Skip to content

feat(releases): build exact revisions in Daytona with guarded rollout - #108

Draft
teckedd-code2save wants to merge 1 commit into
mainfrom
feature/107-daytona-releases
Draft

teckedd-code2save wants to merge 1 commit into
mainfrom
feature/107-daytona-releases

Conversation

@teckedd-code2save

Copy link
Copy Markdown
Owner

Source deployments currently compile on the production VPS, which contributed to memory pressure during RentAWeekend recovery. This adds an explicit per-deployment Daytona builder so the VPS only pulls and runs immutable images.

The release path resolves the queued GitHub commit, transfers a clean archive to a bounded disposable Docker sandbox, builds repository Dockerfiles, supplies GHCR credentials only after builds finish, publishes digests and confirms sandbox deletion before changing host source or configuration. It has no host-build fallback.

Host rollout preserves current image IDs, source, effective Compose and environment files, deploys selected services with building/pulling disabled, verifies actual images, health and public HTTPS, and restores the previous release on failure. Locks and release-specific logs isolate runs. The recorded deployed commit changes only after successful verification. Existing host builds and Daytona reproduction settings remain separate.

Validation:

  • 65 targeted tests across the changed builder, registry preflight, exact source selection, webhook policy, deployment evidence and rollback code pass (64 in the combined run, plus the added image-mismatch case in the final focused run).
  • TypeScript, targeted lint and Next production build pass.
  • The real RentAWeekend web image at PR #220 head d70ce9869317b5ebd550d1b45da03c8ddc852b06 built successfully in Daytona.
  • GHCR rejected the push because the stored token lacks the expected scopes. The sandbox was deleted; no production containers changed. The new preflight now rejects missing write:packages before sandbox creation.
  • Existing GroundControl and RentAWeekend images remain healthy; public web and API checks return 200.

Activation remains blocked: configure an appropriate GHCR writer credential, prove publish/private pull, then complete controlled live rollout and disposable-workload rollback acceptance. Autopilot remains off. GroundControl self-upgrades still require the canonical installer/SQLite recovery gate; its Alpine dependencies also retain an account network blocker.

Supported scope and the full acceptance checklist are in docs/DAYTONA_RELEASES.md. This remains draft until live acceptance is complete. Related RentAWeekend build fix: https://github.com/teckedd-code2save/RentAWeekend/pull/220. Refs #107.

…ollout

Refs #107. Keep activation blocked until registry publishing and live acceptance pass.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant