fix: complete deployment release gates

This commit is contained in:
2026-08-05 14:35:25 +02:00
parent 2ae89c075e
commit 5f015a5a37
10 changed files with 891 additions and 121 deletions
+25 -16
View File
@@ -9,28 +9,37 @@
frontend-to-core routing, embedded pinned Pi, Git registry bootstrap, offline recreation, valid
update, invalid-update retention, and the four persistent stores. `scripts/thothctl-update-smoke.sh`
independently exercises the bad-Pi update and automatic rollback path.
`scripts/server-deployment-smoke.sh` starts the server plus required session overlays with the
same smoke-built core/frontend images, disposable bind roots/secrets/session configuration,
upstream-auth checks, and fail-closed unavailable-session behavior.
- **Isolation and disclosure boundary.** Every run generates a unique temporary root, Compose
project, container/image names, transaction image tags, and run label. The rollback fixture uses
an immutable public digest as a deliberately dead core rather than a host-local image registry.
Cleanup checks ownership before removing exact containers, Compose resources, image references,
control state, and temporary files. There is no global prune. Failure diagnostics are bounded
and sanitized, and all credentials/endpoints used by the smokes are disposable fixtures rather
than operator or repository secrets.
an immutable `hello-world` digest whose preflight exits successfully, guaranteeing the stopped
core state required by `thothctl` compensation. Cleanup includes stopped project containers in
its final ownership check immediately before teardown and removes only exact containers,
Compose resources, image references, control state, and temporary files. There is no global
prune. Failure diagnostics are bounded and sanitized, and all credentials/endpoints used by the
smokes are disposable fixtures rather than operator or repository secrets. Every public smoke
also has an internal 30-minute process-group supervisor with TERM/KILL of the complete group.
- **Cross-platform CI contract.** `.github/workflows/deployment.yml` uses immutable action commits,
pinned supported Node and Go versions, runs LF/Compose/secret/coupling/docs/TypeScript gates on
Linux, runs each Docker smoke once under its own outer timeout, and builds/invokes native Windows
`thothctl` after the PowerShell clone/LF/Compose contract. Native Windows execution remains an
explicit manual release gate in addition to CI; no Windows Docker container startup is claimed
by the static clone job.
Linux, runs each Linux Docker smoke once under its own outer timeout, and copies the Windows
source into a path containing spaces before building/invoking native `thothctl` and rendering
Compose. The optional `windows_docker_startup` dispatch targets a labelled self-hosted Windows
Docker Desktop/WSL2 runner and performs bounded two-service startup and exact cleanup. No local
Windows or Windows Docker execution is claimed until that manual job is recorded.
- **Validation status.** Deterministic Phase A gates, backend **434/434** plus TypeScript,
frontend **386/386** plus TypeScript, and harness **862 passed / 5 L2 deselected** are green.
The unified one-shot Docker run passed frontend/core/internal Pi, registry bootstrap, offline
recreation, valid update, invalid-update retention, and persistence before Docker Desktop
refused the daemon-to-host local-registry push; the update-only run reached the same boundary.
Both exact run/project resource sets were independently proved absent. The local-registry
fixture was then removed in favor of the immutable dead-core digest, but the requested no-retry
rule leaves automatic rollback/preservation pending in CI or a fresh manual release run. Native
Windows PowerShell execution is also still a manual release gate.
Review round 1 ran each Docker smoke exactly once without retry. Unified (`103.86s`) and
update-only (`46.45s`) passed build/start, core/Pi/registry/persistence setup and the stopped
candidate preflight, but `thothctl` stopped before mutation at its active-session inventory gate.
A test-first fix now scopes local inventory to `mine` and supplies the fixture's missing direct
DWH/vector/embedding runtime bindings; the final rollback path was not rerun, so compensation
and all-sentinel preservation remain unproven. Server-profile execution (`12.88s`) built both
images but Docker Desktop/VirtioFS rejected the real profile's parent Pi-state bind plus nested
tracked agent-file binds before service startup. Every run's exact labelled cleanup passed.
Native-Linux server startup and native Windows PowerShell/Docker execution remain explicit
CI/manual release gates; no local success is claimed for either platform.
## Portable deployment decoupling — LIVE 2026-08-05