Skip to content

feat: dev adoption - harden verify pipeline, pin compose project, align env examples - #5

Merged
Cho-Geer merged 22 commits into
developfrom
feat/dev-adoption
Sep 23, 2026
Merged

Cho-Geer merged 22 commits into
developfrom
feat/dev-adoption

Conversation

@Cho-Geer

Copy link
Copy Markdown
Owner

Summary(dev 適用手順 rev.6 の実装一式)

Step 1: verify-images.sh の修復

  • 4 つの待機ループ(postgres/redis/backend/frontend)がタイムアウト時に logs + down -v + exit 1 するよう修正(以前は失敗しても「✅ 驗證通過」を出力 = 検証ゲート無効)
  • health 応答判定を実レスポンス形式(checks.*.status == "up")に修正し、jq 未 instal 環境では grep にフォールバック
  • compose env 生成時に DOCKER_HUB_USER ガード + develop タグ置換を追加(ローカル実行可能化)
  • frontend env への backend 用 sed(死コード)を除去

Step 2: verify-images.yml

  • matrix を [dev] に限定(prod タグ体系確定まで)
  • push/pull_request 両 paths に env/** を追加
  • 注入後ガード 4 種(空 KEY・行中パスワード欠損・compose 空値・残存プレースホルダ)で静かな失敗を防止

Step 3: compose

  • name: booking-dev でプロジェクト名を固定(dev/prod 衝突防止)
  • backend に booking_uploads_dev:/app/uploads ボリューム(再作成でアップロード消失)

Step 4: env examples

  • 死んだ変数 8 個削除(DB_*/LOG_*/HEALTHCHECK_TIMEOUT_MS)
  • MAIL_*/INTEGRATION_TOKEN/RETENTION_*/SF_* 追加、FRONTEND_URLS に 127.0.0.1
  • frontend example から NODE_ENV/未使用変数を削除し NEXT_PUBLIC_SF_SITE_URL を追加

その他

  • .gitattributes: *.sh/*.example を LF 固定(CRLF によるシェバン破壊の再発防止)
  • handoff ドキュメント(docs/handoff/dev-adoption-plan.html)を追加

Test plan

  • 負試験 2 経路: 待機ループ 30/30 タイムアウト → ❌ + down -v + exit 1 / migration 依存障害でも同様
  • 通し実行: pull → 依存起動 → migration 12 件適用 → 全コンテナ healthy → フロント/Swagger 可視 → 成功バナー
  • G-10 永続化: force-recreate 後も /app/uploads のファイルが残存
  • seed: 修正済み migration イメージ(develop)で seed 成功 → 実メール受信 → ログイン成功(booking-backend PR #40 とセット)
  • CI: 本 PR の verify-deployment / verify-images(dev leg)が green になること

TraeAI and others added 22 commits September 22, 2026 20:20
- wait loops (postgres/redis/backend/frontend) exit 1 with logs + down -v on timeout
- health judgement reads the real response shape (checks.*.status == up)
- generate compose env with DOCKER_HUB_USER guard and dev-abc123def -> develop tag
- stop applying backend secret seds to frontend env (dead code)
- matrix environment: [dev] until prod tag scheme is decided
- add env/** to push trigger paths
- document the real CI tag scheme (develop / develop-<sha>) in example comments
- note POSTGRES_PASSWORD must match backend.env DATABASE_URL
verify-images.sh became CRLF during editing and bash refused to run it
(#!/usr/bin/env bash<CR> -> No such file or directory). Pin eol=lf for
.sh (and .example files whose line-ending-anchored checks matter).
…ecrets

- pull_request paths now match push paths (env/** added)
- post-injection guards exit 1 when a secret is unset:
  empty KEY= (JWT), mid-line password loss (DATABASE_URL),
  empty POSTGRES_PASSWORD, or leftover placeholders
jq is not installed on local Windows hosts, so the DB/Redis check
always degraded to the warning branch. Use jq when present, otherwise
match checks.*.status == up with grep. Both paths verified against
real and degraded health payloads.
local batch builds are not used by CI, verify pipeline, or compose;
the mismatched booking-system-* naming made them unusable as-is.
- mount ./certs (host booking-deploy/certs) into backend container at /app/certs
  so SF_PRIVATE_KEY_PATH=certs/booking-integration.key resolves in-container
- ignore certs/ : the real private key must never be committed (kept local only)
- actual SF_*/INTEGRATION_TOKEN values live in env/dev/backend.env (gitignored)
…, HEAD refresh)

- Known limitations 2/3 resolved: SF_SITE_URL baked via Dockerfile ARG + build-args (frontend #25/#26, develop=7e0f83a); certs mount + SF_*/INTEGRATION_TOKEN real values in backend.env (806512a)
- HEAD/PR refreshed: backend 68d708e (PR #40), frontend 7e0f83a (PR #26), booking-deploy feat/dev-adoption 806512a (17 ahead of develop; PR #5 OPEN/REVIEW_REQUIRED/BLOCKED)
- Step 3 G-6 marked unimplemented (compose example comments still stale); Step 7 dev leg proven by PR #5 CI; MAIL/NEXT_PUBLIC/G-15 rows de-staled
- Line-number notes refreshed (cp/sed loop 33-61, generate_app_env 64-87, pull 103; 260 lines) and CRLF caveat added to 1.4
@Cho-Geer Cho-Geer self-assigned this Sep 23, 2026
@Cho-Geer Cho-Geer added CI/CD bug Something isn't working labels Sep 23, 2026
@Cho-Geer
Cho-Geer merged commit b3ffd23 into develop Sep 23, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working CI/CD

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants