feat: ordered multi-file Compose for Git sources (#1380)

* feat: ordered multi-file Compose for Git sources

Extend Git sources to deploy an ordered list of compose files merged with
docker compose -f base.yaml -f override.yaml ..., plus an optional project
directory.

- Pick and reorder compose files from the repository tree (drag to reorder on
  desktop, up/down arrows on phones); manual path entry is also supported.
- The ordered set drives every stack-scoped compose command (deploy, update,
  start/stop/restart/down, image scans, Compose Doctor) and the container
  lookup, so a service or image declared only in an override is handled too.
- Runtime keys off the materialized set, not the saved configuration: saving a
  source does not change deploy args until the pull is applied, and apply
  materializes from the pending snapshot rather than live config.
- The project directory is passed as --project-directory, with -p <stack>
  pinning the Compose project so container labels stay stable.
- The Mesh override is layered last; single-file sources are byte-identical to
  before, and existing rows keep working via the single-path fallback.

Docs cover the picker, ordering, project directory, and the new troubleshooting
and limitations (referenced files are not materialized; the dependency graph,
drift, and networking views read the primary file).

* fix: harden multi-file Git source (hash, unlink, collisions, node id)

- hashContent folds ordered file CONTENTS (not paths) so a clean multi-file
  stack is not flagged as locally edited: create/apply hash the fetched files
  (repo paths) while pull hashes the on-disk files (materialized paths), which
  previously disagreed and showed a false "local edits detected".
- Block unlinking a multi-file or project-directory Git source (409): the deploy
  spec lives on the source row, so removing it would silently revert deploys to
  root compose.yaml. Single-file sources still unlink.
- Reject materialized-path collisions in the selection validator: an additional
  file equal to or nested under compose.yaml, an ancestor/descendant overlap
  between selected files, and a project directory nested under a compose file
  (previously a 500 at materialization).
- DockerController.getContainersByStack uses the controller's node compose dir
  and passes its node id to the authored prefix, instead of the process default.

* fix: CI failures on multi-file Git source (test crash, aria query, path barrier)

- GitSourceFields no longer crashes when repoUrl/branch are falsy: the canBrowse
  trim() is optional-chained, so a reusable field component tolerates partial
  props. Fixes the apply-binding panel test, which feeds a minimal source object.
- GitSourcePanel tests query the footer Remove button by its exact name, so the
  picker's per-file "Remove <path>" buttons no longer collide with the broad
  /remove/i match (the test intent, footer Remove present/absent, is unchanged).
- validateCompose uses an inline resolve + startsWith barrier at the context-dir
  mkdir sink (CodeQL does not credit the wrapped isPathWithinBase helper),
  clearing the js/path-injection alert. The containment check is equivalent and
  contextDir is also validated upstream.

* test: update Git source E2E spec for the multi-file compose picker

The compose-file picker replaced the single #git-source-path input and added
per-file Remove buttons, so the E2E spec drove selectors that no longer exist:

- Drop the redundant compose.yaml fills (the picker defaults to compose.yaml).
- Select the footer Remove button by exact name so the picker's per-file
  "Remove <path>" buttons no longer make the locator ambiguous.
- Set a custom compose path through the picker (add via the manual input, press
  Enter, then remove the default compose.yaml).

* test: match the footer Remove button with an exact Playwright name

Playwright's getByRole name option is a substring match by default, so
{ name: 'Remove' } also matched the picker's "Remove <path>" buttons. Require an
exact match so only the footer Remove button is selected.
This commit is contained in:
Anso
2026-06-17 13:24:55 -04:00
committed by GitHub
parent 7ce045accb
commit f23b7e1bac
34 changed files with 2299 additions and 385 deletions
@@ -2,6 +2,7 @@ import { Input } from '@/components/ui/input';
import { Label } from '@/components/ui/label';
import { Checkbox } from '@/components/ui/checkbox';
import { cn } from '@/lib/utils';
import { GitComposeFilePicker, type GitBrowseResult } from './GitComposeFilePicker';
export type ApplyMode = 'review' | 'auto-write' | 'auto-deploy';
@@ -9,8 +10,8 @@ export type ApplyMode = 'review' | 'auto-write' | 'auto-deploy';
* Mirror of the backend's env-path default (see `/api/stacks/from-git` and
* the git-source PUT handler): if the user ticks "Sync .env" without
* specifying an explicit path, the service reads `<dirname>/.env`
* alongside the compose file. Surfacing this in the form saves the user
* a round-trip to figure out which directory the `.env` will come from.
* alongside the primary compose file. Surfacing this in the form saves the
* user a round-trip to figure out which directory the `.env` will come from.
*/
function computeDefaultEnvPath(composePath: string): string {
const normalized = composePath.trim().replace(/\\/g, '/').replace(/^\.\//, '');
@@ -22,7 +23,8 @@ function computeDefaultEnvPath(composePath: string): string {
export interface GitSourceFieldsState {
repoUrl: string;
branch: string;
composePath: string;
composePaths: string[];
contextDir: string;
syncEnv: boolean;
authType: 'none' | 'token';
token: string;
@@ -37,11 +39,14 @@ export interface GitSourceFieldsProps extends GitSourceFieldsState {
variant: 'edit' | 'create';
onRepoUrlChange: (value: string) => void;
onBranchChange: (value: string) => void;
onComposePathChange: (value: string) => void;
onComposePathsChange: (value: string[]) => void;
onContextDirChange: (value: string) => void;
onSyncEnvChange: (value: boolean) => void;
onAuthTypeChange: (value: 'none' | 'token') => void;
onTokenChange: (value: string) => void;
onApplyModeChange: (value: ApplyMode) => void;
/** Runs the correct browse endpoint (create vs edit); returns the repo file list or null on failure. */
onBrowse: () => Promise<GitBrowseResult | null>;
}
const APPLY_MODE_COPY: Record<'edit' | 'create', Record<ApplyMode, { title: string; description: string }>> = {
@@ -60,7 +65,8 @@ const APPLY_MODE_COPY: Record<'edit' | 'create', Record<ApplyMode, { title: stri
export function GitSourceFields({
repoUrl,
branch,
composePath,
composePaths,
contextDir,
syncEnv,
authType,
token,
@@ -70,13 +76,17 @@ export function GitSourceFields({
variant,
onRepoUrlChange,
onBranchChange,
onComposePathChange,
onComposePathsChange,
onContextDirChange,
onSyncEnvChange,
onAuthTypeChange,
onTokenChange,
onApplyModeChange,
onBrowse,
}: GitSourceFieldsProps) {
const copy = APPLY_MODE_COPY[variant];
const primaryComposePath = composePaths[0] ?? '';
const canBrowse = !!repoUrl?.trim() && !!branch?.trim();
const radioOption = (mode: ApplyMode) => (
<button
@@ -119,31 +129,28 @@ export function GitSourceFields({
/>
</div>
<div className="grid grid-cols-2 gap-3">
<div className="space-y-2">
<Label htmlFor="git-source-branch">Branch</Label>
<Input
id="git-source-branch"
placeholder="main"
value={branch}
onChange={(e) => onBranchChange(e.target.value)}
disabled={disabled}
className="font-mono text-xs"
/>
</div>
<div className="space-y-2">
<Label htmlFor="git-source-path">Compose file path</Label>
<Input
id="git-source-path"
placeholder="compose.yaml"
value={composePath}
onChange={(e) => onComposePathChange(e.target.value)}
disabled={disabled}
className="font-mono text-xs"
/>
</div>
<div className="space-y-2">
<Label htmlFor="git-source-branch">Branch</Label>
<Input
id="git-source-branch"
placeholder="main"
value={branch}
onChange={(e) => onBranchChange(e.target.value)}
disabled={disabled}
className="font-mono text-xs"
/>
</div>
<GitComposeFilePicker
composePaths={composePaths}
contextDir={contextDir}
onComposePathsChange={onComposePathsChange}
onContextDirChange={onContextDirChange}
onBrowse={onBrowse}
canBrowse={canBrowse}
disabled={disabled}
/>
<div className="space-y-1">
<div className="flex items-center gap-2">
<Checkbox
@@ -156,11 +163,11 @@ export function GitSourceFields({
Also sync sibling <span className="font-mono">.env</span> file
</Label>
</div>
{syncEnv && composePath.trim() !== '' && (
{syncEnv && primaryComposePath.trim() !== '' && (
<p className="text-[11px] text-stat-subtitle pl-6">
Will read{' '}
<span className="font-mono">
{computeDefaultEnvPath(composePath)}
{computeDefaultEnvPath(primaryComposePath)}
</span>{' '}
from the repository.
</p>