Files
haproxy-openmanager/.github/workflows/docker-build.yml
T
taylanbakircioglu f7e0df15e3 ci(release): stage version.json into backend build context (drift fix)
The backend Docker image is built with `context: ./backend`, so the
repo-root `version.json` is outside the build context and never
reaches the container. Backend `main.py` falls back to a compile-
time `_version_info` constant when `/app/version.json` is missing.

In practice this produced a real production drift: a successful
redeploy of the v1.5.2 tree silently reported `"v1.5.0"` in
`/api/version` for a window of releases because the constant in
main.py had not been bumped in lockstep with `version.json`, and
the canonical file was never available to read inside the
container.

Fix is workflow-only:
  * New "stage version.json into backend build context" step
    (between `read product version` and `set up qemu`) that runs
    `cp version.json backend/version.json` so the next
    `docker buildx build` includes it.
  * `.gitignore` entry for `backend/version.json` keeps `git status`
    clean for developers (the canonical file remains at repo root;
    `backend/version.json` is a transient CI artefact).

Backend reading logic is unchanged: the loop in `main.py` first
tries `/app/version.json`, then falls back to the constant.
Post-fix, the first path WILL find the file and produce the
correct response; the constant becomes a pure defensive fallback
(rather than the production hot path it accidentally became).

No code or test changes needed: existing tests assert against the
`_version_info` dict regardless of whether it was populated from
JSON or the fallback constant.
2026-05-14 00:08:18 +03:00

79 lines
2.8 KiB
YAML

name: build and push docker images
on:
push:
branches: ["main"]
jobs:
build_and_push:
runs-on: ubuntu-latest
steps:
- name: checkout
uses: actions/checkout@v4
- name: generate version tag
id: version
run: echo "TAG=$(date +'%Y%m%d.%H%M')" >> $GITHUB_OUTPUT
- name: read product version
id: prodversion
run: |
VERSION=$(jq -r .version version.json)
if [ -z "$VERSION" ] || [ "$VERSION" = "null" ]; then
echo "Failed to read product version from version.json" >&2
exit 1
fi
echo "VERSION=$VERSION" >> $GITHUB_OUTPUT
# The backend image is built with `context: ./backend`, so the
# repo-root version.json is OUTSIDE the build context and never
# reaches the container. Backend `main.py` falls back to a
# compile-time constant when /app/version.json is missing, which
# caused a real production drift: a redeploy of the v1.5.2 tree
# silently still reported "v1.5.0" in `/api/version` because the
# constant in main.py had been bumped but the file was not
# available to read. Stage version.json into the backend
# context here so the canonical file IS shipped and the
# constant only serves as a defensive fallback. The staged file
# is gitignored to keep `git status` clean for developers.
- name: stage version.json into backend build context
run: cp version.json backend/version.json
- name: set up qemu
uses: docker/setup-qemu-action@v3
- name: set up docker buildx
uses: docker/setup-buildx-action@v3
- name: login to docker hub
uses: docker/login-action@v3
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: build & push backend
uses: docker/build-push-action@v6
with:
context: ./backend
file: ./backend/Dockerfile
platforms: linux/amd64,linux/arm64
push: true
tags: |
taylanbakircioglu/haproxy-openmanager-backend:latest
taylanbakircioglu/haproxy-openmanager-backend:${{ steps.version.outputs.TAG }}
taylanbakircioglu/haproxy-openmanager-backend:${{ steps.prodversion.outputs.VERSION }}
- name: build & push frontend
uses: docker/build-push-action@v6
with:
context: ./frontend
file: ./frontend/Dockerfile
platforms: linux/amd64,linux/arm64
push: true
tags: |
taylanbakircioglu/haproxy-openmanager-frontend:latest
taylanbakircioglu/haproxy-openmanager-frontend:${{ steps.version.outputs.TAG }}
taylanbakircioglu/haproxy-openmanager-frontend:${{ steps.prodversion.outputs.VERSION }}