The fuel fee nobody can remove FIN-94

Open2 versionsCI/CD · Hard · Fix · about 40 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Sal Brennan opened FIN-94 at 10:15SEV-3

Finance removed the fuel fee on October 1. The change merged, its pipeline was green, it deployed. Customers are still being charged.

The pipeline tests the new commit, then builds and deploys. Somewhere between "tested" and "deployed", the new code gets lost.

"Finance has promised refunds. I need to know the next deploy actually contains what we merged." (Sal)

The running image carries a revision label. Compare it, and the code inside the image, with what the pipeline tested.

Your task

Find how the build ends up with code other than the tested commit, and change the workflow so what deploys is always built from the tested commit and deployed by digest, a failing test still blocks, and earlier artifacts stay available for rollback. Commit and run bin/ci run push.

On the machine

  • repo/.github/workflows/release.yml
  • bin/prod status, registry/waybill.json
  • bin/ci runs, bin/ci log N

Timeline

Sep 30FIN-88 merges: remove fuel_fee from checkout. Pipeline green, deployed.
Oct 1Fee should be gone. Checkout still returns fuel_fee.
Oct 2Two customer complaints, one from a large account.
10:15FIN-94 opened.

Done when

  1. A commit with a failing test does not deploy.
  2. Production runs an image built from the commit the pipeline tested, deployed by digest.
  3. The previous release's image stays in the registry for rollback.

Hints

Hint 1

Ask which commit the running image was built from: its revision label says.

Hint 2

Then ask how that commit's code reached the build: a cache restore, or a checkout of something other than the pushed commit.

Hint 3

A cache is not a release artifact, and a pinned ref is not the commit under test.

Hint 4

Build after the tests, from the pushed commit, and deploy the digest that build produced.

Show the solution

Read the running image's revision label (`bin/registry inspect`): it is not the commit the pipeline tested. Find out why in `release.yml`: either `dist/` is restored from a cache keyed only on `VERSION`, or the build job checks out a pinned `ref` (a release branch cut before the fee was removed). Make `build` need `test`, build from the pushed commit with no cached `dist/`, tag the image `waybill:${{ github.sha }}`, expose its digest as a job output, and deploy `waybill@${{ needs.build.outputs.digest }}`. Commit to main, run `bin/ci run push`, and confirm with `bin/prod status`.