Restore image versioning and auth safety
This commit is contained in:
parent
90e71a068c
commit
7461ae27aa
|
|
@ -56,7 +56,6 @@ rails e2e spec:
|
|||
- name: $CI_REGISTRY_IMAGE/production/commits:$CI_COMMIT_SHA
|
||||
alias: app
|
||||
variables:
|
||||
GIT_COMMIT_SHA: $CI_COMMIT_SHA
|
||||
TURNIERE_DISABLE_EMAIL_DELIVERY: "1"
|
||||
command:
|
||||
- bundle
|
||||
|
|
@ -128,7 +127,6 @@ rails follow sync e2e spec:
|
|||
SECRET_KEY_BASE: turniere-blackbox-secret-key-base-please-change-in-real-prod
|
||||
MAILGUN_API_KEY: blackbox-test-api-key
|
||||
MAILGUN_DOMAIN: blackbox.example.com
|
||||
GIT_COMMIT_SHA: $CI_COMMIT_SHA
|
||||
TURNIERE_DISABLE_EMAIL_DELIVERY: "1"
|
||||
TOURNAMENT_SYNC_HTTP_TIMEOUT_SECONDS: "3"
|
||||
NO_PROXY: source-app,follower-app,source-postgres,follower-postgres,localhost,127.0.0.1
|
||||
|
|
@ -153,7 +151,6 @@ rails follow sync e2e spec:
|
|||
SECRET_KEY_BASE: turniere-blackbox-secret-key-base-please-change-in-real-prod
|
||||
MAILGUN_API_KEY: blackbox-test-api-key
|
||||
MAILGUN_DOMAIN: blackbox.example.com
|
||||
GIT_COMMIT_SHA: $CI_COMMIT_SHA
|
||||
TURNIERE_DISABLE_EMAIL_DELIVERY: "1"
|
||||
TOURNAMENT_SYNC_HTTP_TIMEOUT_SECONDS: "3"
|
||||
NO_PROXY: source-app,follower-app,source-postgres,follower-postgres,localhost,127.0.0.1
|
||||
|
|
|
|||
10
Dockerfile
10
Dockerfile
|
|
@ -2,7 +2,7 @@
|
|||
|
||||
ARG RUBY_VERSION=4.0.3
|
||||
ARG BUNDLER_VERSION=4.0.6
|
||||
ARG GIT_COMMIT_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
||||
ARG base_commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
||||
|
||||
FROM ruby:${RUBY_VERSION}-slim AS runtime-base
|
||||
|
||||
|
|
@ -57,10 +57,10 @@ RUN bundle config set with 'development test' \
|
|||
|
||||
FROM runtime-base AS production
|
||||
|
||||
ARG GIT_COMMIT_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
||||
ARG base_commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
||||
|
||||
ENV RAILS_ENV=production \
|
||||
GIT_COMMIT_SHA=${GIT_COMMIT_SHA}
|
||||
GIT_COMMIT_SHA=${base_commit}
|
||||
|
||||
COPY --from=bundle-production /usr/local/bundle /usr/local/bundle
|
||||
COPY --from=bundle-production /app/vendor/bundle /app/vendor/bundle
|
||||
|
|
@ -83,10 +83,10 @@ CMD ["sh", "-lc", "bundle exec rails db:migrate && bundle exec rails s -p 3000 -
|
|||
|
||||
FROM runtime-base AS test
|
||||
|
||||
ARG GIT_COMMIT_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
||||
ARG base_commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
||||
|
||||
ENV RAILS_ENV=test \
|
||||
GIT_COMMIT_SHA=${GIT_COMMIT_SHA}
|
||||
GIT_COMMIT_SHA=${base_commit}
|
||||
|
||||
RUN apt-get update -qq \
|
||||
&& apt-get install -y --no-install-recommends \
|
||||
|
|
|
|||
|
|
@ -10,10 +10,6 @@ class ApplicationController < ActionController::API
|
|||
end
|
||||
rescue_from ActiveRecord::RecordNotFound, with: :render_not_found_error
|
||||
|
||||
def bypass_sign_in(_resource, scope: nil)
|
||||
true
|
||||
end
|
||||
|
||||
protected
|
||||
|
||||
def configure_permitted_parameters
|
||||
|
|
|
|||
|
|
@ -0,0 +1,58 @@
|
|||
# Rails 8 Dependency Update Notes
|
||||
|
||||
## Scope
|
||||
|
||||
This update moves the backend runtime to Ruby 4.0.3, Bundler 4.0.6, Rails 8.1,
|
||||
Puma 8, and the released `devise_token_auth` gem.
|
||||
|
||||
The project no longer uses the Thor77 `devise_token_auth` fork. The released
|
||||
gem currently supports this stack through `devise_token_auth` 1.2.6 with
|
||||
`devise` 4.9.4.
|
||||
|
||||
## Docker Versioning
|
||||
|
||||
Container versioning still uses the shared pipeline `base_commit` build arg.
|
||||
The production and test images burn that value into `GIT_COMMIT_SHA` at build
|
||||
time.
|
||||
|
||||
Do not set `GIT_COMMIT_SHA` as a runtime service variable in CI or deployment.
|
||||
Runtime overrides can make `/version` report a different SHA than the image was
|
||||
built from.
|
||||
|
||||
## Email Delivery In Blackbox Runs
|
||||
|
||||
`TURNIERE_BLACKBOX_DISABLE_EMAIL_DELIVERY` is a local blackbox compose variable.
|
||||
It maps to the app runtime variable `TURNIERE_DISABLE_EMAIL_DELIVERY`.
|
||||
|
||||
Blackbox production E2E uses real production mode but fake Mailgun credentials.
|
||||
Registration sends a confirmation email, so blackbox runs disable delivery to
|
||||
avoid calling Mailgun while still keeping the production confirmation flow.
|
||||
|
||||
Normal production deployments should not set `TURNIERE_DISABLE_EMAIL_DELIVERY`
|
||||
unless email delivery is intentionally disabled.
|
||||
|
||||
## Schema Diff
|
||||
|
||||
Rails 8.1 dumps columns in a different order than Rails 7. That creates a large
|
||||
`db/schema.rb` diff, but it is ordering churn, not dropped columns.
|
||||
|
||||
Relative to current `master`, no existing schema columns are removed by the
|
||||
dependency update. The timer reason work on `master` adds:
|
||||
|
||||
- `tournaments.timer_reason`
|
||||
- `tournaments.timer_reason_text`
|
||||
|
||||
## API And Frontend Compatibility
|
||||
|
||||
Known frontend-facing API changes are additive:
|
||||
|
||||
- tournament payloads include `timer_reason`
|
||||
- tournament payloads include `timer_reason_text`
|
||||
- timer endpoints accept and return those same fields
|
||||
|
||||
Existing frontend code can ignore these fields and keep using `timestamp` and
|
||||
`timer_mode`. Frontend changes are only needed if the UI should show or edit
|
||||
timer reasons.
|
||||
|
||||
No deployment configuration change is required beyond building/running the new
|
||||
image with the existing shared pipeline build metadata.
|
||||
4
tasks.py
4
tasks.py
|
|
@ -256,7 +256,7 @@ def _docker_build_command(tag, target, platforms=None, push=False):
|
|||
"--target",
|
||||
target,
|
||||
"--build-arg",
|
||||
f"GIT_COMMIT_SHA={_git_commit_sha()}",
|
||||
f"base_commit={_git_commit_sha()}",
|
||||
"-t",
|
||||
tag,
|
||||
"-f",
|
||||
|
|
@ -274,7 +274,7 @@ def _docker_build_command(tag, target, platforms=None, push=False):
|
|||
"--target",
|
||||
target,
|
||||
"--build-arg",
|
||||
f"GIT_COMMIT_SHA={_git_commit_sha()}",
|
||||
f"base_commit={_git_commit_sha()}",
|
||||
"-t",
|
||||
tag,
|
||||
"-f",
|
||||
|
|
|
|||
Loading…
Reference in New Issue