Advisory tests, "for a week", three months ago OPS-861

Open3 versionsCI/CD · Medium · Fix · about 30 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Dmitri Vos opened OPS-861 at 09:00SEV-3

Yesterday's checkout change failed the integration tests and deployed anyway. One in five depot checkouts now errors.

Someone set the integration step to continue on error during a migration, and nobody turned it back. The pipeline has been decorative since July.

"You do not need to fix the checkout bug, Ivo has that. Fix the pipeline so this cannot happen again, and keep the test report, people need it to debug." (Dmitri)

The CI runner here behaves like GitHub Actions: jobs, steps, needs, if, and artifacts.

Your task

Make a failing test suite stop the pipeline before anything deploys, upload the integration report even when tests fail, and keep green pipelines deploying. Commit the workflow to main and run bin/ci run push.

On the machine

  • repo/.github/workflows/release.yml
  • bin/ci runs, bin/ci log N
  • bin/prod status, bin/deployctl, bin/registry

Timeline

JulyDuring the depot migration, integration tests are made advisory "for a week".
15:20A checkout change fails integration tests. The pipeline goes green and deploys.
15:40Depots: 1 in 5 checkouts fail.
09:00OPS-861: the pipeline is the incident.

Done when

  1. A failing test suite stops the pipeline before anything deploys, and a green one still deploys.
  2. The integration report is uploaded even when the tests fail.

Hints

Hint 1

`bin/ci log N` for yesterday's run: which job or step failed, and what ran anyway?

Hint 2

Look for the ways a workflow ignores failure. On a step, `continue-on-error` or `|| true`. On a job, an `if:` that runs regardless.

Hint 3

A command piped into `tee` returns tee's exit status unless the shell has `set -o pipefail`.

Hint 4

Uploading the report and deploying are separate decisions. The upload can run `if: always()`, and the deploy only on success.

Show the solution

Read yesterday's run with `bin/ci log`, then the workflow, and find what turns a failed test into a success or lets the release go on without it. It can be `continue-on-error: true` on the step (plus a `| tee` that hides the exit code; add `set -o pipefail`), `|| true` at the end of the test command, or `if: always()` on the build job. Remove it. Change the report upload to `if: always()` so the report still reaches people when the tests fail. Commit to main and run `bin/ci run push`.