You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Deploy verification today is manual inference: compare docker images creation time with the merge time, or grep a string out of the shipped binary. docs/ARCANE-GIT-SYNC.md already documents the failure mode ("green, healthy, running the old code").
apiary-backend:latest on the homeserver has Labels: null and Created 2026-09-08T21:00. Every backend merge since then, including fix(backend): migrate rand call sites to 0.10 #3300, is undeployed, and nothing surfaces that.
backend-service/healthz returns {ok: true, es: <bool>} with no version or commit.
Proposal
Build arg GIT_SHA → LABEL org.opencontainers.image.revision=$GIT_SHA (+ .created, .source) in the backend-service and frontend-next Dockerfiles. Arcane builds pass it from the synced checkout.
Backend: embed the SHA at compile time (env!/option_env!) and return it from /healthz ({ok, es, revision}). Frontend: same through a static /build.json or response header.
Docs + a scripts/verify-deploy.sh <expected-sha> that compares the live /healthz revision and the image labels against origin/main. Diagnostics can then warn when the deployed revision lags main by more than N days.
docs/ops/BRANCHING_MODEL.md
RELEASE_CHECKLIST's "Artifact Validation"/"Deploy" sections: dist/BUILD_SHA == git rev-parse --short HEAD before and after deploy.
Found by the #3194 OmniRoute ops/CI deep-check (pinned 18bbb101, APIARY main3dca4457).
What
Deploy verification today is manual inference: compare
docker imagescreation time with the merge time, or grep a string out of the shipped binary.docs/ARCANE-GIT-SYNC.mdalready documents the failure mode ("green, healthy, running the old code").apiary-backend:lateston the homeserver hasLabels: nullandCreated 2026-09-08T21:00. Every backend merge since then, including fix(backend): migrate rand call sites to 0.10 #3300, is undeployed, and nothing surfaces that.backend-service/healthzreturns{ok: true, es: <bool>}with no version or commit.Proposal
GIT_SHA→LABEL org.opencontainers.image.revision=$GIT_SHA(+.created,.source) in the backend-service and frontend-next Dockerfiles. Arcane builds pass it from the synced checkout.env!/option_env!) and return it from/healthz({ok, es, revision}). Frontend: same through a static/build.jsonor response header.scripts/verify-deploy.sh <expected-sha>that compares the live/healthzrevision and the image labels againstorigin/main. Diagnostics can then warn when the deployed revision lagsmainby more than N days.Sources
docs/ops/RELEASE_CHECKLIST.mddocs/ops/MONITORING_GUIDE.mddocs/ops/BRANCHING_MODEL.mdRELEASE_CHECKLIST's "Artifact Validation"/"Deploy" sections:
dist/BUILD_SHA == git rev-parse --short HEADbefore and after deploy.Found by the #3194 OmniRoute ops/CI deep-check (pinned
18bbb101, APIARYmain3dca4457).