fix(hrafn-ci): make the deploy converge instead of accrete
The first CI run shipped clean but revealed a design gap in the playbook: unpacking the context tarball in place overwrites tracked files and never removes anything. Leftovers from the pre-CI hand-rsync (tests/, docs/, ROADMAP.md, persistent-memory.md, CLAUDE.md, LICENSE) survived the deploy and had to be cleaned off ana-docker by hand. That is the same failure class that produced the mess in the first place: a deploy that only ever adds cannot return the host to a known state. - unpack to a staging dir, then rsync --delete onto the compose dir - protect host-owned .env and .deployed by name - add .env.example to the context tarball so converge does not delete it - record in the workflow that the tar list is now AUTHORITATIVE: anything omitted is removed from the host on the next deploy Re-validated with `elway --dry-run` (9 steps, 3 verify, parses clean). Not yet in vh/hrafn -- infra-ops has no write access there, so this is offered to the repo holder rather than pushed.
This commit is contained in:
@@ -67,14 +67,19 @@ jobs:
|
||||
chmod 600 ~/.ssh/config
|
||||
|
||||
- name: Build the deploy context
|
||||
# Only what the Dockerfile actually consumes, plus compose.yaml.
|
||||
# Deliberately excludes tests/, docs/, persistent-memory.md,
|
||||
# ROADMAP.md, CLAUDE.md, LICENSE and .env — none of them belong
|
||||
# in a production compose directory.
|
||||
# Only what the Dockerfile actually consumes, plus compose.yaml
|
||||
# and .env.example. Deliberately excludes tests/, docs/,
|
||||
# persistent-memory.md, ROADMAP.md, CLAUDE.md, LICENSE and .env —
|
||||
# none of them belong in a production compose directory.
|
||||
#
|
||||
# This list is AUTHORITATIVE: the playbook converges the host
|
||||
# directory onto this tarball with rsync --delete, so anything
|
||||
# omitted here is removed from the host on the next deploy
|
||||
# (except the host-owned .env and .deployed).
|
||||
run: |
|
||||
mkdir -p dist
|
||||
tar czf dist/hrafn-context.tgz \
|
||||
Dockerfile compose.yaml pyproject.toml README.md src
|
||||
Dockerfile compose.yaml pyproject.toml README.md .env.example src
|
||||
echo "context contents:"
|
||||
tar tzf dist/hrafn-context.tgz
|
||||
|
||||
|
||||
Reference in New Issue
Block a user