Restore image versioning and auth safety

This commit is contained in:
Daniel Schädler 2026-04-28 23:51:36 +02:00
parent 90e71a068c
commit 7461ae27aa
5 changed files with 65 additions and 14 deletions

View File

@ -56,7 +56,6 @@ rails e2e spec:
- name: $CI_REGISTRY_IMAGE/production/commits:$CI_COMMIT_SHA
alias: app
variables:
GIT_COMMIT_SHA: $CI_COMMIT_SHA
TURNIERE_DISABLE_EMAIL_DELIVERY: "1"
command:
- bundle
@ -128,7 +127,6 @@ rails follow sync e2e spec:
SECRET_KEY_BASE: turniere-blackbox-secret-key-base-please-change-in-real-prod
MAILGUN_API_KEY: blackbox-test-api-key
MAILGUN_DOMAIN: blackbox.example.com
GIT_COMMIT_SHA: $CI_COMMIT_SHA
TURNIERE_DISABLE_EMAIL_DELIVERY: "1"
TOURNAMENT_SYNC_HTTP_TIMEOUT_SECONDS: "3"
NO_PROXY: source-app,follower-app,source-postgres,follower-postgres,localhost,127.0.0.1
@ -153,7 +151,6 @@ rails follow sync e2e spec:
SECRET_KEY_BASE: turniere-blackbox-secret-key-base-please-change-in-real-prod
MAILGUN_API_KEY: blackbox-test-api-key
MAILGUN_DOMAIN: blackbox.example.com
GIT_COMMIT_SHA: $CI_COMMIT_SHA
TURNIERE_DISABLE_EMAIL_DELIVERY: "1"
TOURNAMENT_SYNC_HTTP_TIMEOUT_SECONDS: "3"
NO_PROXY: source-app,follower-app,source-postgres,follower-postgres,localhost,127.0.0.1

View File

@ -2,7 +2,7 @@
ARG RUBY_VERSION=4.0.3
ARG BUNDLER_VERSION=4.0.6
ARG GIT_COMMIT_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
ARG base_commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
FROM ruby:${RUBY_VERSION}-slim AS runtime-base
@ -57,10 +57,10 @@ RUN bundle config set with 'development test' \
FROM runtime-base AS production
ARG GIT_COMMIT_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
ARG base_commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
ENV RAILS_ENV=production \
GIT_COMMIT_SHA=${GIT_COMMIT_SHA}
GIT_COMMIT_SHA=${base_commit}
COPY --from=bundle-production /usr/local/bundle /usr/local/bundle
COPY --from=bundle-production /app/vendor/bundle /app/vendor/bundle
@ -83,10 +83,10 @@ CMD ["sh", "-lc", "bundle exec rails db:migrate && bundle exec rails s -p 3000 -
FROM runtime-base AS test
ARG GIT_COMMIT_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
ARG base_commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
ENV RAILS_ENV=test \
GIT_COMMIT_SHA=${GIT_COMMIT_SHA}
GIT_COMMIT_SHA=${base_commit}
RUN apt-get update -qq \
&& apt-get install -y --no-install-recommends \

View File

@ -10,10 +10,6 @@ class ApplicationController < ActionController::API
end
rescue_from ActiveRecord::RecordNotFound, with: :render_not_found_error
def bypass_sign_in(_resource, scope: nil)
true
end
protected
def configure_permitted_parameters

View File

@ -0,0 +1,58 @@
# Rails 8 Dependency Update Notes
## Scope
This update moves the backend runtime to Ruby 4.0.3, Bundler 4.0.6, Rails 8.1,
Puma 8, and the released `devise_token_auth` gem.
The project no longer uses the Thor77 `devise_token_auth` fork. The released
gem currently supports this stack through `devise_token_auth` 1.2.6 with
`devise` 4.9.4.
## Docker Versioning
Container versioning still uses the shared pipeline `base_commit` build arg.
The production and test images burn that value into `GIT_COMMIT_SHA` at build
time.
Do not set `GIT_COMMIT_SHA` as a runtime service variable in CI or deployment.
Runtime overrides can make `/version` report a different SHA than the image was
built from.
## Email Delivery In Blackbox Runs
`TURNIERE_BLACKBOX_DISABLE_EMAIL_DELIVERY` is a local blackbox compose variable.
It maps to the app runtime variable `TURNIERE_DISABLE_EMAIL_DELIVERY`.
Blackbox production E2E uses real production mode but fake Mailgun credentials.
Registration sends a confirmation email, so blackbox runs disable delivery to
avoid calling Mailgun while still keeping the production confirmation flow.
Normal production deployments should not set `TURNIERE_DISABLE_EMAIL_DELIVERY`
unless email delivery is intentionally disabled.
## Schema Diff
Rails 8.1 dumps columns in a different order than Rails 7. That creates a large
`db/schema.rb` diff, but it is ordering churn, not dropped columns.
Relative to current `master`, no existing schema columns are removed by the
dependency update. The timer reason work on `master` adds:
- `tournaments.timer_reason`
- `tournaments.timer_reason_text`
## API And Frontend Compatibility
Known frontend-facing API changes are additive:
- tournament payloads include `timer_reason`
- tournament payloads include `timer_reason_text`
- timer endpoints accept and return those same fields
Existing frontend code can ignore these fields and keep using `timestamp` and
`timer_mode`. Frontend changes are only needed if the UI should show or edit
timer reasons.
No deployment configuration change is required beyond building/running the new
image with the existing shared pipeline build metadata.

View File

@ -256,7 +256,7 @@ def _docker_build_command(tag, target, platforms=None, push=False):
"--target",
target,
"--build-arg",
f"GIT_COMMIT_SHA={_git_commit_sha()}",
f"base_commit={_git_commit_sha()}",
"-t",
tag,
"-f",
@ -274,7 +274,7 @@ def _docker_build_command(tag, target, platforms=None, push=False):
"--target",
target,
"--build-arg",
f"GIT_COMMIT_SHA={_git_commit_sha()}",
f"base_commit={_git_commit_sha()}",
"-t",
tag,
"-f",