncomment; while commented the TF var defaults to "" and admin-api logs and
# skips sends (docs/email.md).
# export TF_VAR_yucca_postmark_server_token="op://yucca_tf_prod/POSTMARK_SERVER_TOKEN/password"
# Postmark server token for invite/transactional email (docs/email.md); one
# server token in yucca_tf serves staging + prod.
export TF_VAR_yucca_postmark_server_token="op://yucca_tf/POSTMARK_API_TOKEN/password"
# michael → spice RGW (svc-yucca-restic, out-of-band contract items).
export TF_VAR_yucca_rgw_access_key_id="op://yucca_tf_prod/SPICE_CEPH_S3_SVC_YUCCA_RESTIC_ACCESS_KEY/password"