Skip to content

deploy: stamp images with their git revision and expose it from /healthz, so a deploy can be verified mechanically #3315

Description

@Xore

What

Deploy verification today is manual inference: compare docker images creation time with the merge time, or grep a string out of the shipped binary. docs/ARCANE-GIT-SYNC.md already documents the failure mode ("green, healthy, running the old code").

  • apiary-backend:latest on the homeserver has Labels: null and Created 2026-09-08T21:00. Every backend merge since then, including fix(backend): migrate rand call sites to 0.10 #3300, is undeployed, and nothing surfaces that.
  • backend-service /healthz returns {ok: true, es: <bool>} with no version or commit.

Proposal

  • Build arg GIT_SHA → LABEL org.opencontainers.image.revision=$GIT_SHA (+ .created, .source) in the backend-service and frontend-next Dockerfiles. Arcane builds pass it from the synced checkout.
  • Backend: embed the SHA at compile time (env!/option_env!) and return it from /healthz ({ok, es, revision}). Frontend: same through a static /build.json or response header.
  • Docs + a scripts/verify-deploy.sh <expected-sha> that compares the live /healthz revision and the image labels against origin/main. Diagnostics can then warn when the deployed revision lags main by more than N days.

Sources

Found by the #3194 OmniRoute ops/CI deep-check (pinned 18bbb101, APIARY main 3dca4457).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    dashboardDashboard product area — routes, templates, styling and frontend UXenhancementNew feature or requestopsDeployment, runners, observability, host access

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions