Reuse approved worker networking and retry only confirmed clean probe failures
This commit is contained in:
@@ -4,7 +4,6 @@
|
||||
"project": "otche-local",
|
||||
"worker_container": "otche-local-worker-1",
|
||||
"postgres_container": "otche-local-postgres-1",
|
||||
"compose_network": "otche-local_private",
|
||||
"database_user": "otche",
|
||||
"database": "otche",
|
||||
"worker_config": "/srv/otche/secrets/worker/config.json",
|
||||
|
||||
+14
-1
@@ -229,7 +229,7 @@ class Renewal:
|
||||
# Exec inside the existing approved image; no builds, pulls, migrations or project changes.
|
||||
info = json.loads(self.docker('inspect', self.worker))[0]
|
||||
image = info['Image']
|
||||
command = ['run', '--rm', '--network', self.c['compose_network'], '--volumes-from', self.worker + ':ro',
|
||||
command = ['run', '--rm', '--network', 'container:' + self.worker, '--volumes-from', self.worker + ':ro',
|
||||
'--env', 'DATABASE_URL_FILE=/run/secrets/database-url', '--env', 'WORKER_CONFIG_FILE=/run/otche/config.json',
|
||||
image, 'bindings-sync']
|
||||
self.docker(*command, timeout=120)
|
||||
@@ -269,6 +269,19 @@ class Renewal:
|
||||
self.publish()
|
||||
self.current.unlink()
|
||||
print('Fresh owner and online proofs published after real probes and cleanup', flush=True)
|
||||
except Exception:
|
||||
if self.work:
|
||||
save(self.state / 'last-failure.json', {'at': dt.datetime.now(dt.timezone.utc).isoformat(), 'work_dir': str(self.work)})
|
||||
owner_journal = self.work / 'owner-resources.json'
|
||||
network_journal = self.work / 'network-resources.json'
|
||||
owner_clean = owner_journal.exists() and any(row['phase'] == 'complete' and row['resource'] == 'cleanup'
|
||||
for row in load(owner_journal)['events'])
|
||||
network_clean = not network_journal.exists() or load(network_journal).get('cleanup_complete') is True
|
||||
if owner_clean and network_clean and not load('/var/lib/otche-network/state.json')['records']:
|
||||
self.delete_clone()
|
||||
self.current.unlink(missing_ok=True)
|
||||
print('Failed checks left no resources; next timer may retry without renewing old proofs', flush=True)
|
||||
raise
|
||||
finally:
|
||||
# A failed/ambiguous test retains its journal and cannot be automatically overwritten.
|
||||
# Never force-delete a running/changed VM or hide a failed cleanup.
|
||||
|
||||
Reference in New Issue
Block a user