- deploy_app: checkout the pinned tag + deploy NON-chaos when a version is pinned (chaos only for version=None / PR-head). Was always -C, which ignored the pin and deployed LATEST -> upgrade no-op. - do_upgrade: assert the deployment actually MOVED (coop-cloud version label and/or image changed) via lifecycle.deployed_identity -> a vacuous no-op upgrade can no longer pass (DG2). - G2: migrate custom-html overlays to the assertion-only contract (override + extend-by-composition + data-continuity; split backup/restore). tests/unit/test_discovery.py proves precedence (5/5). Probe (Adversary's F1d-2 test): hedgedoc deploy-prev=1.10.7 -> upgrade=1.10.8, CHANGED=True. hedgedoc full generic lifecycle green (install/upgrade/backup/restore, deploy-count=1). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
30 lines
1.3 KiB
Python
30 lines
1.3 KiB
Python
"""custom-html — UPGRADE overlay (Phase 1d, DG4): data-continuity, extends the generic upgrade.
|
|
|
|
The orchestrator deployed the previous published version ONCE; this overlay seeds a marker into the
|
|
served volume, performs the in-place upgrade via the shared op helper (`generic.do_upgrade`, which
|
|
also asserts reconverge + serving), then asserts the data SURVIVED. Assertion-only on the shared
|
|
deployment (no deploy/teardown here)."""
|
|
|
|
import os
|
|
import sys
|
|
|
|
sys.path.insert(0, os.path.join(os.path.dirname(__file__), "..", "..", "runner"))
|
|
from harness import generic, lifecycle # noqa: E402
|
|
|
|
MARKER_PATH = "/usr/share/nginx/html/ci-marker.txt"
|
|
|
|
|
|
def test_upgrade_preserves_data(live_app, meta):
|
|
domain = live_app
|
|
# write a data marker into the served volume (nginx serves /usr/share/nginx/html)
|
|
lifecycle.exec_in_app(domain, ["sh", "-c", f"echo upgrade-survives > {MARKER_PATH}"])
|
|
assert lifecycle.http_fetch(domain, "/ci-marker.txt")[1].strip() == "upgrade-survives"
|
|
|
|
# in-place upgrade previous -> target (reuses the generic op: upgrade + assert reconverge/serving)
|
|
generic.do_upgrade(domain, os.environ.get("VERSION") or None, meta)
|
|
|
|
# the data written before the upgrade is still there
|
|
assert (
|
|
lifecycle.http_fetch(domain, "/ci-marker.txt")[1].strip() == "upgrade-survives"
|
|
), "data did not survive the upgrade"
|