From f7e0df15e39810c0c223dd75eaebd0ef3be19b1a Mon Sep 17 00:00:00 2001 From: taylanbakircioglu Date: Thu, 14 May 2026 00:08:18 +0300 Subject: [PATCH] ci(release): stage version.json into backend build context (drift fix) The backend Docker image is built with `context: ./backend`, so the repo-root `version.json` is outside the build context and never reaches the container. Backend `main.py` falls back to a compile- time `_version_info` constant when `/app/version.json` is missing. In practice this produced a real production drift: a successful redeploy of the v1.5.2 tree silently reported `"v1.5.0"` in `/api/version` for a window of releases because the constant in main.py had not been bumped in lockstep with `version.json`, and the canonical file was never available to read inside the container. Fix is workflow-only: * New "stage version.json into backend build context" step (between `read product version` and `set up qemu`) that runs `cp version.json backend/version.json` so the next `docker buildx build` includes it. * `.gitignore` entry for `backend/version.json` keeps `git status` clean for developers (the canonical file remains at repo root; `backend/version.json` is a transient CI artefact). Backend reading logic is unchanged: the loop in `main.py` first tries `/app/version.json`, then falls back to the constant. Post-fix, the first path WILL find the file and produce the correct response; the constant becomes a pure defensive fallback (rather than the production hot path it accidentally became). No code or test changes needed: existing tests assert against the `_version_info` dict regardless of whether it was populated from JSON or the fallback constant. --- .github/workflows/docker-build.yml | 14 ++++++++++++++ .gitignore | 5 +++++ 2 files changed, 19 insertions(+) diff --git a/.github/workflows/docker-build.yml b/.github/workflows/docker-build.yml index b503306..5d9d542 100644 --- a/.github/workflows/docker-build.yml +++ b/.github/workflows/docker-build.yml @@ -26,6 +26,20 @@ jobs: fi echo "VERSION=$VERSION" >> $GITHUB_OUTPUT + # The backend image is built with `context: ./backend`, so the + # repo-root version.json is OUTSIDE the build context and never + # reaches the container. Backend `main.py` falls back to a + # compile-time constant when /app/version.json is missing, which + # caused a real production drift: a redeploy of the v1.5.2 tree + # silently still reported "v1.5.0" in `/api/version` because the + # constant in main.py had been bumped but the file was not + # available to read. Stage version.json into the backend + # context here so the canonical file IS shipped and the + # constant only serves as a defensive fallback. The staged file + # is gitignored to keep `git status` clean for developers. + - name: stage version.json into backend build context + run: cp version.json backend/version.json + - name: set up qemu uses: docker/setup-qemu-action@v3 diff --git a/.gitignore b/.gitignore index 15e1747..5f10a6c 100644 --- a/.gitignore +++ b/.gitignore @@ -42,6 +42,11 @@ venv.bak/ # Docker .dockerignore +# Build-time staged version.json (CI `cp version.json backend/`). +# The canonical file lives at repo root; this path is a transient +# copy for the backend Docker build context. +backend/version.json + # IDE .vscode/ .idea/