fix(hrafn-ci): make the deploy converge instead of accrete
The first CI run shipped clean but revealed a design gap in the playbook: unpacking the context tarball in place overwrites tracked files and never removes anything. Leftovers from the pre-CI hand-rsync (tests/, docs/, ROADMAP.md, persistent-memory.md, CLAUDE.md, LICENSE) survived the deploy and had to be cleaned off ana-docker by hand. That is the same failure class that produced the mess in the first place: a deploy that only ever adds cannot return the host to a known state. - unpack to a staging dir, then rsync --delete onto the compose dir - protect host-owned .env and .deployed by name - add .env.example to the context tarball so converge does not delete it - record in the workflow that the tar list is now AUTHORITATIVE: anything omitted is removed from the host on the next deploy Re-validated with `elway --dry-run` (9 steps, 3 verify, parses clean). Not yet in vh/hrafn -- infra-ops has no write access there, so this is offered to the repo holder rather than pushed.
This commit is contained in:
@@ -38,6 +38,15 @@ then `docker compose build && up`. Two problems, both fixed here.
|
||||
- **`.env` is never deployed.** It is host-owned, `0600`, and holds the
|
||||
bearer token. The playbook *refuses to run* if it is missing or not `0600`
|
||||
— a guard added because the file arrived at `0644` on handoff.
|
||||
- **The deploy converges, it does not accrete.** The first version unpacked
|
||||
the tarball in place, which overwrote tracked files but never removed
|
||||
anything — so leftovers from the pre-CI hand-rsync (`tests/`, `docs/`,
|
||||
`ROADMAP.md`, `persistent-memory.md`, `CLAUDE.md`, `LICENSE`) survived the
|
||||
first CI deploy and had to be cleaned off the host by hand. Now the
|
||||
tarball unpacks to a staging dir and `rsync --delete` converges the compose
|
||||
directory onto it, so a stray file cannot outlive the next deploy. The
|
||||
consequence: **the tar list in the workflow is authoritative** — anything
|
||||
omitted from it is deleted from the host, except `.env` and `.deployed`.
|
||||
|
||||
## Validation
|
||||
|
||||
|
||||
Reference in New Issue
Block a user