diff --git a/playbooks/repin-worldtree-image.yaml b/playbooks/repin-worldtree-image.yaml index 8919318..1755526 100644 --- a/playbooks/repin-worldtree-image.yaml +++ b/playbooks/repin-worldtree-image.yaml @@ -46,16 +46,27 @@ steps: shell: test -n "{{ expect_sha }}" changed_when: "false" - - name: Confirm the container is actually running the SHA we are about to pin - # Guards against a deploy landing between the operator reading the SHA - # and this playbook writing it — pinning a SHA that is NOT running would - # arm the exact hazard we are disarming, just with a different image. + - name: Confirm the tag we are about to pin resolves to the running image + # Guards against a deploy landing between reading the SHA and writing it — + # pinning a SHA that is NOT running would arm the exact hazard we are + # disarming, just with a different image. + # + # Compares IMAGE IDs, not the container's .Config.Image string. The string + # is only the tag the container was CREATED from, which can differ from + # what it actually runs: worldtree-pinned was created from `:latest` back + # when that tag pointed at 446e5807, and `:latest` has since moved. A + # string compare rejects that instance even though pinning it is correct; + # an ID compare asserts the thing we actually care about — that this tag + # names the bytes currently running. shell: | - running=$(docker inspect {{ api_container }} --format '{{.Config.Image}}') - test "$running" = "{{ registry }}:{{ expect_sha }}" || { - echo "REFUSING: {{ api_container }} runs $running, not {{ registry }}:{{ expect_sha }}" + running=$(docker inspect {{ api_container }} --format '{{.Image}}') + tagged=$(docker image inspect {{ registry }}:{{ expect_sha }} --format '{{.Id}}' 2>/dev/null) || { + echo "REFUSING: no local image tagged {{ registry }}:{{ expect_sha }} — tag it first" exit 1; } - echo "confirmed: $running" + test "$running" = "$tagged" || { + echo "REFUSING: {{ api_container }} runs $running but {{ registry }}:{{ expect_sha }} is $tagged" + exit 1; } + echo "confirmed: {{ registry }}:{{ expect_sha }} == running image $running" changed_when: "false" - name: Back up .env @@ -65,6 +76,10 @@ steps: - name: Re-pin WORLDTREE_IMAGE to the running SHA sudo: true + # Skipped when already correct, so a re-run reports OK rather than a + # phantom CHANGED — a playbook that always claims to have changed + # something trains you to stop reading the summary. + when: "! sudo grep -q '^WORLDTREE_IMAGE={{ registry }}:{{ expect_sha }}$' {{ instance_dir }}/.env" # `|` delimiter because the image reference contains slashes. shell: | grep -q '^WORLDTREE_IMAGE=' {{ instance_dir }}/.env || {