docs(hrafn-ci): mirror the now-canonical vh/hrafn pipeline; record two failed runs
claude-bot holds write on vh/hrafn as of 2026-08-23, so the canonical copy of the pipeline moved there and infra-ops maintains it directly instead of routing patches through the repo holder. The files here are a verified mirror (byte-identical to live at 22e0eb9d75a6). Live state: run 9922 green, and both new content assertions executed rather than merely existing -- verify 4/5 host tree matches shipped context (a99ce748a0c9...) verify 5/5 image source matches host source (06f209fd0641...) The CI-computed context hash matching on the host is the end-to-end proof that the converge lands what CI ships. Its absence is what let the frozen-source bug survive every green deploy. Also records why the HEAD == GITHUB_SHA assertion was added and then removed: it needed the git binary (run 9920, exit 127), and installing git flipped actions/checkout@v4 from its node implementation to the git binary, which died on a missing CA bundle (run 9921). A nice-to-have assertion changed the checkout code path and broke a working pipeline; it guarded a hypothesis that proved wrong, so it went rather than getting ca-certificates bolted on.
This commit is contained in:
@@ -36,6 +36,13 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Install playbook prerequisites
|
||||
# DO NOT add `git` here. actions/checkout@v4 uses its node
|
||||
# implementation when no git binary is present, which is what every
|
||||
# working run of this pipeline has used. Installing git flips it to
|
||||
# the git binary, and this image ships no CA bundle — the checkout
|
||||
# then dies with "server certificate verification failed. CAfile:
|
||||
# none" (run 9921). Adding ca-certificates would paper over it; not
|
||||
# installing git avoids the code-path change entirely.
|
||||
run: |
|
||||
apt-get update -qq
|
||||
apt-get install -y --no-install-recommends \
|
||||
@@ -50,16 +57,14 @@ jobs:
|
||||
# exactly the kind of drift the SHA tagging is supposed to prevent.
|
||||
clean: true
|
||||
|
||||
- name: Assert the checkout really is the triggering commit
|
||||
# Cheap, and it converts "the runner shipped stale files" from a
|
||||
# silent deploy into a failed job.
|
||||
run: |
|
||||
head=$(git rev-parse HEAD)
|
||||
echo "checkout HEAD : $head"
|
||||
echo "GITHUB_SHA : $GITHUB_SHA"
|
||||
test "$head" = "$GITHUB_SHA" || {
|
||||
echo "CHECKOUT DRIFT — refusing to deploy a tree that is not $GITHUB_SHA"
|
||||
exit 1; }
|
||||
# NO HEAD-vs-GITHUB_SHA ASSERTION. One was added here and removed: it
|
||||
# needed the git binary, whose installation broke the checkout (above),
|
||||
# and it was guarding a hypothesis that turned out to be wrong — the
|
||||
# frozen-source bug was a self-referential rsync in the playbook, not a
|
||||
# stale runner checkout. `clean: true` covers workspace reuse, and the
|
||||
# host-side content hash proves the shipped bytes landed. Adding a
|
||||
# package and a code-path change to assert a third time was not worth
|
||||
# destabilising a working checkout.
|
||||
|
||||
- name: Checkout management repo (for elway)
|
||||
uses: actions/checkout@v4
|
||||
|
||||
Reference in New Issue
Block a user