diff --git a/AGENTS.md b/AGENTS.md index 1ea71eb1..8b853e04 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -16,7 +16,7 @@ HWLAB 是硬件实验室运行面和控制面项目。本文是 agent、指挥 ## 工作区 - Runner 和指挥常用工作区是 `/workspace/hwlab`;进入仓库先检查分支与工作树状态,详见 [docs/reference/commander-collaboration.md](docs/reference/commander-collaboration.md)。 -- D601 发布/构建工作区是 `/home/ubuntu/workspace/hwlab`;不要把 runner 临时目录当作发布真相,详见 [docs/reference/deployment-publish.md](docs/reference/deployment-publish.md)。 +- D601 发布/构建必须使用干净 worktree;`/home/ubuntu/workspace/hwlab` 只是共享缓存或建树来源,发现脏、落后或被并行任务占用时改用 `/tmp/hwlab-cicd-` detached worktree,详见 [docs/reference/deployment-publish.md](docs/reference/deployment-publish.md)。 - Master server 只做控制、Git、issue/PR 和短轮询;HWLAB `check`、Playwright、本地构建、发布预检和 CI/CD 验证必须放到 D601/runner/CI/CD,详见 [docs/reference/deployment-publish.md](docs/reference/deployment-publish.md)。 - 当前一律走 PR 工作流;不要直推 `main`,默认不要合并自己的 PR;用户或指挥官明确授权且满足门禁时可按长期参考自合并,不要改 PROD、不要重启服务。 - `DC-DCSN-P0-2026-003` / [pikasTech/HWLAB#78](https://github.com/pikasTech/HWLAB/issues/78) 是当前 M3 虚拟硬件可信闭环的上位约束;其他任务不得把 SOURCE、LOCAL、DRY-RUN、fixture 或前端状态误报为 M3 DEV-LIVE。 diff --git a/deploy/artifact-catalog.dev.json b/deploy/artifact-catalog.dev.json index 7d4db3da..139a496a 100644 --- a/deploy/artifact-catalog.dev.json +++ b/deploy/artifact-catalog.dev.json @@ -5,12 +5,12 @@ "profile": "dev", "namespace": "hwlab-dev", "endpoint": "http://74.48.78.17:16667", - "commitId": "fa216f1", + "commitId": "203bbe7", "artifactState": "published", "publish": { "ciPublished": true, "registryVerified": true, - "provenance": "ci-artifact:ci-publish-20260524T180538-ab5150", + "provenance": "ci-artifact:ci-publish-20260525T050149-7511df", "note": "Digest fields were copied from a successful DEV artifact publish report for this source commit." }, "healthContract": { @@ -66,10 +66,10 @@ "services": [ { "serviceId": "hwlab-cloud-api", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-cloud-api:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:67f2e5c5f775f3904182bc8b375ec8db9f6a750837ce9f5395f1c793b8c6db80", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-cloud-api:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:ee8b051a9f3861197555101cb1c8b233736254ad92ffd6f45fd60dea9b2569b2", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -79,15 +79,15 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" }, { "serviceId": "hwlab-cloud-web", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-cloud-web:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:61951fce0fc5efa70bfe20b91a7d0caa00f8f4f4d0f28cf36d40bff0c1cfb643", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-cloud-web:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:8d4d5f811278992cdbf1e2260847147bcd3b1f08814d679390ba17cd43a079c2", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -97,15 +97,15 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" }, { "serviceId": "hwlab-agent-mgr", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-agent-mgr:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:801210386c260b55787e75d4f35d285c33bfd4a3c688fda688ec2f11ab224621", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-agent-mgr:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:7bfc6ac935afe6a3464e5dbf2fef4d4ee6effef70ec12367a2b81a934902da25", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -115,15 +115,15 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" }, { "serviceId": "hwlab-agent-worker", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-agent-worker:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:a6f0a1e19421728f957b0002755d4a65d53ec4fae40a7fb37f77e9993da5d807", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-agent-worker:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:52646c3ada718fe18828d72f6352dfada891e9be68dd563a87c991d43a60d0e4", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -133,15 +133,15 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" }, { "serviceId": "hwlab-gateway", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-gateway:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:f5a27d5a54f3190f228063258ec05654d70371fea8e36b31e4de29ed073f1ab5", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-gateway:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:7b288617dd921be41f38372970e7a46eb6caad7ad9615c9ce22f31c214f5d96c", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -151,15 +151,15 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" }, { "serviceId": "hwlab-gateway-simu", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-gateway-simu:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:38c05ab740b2cbc8d162897eb6864f2614f3530407aa7530a6b50ce780fc38e0", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-gateway-simu:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:1749e1c5ba3762b9622b7caafa320be855dee1f0e84e9ae78e95d20bc3720e2e", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -169,15 +169,15 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" }, { "serviceId": "hwlab-box-simu", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-box-simu:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:b9d3beddf98e250b0b63881465fbaa93b5eefd609521f947779ebdcef02c0834", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-box-simu:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:f521f7486c1fe1849be8c03bef0cf63909da6e443406e7981e46ba9b22acb074", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -187,15 +187,15 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" }, { "serviceId": "hwlab-patch-panel", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-patch-panel:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:0b0b5899aa1d8b23839121d14a4b601786f1a17ec786063ca5554adb966cb26b", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-patch-panel:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:9f6546d2013a04f7d869ae2158737273e6ceadb34811b7c9b3cb85873da2e445", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -205,15 +205,15 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" }, { "serviceId": "hwlab-router", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-router:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:66d3a456f3af6cc93b52ae4ad84f7c55c0a011991677e642b2044d30c088cd63", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-router:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:163adef6ca1ed79309ab81c0af13805fcc15b8b67ed382325663f19ea1e9726e", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -223,15 +223,15 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" }, { "serviceId": "hwlab-tunnel-client", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-tunnel-client:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:f24dd2056647de7d55c4855708246752831b5960fa07b17e34612fc4e77c3e11", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-tunnel-client:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:d3f40eb37e9b103bf9f86b0086cd4079d4827bce64fb275eb7f710c61d87f628", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -241,15 +241,15 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" }, { "serviceId": "hwlab-edge-proxy", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-edge-proxy:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:71d7c66a67693b72bfbe2055cd54bb6340c083faaa5a187a43cf934e1d0d1ded", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-edge-proxy:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:b0795e7e57e1d5e65ef5242be71774c811755a4d215b81814367c0e3eb89e759", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -259,15 +259,15 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" }, { "serviceId": "hwlab-cli", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-cli:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:3e4fbf11719141a7013cc6230b7364e7e1acfc8282df14592d562dd438ddd9b4", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-cli:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:7a26cd09dfceddee48a6fffe68fe755b0ccf39cfb00a2d94233e99f3e6800837", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -277,15 +277,15 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" }, { "serviceId": "hwlab-agent-skills", - "commitId": "fa216f1", - "image": "127.0.0.1:5000/hwlab/hwlab-agent-skills:fa216f1", - "imageTag": "fa216f1", - "digest": "sha256:bf0f1a2a0236fb120f66bcc4f2b25fdd765b970578ebb8bf11f8254c812122c1", + "commitId": "203bbe7", + "image": "127.0.0.1:5000/hwlab/hwlab-agent-skills:203bbe7", + "imageTag": "203bbe7", + "digest": "sha256:c671b54002e07fa7e8a34409658458b9e1f04887603701dd4437ca1b82412065", "publishState": "published", "profile": "dev", "namespace": "hwlab-dev", @@ -295,8 +295,8 @@ "artifactRequired": true, "artifactScope": "required", "notPublishedReason": null, - "buildCreatedAt": "2026-05-24T18:05:40.725Z", - "buildSource": "pikasTech/HWLAB@fa216f1cd86e65b6c500b2047672b8335f6bf16a" + "buildCreatedAt": "2026-05-25T05:01:52.171Z", + "buildSource": "pikasTech/HWLAB@203bbe7f9a10e7a03691485b967c44a133a509ba" } ], "serviceInventory": { diff --git a/deploy/deploy.json b/deploy/deploy.json index a5d477d4..8f442dc2 100644 --- a/deploy/deploy.json +++ b/deploy/deploy.json @@ -1,7 +1,7 @@ { "manifestVersion": "v1", "environment": "dev", - "commitId": "fa216f1", + "commitId": "203bbe7", "namespace": "hwlab-dev", "endpoint": "http://74.48.78.17:16667", "health": { @@ -181,7 +181,7 @@ "services": [ { "serviceId": "hwlab-cloud-api", - "image": "127.0.0.1:5000/hwlab/hwlab-cloud-api:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-cloud-api:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", @@ -190,9 +190,9 @@ "HWLAB_ENVIRONMENT": "dev", "HWLAB_PUBLIC_ENDPOINT": "http://74.48.78.17:16667", "HWLAB_CLOUD_API_PORT": "6667", - "HWLAB_COMMIT_ID": "fa216f1", - "HWLAB_IMAGE": "127.0.0.1:5000/hwlab/hwlab-cloud-api:fa216f1", - "HWLAB_IMAGE_TAG": "fa216f1", + "HWLAB_COMMIT_ID": "203bbe7", + "HWLAB_IMAGE": "127.0.0.1:5000/hwlab/hwlab-cloud-api:203bbe7", + "HWLAB_IMAGE_TAG": "203bbe7", "HWLAB_RUNTIME_SUBSTITUTE_FORBIDDEN": "unidesk-backend,provider-gateway,microservice-proxy", "HWLAB_CLOUD_DB_URL": "secretRef:hwlab-cloud-api-dev-db/database-url", "HWLAB_CLOUD_DB_SSL_MODE": "disable", @@ -223,7 +223,7 @@ }, { "serviceId": "hwlab-cloud-web", - "image": "127.0.0.1:5000/hwlab/hwlab-cloud-web:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-cloud-web:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", @@ -232,14 +232,14 @@ "HWLAB_ENVIRONMENT": "dev", "HWLAB_API_BASE_URL": "http://hwlab-cloud-api.hwlab-dev.svc.cluster.local:6667", "HWLAB_CLOUD_WEB_PROXY_TIMEOUT_MS": "660000", - "HWLAB_COMMIT_ID": "fa216f1", - "HWLAB_IMAGE": "127.0.0.1:5000/hwlab/hwlab-cloud-web:fa216f1", - "HWLAB_IMAGE_TAG": "fa216f1" + "HWLAB_COMMIT_ID": "203bbe7", + "HWLAB_IMAGE": "127.0.0.1:5000/hwlab/hwlab-cloud-web:203bbe7", + "HWLAB_IMAGE_TAG": "203bbe7" } }, { "serviceId": "hwlab-agent-mgr", - "image": "127.0.0.1:5000/hwlab/hwlab-agent-mgr:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-agent-mgr:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", @@ -251,7 +251,7 @@ }, { "serviceId": "hwlab-agent-worker", - "image": "127.0.0.1:5000/hwlab/hwlab-agent-worker:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-agent-worker:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", @@ -263,7 +263,7 @@ }, { "serviceId": "hwlab-gateway", - "image": "127.0.0.1:5000/hwlab/hwlab-gateway:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-gateway:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", @@ -275,7 +275,7 @@ }, { "serviceId": "hwlab-gateway-simu", - "image": "127.0.0.1:5000/hwlab/hwlab-gateway-simu:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-gateway-simu:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", @@ -295,7 +295,7 @@ }, { "serviceId": "hwlab-box-simu", - "image": "127.0.0.1:5000/hwlab/hwlab-box-simu:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-box-simu:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", @@ -314,7 +314,7 @@ }, { "serviceId": "hwlab-patch-panel", - "image": "127.0.0.1:5000/hwlab/hwlab-patch-panel:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-patch-panel:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", @@ -335,7 +335,7 @@ }, { "serviceId": "hwlab-router", - "image": "127.0.0.1:5000/hwlab/hwlab-router:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-router:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", @@ -347,7 +347,7 @@ }, { "serviceId": "hwlab-tunnel-client", - "image": "127.0.0.1:5000/hwlab/hwlab-tunnel-client:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-tunnel-client:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", @@ -361,7 +361,7 @@ }, { "serviceId": "hwlab-edge-proxy", - "image": "127.0.0.1:5000/hwlab/hwlab-edge-proxy:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-edge-proxy:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", @@ -374,7 +374,7 @@ }, { "serviceId": "hwlab-cli", - "image": "127.0.0.1:5000/hwlab/hwlab-cli:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-cli:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", @@ -385,13 +385,13 @@ }, { "serviceId": "hwlab-agent-skills", - "image": "127.0.0.1:5000/hwlab/hwlab-agent-skills:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-agent-skills:203bbe7", "namespace": "hwlab-dev", "healthPath": "/health/live", "profile": "dev", "replicas": 1, "env": { - "HWLAB_SKILLS_COMMIT_ID": "fa216f1" + "HWLAB_SKILLS_COMMIT_ID": "203bbe7" } } ], diff --git a/deploy/k8s/base/workloads.yaml b/deploy/k8s/base/workloads.yaml index 7927cc97..932a6d38 100644 --- a/deploy/k8s/base/workloads.yaml +++ b/deploy/k8s/base/workloads.yaml @@ -31,7 +31,7 @@ "containers": [ { "name": "hwlab-cloud-api", - "image": "127.0.0.1:5000/hwlab/hwlab-cloud-api:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-cloud-api:203bbe7", "ports": [ { "name": "http", @@ -53,15 +53,15 @@ }, { "name": "HWLAB_COMMIT_ID", - "value": "fa216f1" + "value": "203bbe7" }, { "name": "HWLAB_IMAGE", - "value": "127.0.0.1:5000/hwlab/hwlab-cloud-api:fa216f1" + "value": "127.0.0.1:5000/hwlab/hwlab-cloud-api:203bbe7" }, { "name": "HWLAB_IMAGE_TAG", - "value": "fa216f1" + "value": "203bbe7" }, { "name": "HWLAB_RUNTIME_SUBSTITUTE_FORBIDDEN", @@ -283,7 +283,7 @@ "containers": [ { "name": "hwlab-cloud-web", - "image": "127.0.0.1:5000/hwlab/hwlab-cloud-web:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-cloud-web:203bbe7", "ports": [ { "name": "http", @@ -301,15 +301,15 @@ }, { "name": "HWLAB_COMMIT_ID", - "value": "fa216f1" + "value": "203bbe7" }, { "name": "HWLAB_IMAGE", - "value": "127.0.0.1:5000/hwlab/hwlab-cloud-web:fa216f1" + "value": "127.0.0.1:5000/hwlab/hwlab-cloud-web:203bbe7" }, { "name": "HWLAB_IMAGE_TAG", - "value": "fa216f1" + "value": "203bbe7" } ], "readinessProbe": { @@ -359,7 +359,7 @@ "containers": [ { "name": "hwlab-agent-mgr", - "image": "127.0.0.1:5000/hwlab/hwlab-agent-mgr:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-agent-mgr:203bbe7", "ports": [ { "name": "http", @@ -415,7 +415,7 @@ "containers": [ { "name": "hwlab-agent-worker", - "image": "127.0.0.1:5000/hwlab/hwlab-agent-worker:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-agent-worker:203bbe7", "env": [ { "name": "HWLAB_AGENT_SESSION_MODE", @@ -458,7 +458,7 @@ "containers": [ { "name": "hwlab-gateway", - "image": "127.0.0.1:5000/hwlab/hwlab-gateway:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-gateway:203bbe7", "ports": [ { "name": "http", @@ -519,7 +519,7 @@ "containers": [ { "name": "hwlab-gateway-simu", - "image": "127.0.0.1:5000/hwlab/hwlab-gateway-simu:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-gateway-simu:203bbe7", "ports": [ { "name": "http", @@ -592,7 +592,7 @@ "containers": [ { "name": "hwlab-box-simu", - "image": "127.0.0.1:5000/hwlab/hwlab-box-simu:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-box-simu:203bbe7", "ports": [ { "name": "http", @@ -660,7 +660,7 @@ "containers": [ { "name": "hwlab-patch-panel", - "image": "127.0.0.1:5000/hwlab/hwlab-patch-panel:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-patch-panel:203bbe7", "ports": [ { "name": "http", @@ -724,7 +724,7 @@ "containers": [ { "name": "hwlab-router", - "image": "127.0.0.1:5000/hwlab/hwlab-router:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-router:203bbe7", "ports": [ { "name": "http", @@ -784,7 +784,7 @@ "containers": [ { "name": "hwlab-tunnel-client", - "image": "127.0.0.1:5000/hwlab/hwlab-tunnel-client:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-tunnel-client:203bbe7", "ports": [ { "name": "http", @@ -856,7 +856,7 @@ "containers": [ { "name": "hwlab-edge-proxy", - "image": "127.0.0.1:5000/hwlab/hwlab-edge-proxy:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-edge-proxy:203bbe7", "ports": [ { "name": "http", @@ -921,7 +921,7 @@ "containers": [ { "name": "hwlab-cli", - "image": "127.0.0.1:5000/hwlab/hwlab-cli:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-cli:203bbe7", "env": [ { "name": "HWLAB_CLI_ENDPOINT", @@ -963,7 +963,7 @@ "containers": [ { "name": "hwlab-agent-skills", - "image": "127.0.0.1:5000/hwlab/hwlab-agent-skills:fa216f1", + "image": "127.0.0.1:5000/hwlab/hwlab-agent-skills:203bbe7", "ports": [ { "name": "http", @@ -973,7 +973,7 @@ "env": [ { "name": "HWLAB_SKILLS_COMMIT_ID", - "value": "fa216f1" + "value": "203bbe7" } ], "readinessProbe": { diff --git a/docs/reference/deployment-publish.md b/docs/reference/deployment-publish.md index bc6f1b23..d678cf0f 100644 --- a/docs/reference/deployment-publish.md +++ b/docs/reference/deployment-publish.md @@ -32,11 +32,46 @@ blocker and cannot be used as deploy, rollout, smoke, or acceptance proof. | Purpose | Path | | --- | --- | | Runner and commander worktree | `/workspace/hwlab` | -| D601 publish/build worktree | `/home/ubuntu/workspace/hwlab` | +| D601 shared source cache | `/home/ubuntu/workspace/hwlab` | +| D601 clean CI/CD worktree | `/tmp/hwlab-cicd-` | +| D601 runtime experiment worktree | `/tmp/hwlab--` | -Use `/home/ubuntu/workspace/hwlab` for D601 build and rollout operations. -Do not treat `/home/ubuntu/hwlab` or other runner worktrees as the publishing -truth. +Git remote is the source of truth. D601 may contain several HWLAB clones or +worktrees from earlier reviews, Code Queue runs, runtime experiments, or CI/CD +jobs; none of those local directories is authoritative by itself. Before using +any D601 repo path for checks, publish, or CD, verify its role, `origin`, HEAD, +and cleanliness. + +`/home/ubuntu/workspace/hwlab` is the shared source cache and convenient seed +clone. It is allowed to be stale, behind `origin/main`, or dirty with generated +`reports/dev-gate/**` files from previous runs. Do not `reset --hard`, delete +reports, or overwrite that directory just to make a release command work. If it +is not clean and already at the target commit, use it only to `git fetch` and +create a detached clean worktree. + +Formal CI publish and DEV CD apply must run from a clean, target-pinned +worktree such as `/tmp/hwlab-cicd-`. The worktree may be +created from the shared cache, but it must prove all of the following before +side effects: + +- `git remote get-url origin` points to `git@github.com:pikasTech/HWLAB.git` + or the approved GitHub source of truth. +- `git fetch origin main` succeeds, and `git rev-parse HEAD` equals the target + commit being published or deployed. +- `git status --short` is empty. +- The `hwlab-cli cicd submit ...` job `cwd` in `state.json` points to the clean + worktree, not to a stale runner directory or a dirty shared cache. + +Runtime hotfix and gateway probing may use purpose-specific D601 worktrees under +`/tmp/hwlab--`. Those worktrees are for copying scripts into pods, +running probes, and staging temporary patches; they are not release truth and +must not be used to infer desired state unless they are also clean and pinned to +the target commit. + +Do not treat `/home/ubuntu/hwlab`, historical runner directories, previous PR +review worktrees, or pod-local copied trees as publish/build truth. If a path's +role is unclear, stop and create a new detached worktree from `origin/main` +instead of repairing the unknown directory in place. ## Master Server Check Boundary @@ -541,18 +576,25 @@ After a successful multi-service publish, refresh the artifact catalog from the publish report: ```sh -node scripts/refresh-artifact-catalog.mjs --target-ref origin/main --publish-report /tmp/hwlab-dev-gate/dev-artifacts.json -node scripts/deploy-desired-state-plan.mjs --target-ref origin/main --check +node scripts/refresh-artifact-catalog.mjs --target-ref --publish-report /tmp/hwlab-dev-gate/dev-artifacts.json +node scripts/deploy-desired-state-plan.mjs --promotion-commit --check ``` `ci-publish` only proves that images for its `sourceCommitId` were built and -pushed; it does not change the rollout target by itself. Before any formal -`dev-cd-apply`, operators must refresh `deploy/artifact-catalog.dev.json`, -`deploy/k8s/base/workloads.yaml`, and `deploy/deploy.json`, commit/push that -promotion, and verify the desired-state plan points at the intended -`sourceCommitId`. If `deploy/deploy.json` still names an older commit, CD will -correctly keep deploying that older promotion even when a newer publish report -exists. Do not treat the newest CI publish report as implicit CD desired state. +pushed; it does not change the rollout target by itself. The refresh target +must be the already published `sourceCommitId` from the CI publish report. A +later documentation, catalog, or desired-state commit may record the promotion, +but it is not automatically an image source and must not be passed as +`--target-ref` unless a matching publish report proves images for that exact +commit. + +Before any formal `dev-cd-apply`, operators must refresh +`deploy/artifact-catalog.dev.json`, `deploy/k8s/base/workloads.yaml`, and +`deploy/deploy.json`, commit/push that promotion, and verify the desired-state +plan points at the intended `sourceCommitId`. If `deploy/deploy.json` still +names an older commit, CD will correctly keep deploying that older promotion +even when a newer publish report exists. Do not treat the newest CI publish +report, or a later bookkeeping commit, as implicit CD desired state. If publish is blocked, keep the report blocked rather than inventing digests: