Restore image versioning and auth safety
This commit is contained in:
parent
90e71a068c
commit
7461ae27aa
|
|
@ -56,7 +56,6 @@ rails e2e spec:
|
||||||
- name: $CI_REGISTRY_IMAGE/production/commits:$CI_COMMIT_SHA
|
- name: $CI_REGISTRY_IMAGE/production/commits:$CI_COMMIT_SHA
|
||||||
alias: app
|
alias: app
|
||||||
variables:
|
variables:
|
||||||
GIT_COMMIT_SHA: $CI_COMMIT_SHA
|
|
||||||
TURNIERE_DISABLE_EMAIL_DELIVERY: "1"
|
TURNIERE_DISABLE_EMAIL_DELIVERY: "1"
|
||||||
command:
|
command:
|
||||||
- bundle
|
- bundle
|
||||||
|
|
@ -128,7 +127,6 @@ rails follow sync e2e spec:
|
||||||
SECRET_KEY_BASE: turniere-blackbox-secret-key-base-please-change-in-real-prod
|
SECRET_KEY_BASE: turniere-blackbox-secret-key-base-please-change-in-real-prod
|
||||||
MAILGUN_API_KEY: blackbox-test-api-key
|
MAILGUN_API_KEY: blackbox-test-api-key
|
||||||
MAILGUN_DOMAIN: blackbox.example.com
|
MAILGUN_DOMAIN: blackbox.example.com
|
||||||
GIT_COMMIT_SHA: $CI_COMMIT_SHA
|
|
||||||
TURNIERE_DISABLE_EMAIL_DELIVERY: "1"
|
TURNIERE_DISABLE_EMAIL_DELIVERY: "1"
|
||||||
TOURNAMENT_SYNC_HTTP_TIMEOUT_SECONDS: "3"
|
TOURNAMENT_SYNC_HTTP_TIMEOUT_SECONDS: "3"
|
||||||
NO_PROXY: source-app,follower-app,source-postgres,follower-postgres,localhost,127.0.0.1
|
NO_PROXY: source-app,follower-app,source-postgres,follower-postgres,localhost,127.0.0.1
|
||||||
|
|
@ -153,7 +151,6 @@ rails follow sync e2e spec:
|
||||||
SECRET_KEY_BASE: turniere-blackbox-secret-key-base-please-change-in-real-prod
|
SECRET_KEY_BASE: turniere-blackbox-secret-key-base-please-change-in-real-prod
|
||||||
MAILGUN_API_KEY: blackbox-test-api-key
|
MAILGUN_API_KEY: blackbox-test-api-key
|
||||||
MAILGUN_DOMAIN: blackbox.example.com
|
MAILGUN_DOMAIN: blackbox.example.com
|
||||||
GIT_COMMIT_SHA: $CI_COMMIT_SHA
|
|
||||||
TURNIERE_DISABLE_EMAIL_DELIVERY: "1"
|
TURNIERE_DISABLE_EMAIL_DELIVERY: "1"
|
||||||
TOURNAMENT_SYNC_HTTP_TIMEOUT_SECONDS: "3"
|
TOURNAMENT_SYNC_HTTP_TIMEOUT_SECONDS: "3"
|
||||||
NO_PROXY: source-app,follower-app,source-postgres,follower-postgres,localhost,127.0.0.1
|
NO_PROXY: source-app,follower-app,source-postgres,follower-postgres,localhost,127.0.0.1
|
||||||
|
|
|
||||||
10
Dockerfile
10
Dockerfile
|
|
@ -2,7 +2,7 @@
|
||||||
|
|
||||||
ARG RUBY_VERSION=4.0.3
|
ARG RUBY_VERSION=4.0.3
|
||||||
ARG BUNDLER_VERSION=4.0.6
|
ARG BUNDLER_VERSION=4.0.6
|
||||||
ARG GIT_COMMIT_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
ARG base_commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
||||||
|
|
||||||
FROM ruby:${RUBY_VERSION}-slim AS runtime-base
|
FROM ruby:${RUBY_VERSION}-slim AS runtime-base
|
||||||
|
|
||||||
|
|
@ -57,10 +57,10 @@ RUN bundle config set with 'development test' \
|
||||||
|
|
||||||
FROM runtime-base AS production
|
FROM runtime-base AS production
|
||||||
|
|
||||||
ARG GIT_COMMIT_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
ARG base_commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
||||||
|
|
||||||
ENV RAILS_ENV=production \
|
ENV RAILS_ENV=production \
|
||||||
GIT_COMMIT_SHA=${GIT_COMMIT_SHA}
|
GIT_COMMIT_SHA=${base_commit}
|
||||||
|
|
||||||
COPY --from=bundle-production /usr/local/bundle /usr/local/bundle
|
COPY --from=bundle-production /usr/local/bundle /usr/local/bundle
|
||||||
COPY --from=bundle-production /app/vendor/bundle /app/vendor/bundle
|
COPY --from=bundle-production /app/vendor/bundle /app/vendor/bundle
|
||||||
|
|
@ -83,10 +83,10 @@ CMD ["sh", "-lc", "bundle exec rails db:migrate && bundle exec rails s -p 3000 -
|
||||||
|
|
||||||
FROM runtime-base AS test
|
FROM runtime-base AS test
|
||||||
|
|
||||||
ARG GIT_COMMIT_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
ARG base_commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
||||||
|
|
||||||
ENV RAILS_ENV=test \
|
ENV RAILS_ENV=test \
|
||||||
GIT_COMMIT_SHA=${GIT_COMMIT_SHA}
|
GIT_COMMIT_SHA=${base_commit}
|
||||||
|
|
||||||
RUN apt-get update -qq \
|
RUN apt-get update -qq \
|
||||||
&& apt-get install -y --no-install-recommends \
|
&& apt-get install -y --no-install-recommends \
|
||||||
|
|
|
||||||
|
|
@ -10,10 +10,6 @@ class ApplicationController < ActionController::API
|
||||||
end
|
end
|
||||||
rescue_from ActiveRecord::RecordNotFound, with: :render_not_found_error
|
rescue_from ActiveRecord::RecordNotFound, with: :render_not_found_error
|
||||||
|
|
||||||
def bypass_sign_in(_resource, scope: nil)
|
|
||||||
true
|
|
||||||
end
|
|
||||||
|
|
||||||
protected
|
protected
|
||||||
|
|
||||||
def configure_permitted_parameters
|
def configure_permitted_parameters
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,58 @@
|
||||||
|
# Rails 8 Dependency Update Notes
|
||||||
|
|
||||||
|
## Scope
|
||||||
|
|
||||||
|
This update moves the backend runtime to Ruby 4.0.3, Bundler 4.0.6, Rails 8.1,
|
||||||
|
Puma 8, and the released `devise_token_auth` gem.
|
||||||
|
|
||||||
|
The project no longer uses the Thor77 `devise_token_auth` fork. The released
|
||||||
|
gem currently supports this stack through `devise_token_auth` 1.2.6 with
|
||||||
|
`devise` 4.9.4.
|
||||||
|
|
||||||
|
## Docker Versioning
|
||||||
|
|
||||||
|
Container versioning still uses the shared pipeline `base_commit` build arg.
|
||||||
|
The production and test images burn that value into `GIT_COMMIT_SHA` at build
|
||||||
|
time.
|
||||||
|
|
||||||
|
Do not set `GIT_COMMIT_SHA` as a runtime service variable in CI or deployment.
|
||||||
|
Runtime overrides can make `/version` report a different SHA than the image was
|
||||||
|
built from.
|
||||||
|
|
||||||
|
## Email Delivery In Blackbox Runs
|
||||||
|
|
||||||
|
`TURNIERE_BLACKBOX_DISABLE_EMAIL_DELIVERY` is a local blackbox compose variable.
|
||||||
|
It maps to the app runtime variable `TURNIERE_DISABLE_EMAIL_DELIVERY`.
|
||||||
|
|
||||||
|
Blackbox production E2E uses real production mode but fake Mailgun credentials.
|
||||||
|
Registration sends a confirmation email, so blackbox runs disable delivery to
|
||||||
|
avoid calling Mailgun while still keeping the production confirmation flow.
|
||||||
|
|
||||||
|
Normal production deployments should not set `TURNIERE_DISABLE_EMAIL_DELIVERY`
|
||||||
|
unless email delivery is intentionally disabled.
|
||||||
|
|
||||||
|
## Schema Diff
|
||||||
|
|
||||||
|
Rails 8.1 dumps columns in a different order than Rails 7. That creates a large
|
||||||
|
`db/schema.rb` diff, but it is ordering churn, not dropped columns.
|
||||||
|
|
||||||
|
Relative to current `master`, no existing schema columns are removed by the
|
||||||
|
dependency update. The timer reason work on `master` adds:
|
||||||
|
|
||||||
|
- `tournaments.timer_reason`
|
||||||
|
- `tournaments.timer_reason_text`
|
||||||
|
|
||||||
|
## API And Frontend Compatibility
|
||||||
|
|
||||||
|
Known frontend-facing API changes are additive:
|
||||||
|
|
||||||
|
- tournament payloads include `timer_reason`
|
||||||
|
- tournament payloads include `timer_reason_text`
|
||||||
|
- timer endpoints accept and return those same fields
|
||||||
|
|
||||||
|
Existing frontend code can ignore these fields and keep using `timestamp` and
|
||||||
|
`timer_mode`. Frontend changes are only needed if the UI should show or edit
|
||||||
|
timer reasons.
|
||||||
|
|
||||||
|
No deployment configuration change is required beyond building/running the new
|
||||||
|
image with the existing shared pipeline build metadata.
|
||||||
4
tasks.py
4
tasks.py
|
|
@ -256,7 +256,7 @@ def _docker_build_command(tag, target, platforms=None, push=False):
|
||||||
"--target",
|
"--target",
|
||||||
target,
|
target,
|
||||||
"--build-arg",
|
"--build-arg",
|
||||||
f"GIT_COMMIT_SHA={_git_commit_sha()}",
|
f"base_commit={_git_commit_sha()}",
|
||||||
"-t",
|
"-t",
|
||||||
tag,
|
tag,
|
||||||
"-f",
|
"-f",
|
||||||
|
|
@ -274,7 +274,7 @@ def _docker_build_command(tag, target, platforms=None, push=False):
|
||||||
"--target",
|
"--target",
|
||||||
target,
|
target,
|
||||||
"--build-arg",
|
"--build-arg",
|
||||||
f"GIT_COMMIT_SHA={_git_commit_sha()}",
|
f"base_commit={_git_commit_sha()}",
|
||||||
"-t",
|
"-t",
|
||||||
tag,
|
tag,
|
||||||
"-f",
|
"-f",
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue