Commit Graph
8 Commits
Author SHA1 Message Date
austinandClaude Opus 5 4f4082ecd7 A pull request must not touch :latest
build-and-publish / build (pull_request) Successful in 2m0s
This runner builds on the host's Docker daemon — the same daemon the live
container runs on — so retagging :latest IS a deployment. Watchtower compares
the running container's image against :latest, sees they differ, and recreates
the container from whatever was just built locally. Gating only the push was
never enough; the build itself was the deploy.

The worse failure is quieter. Reassigning :latest leaves the running
container's old image untagged, and once that image is pruned Watchtower can no
longer read it to compare against:

  Failed to retrieve container image info: No such image: sha256:…
  Unable to update container: no available image info.

bennett-portfolio hit exactly that. It sat on a four-day-old build, failing to
update 720 times in twenty-four hours, reporting healthy the whole time, and had
to be recreated by hand. This repo has the same workflow and the same exposure —
it simply has not been unlucky yet.

A PR now builds pr-<number>, which nothing watches. Trivy scans whatever was
built either way, so a bad Dockerfile or a new CVE still blocks the merge, and
the push step is unchanged — still main-only.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-27 09:53:24 -05:00
austinandClaude Opus 4.8 166222cd67 CI: gate the merge, not just the image
build-and-publish / build (pull_request) Successful in 1m53s
Run the workflow on pull_request too, so tests + build + Trivy must pass before main can be
merged (branch protection requires this check). Push the image only on a real push to main —
never from a PR. Also standardises the workflow across all apps (three had drifted).

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XXKjx7FNyRVAjU8dgB5KhN
2026-07-23 13:53:57 -05:00
austinandClaude Opus 4.8 f7f059638f CI: actually run the tests, and let them gate the image
build-and-publish / build (push) Successful in 2m3s
The image build runs 'mvn -DskipTests' and the workflow was only build -> Trivy -> push, so
no app test has ever run in CI — only Trivy gated a merge. The platform contract tests added
in 0.1.9 were not running either, which defeated their purpose.

They cannot run inside 'docker build' — Testcontainers needs a Docker daemon and a build has
none. Maven runs as a sibling container instead, mounting the workspace volume act_runner
gave this job (matched on GITHUB_WORKSPACE, since it is mounted at the full repo path rather
than at /workspace) and sharing the host network so published test ports resolve as localhost.

Verified on itsthevine before rolling out here: 33 tests ran, and a deliberately failing test
failed the run at the Test step with the registry digest unchanged — no image published.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XXKjx7FNyRVAjU8dgB5KhN
2026-07-23 12:20:41 -05:00
austinandClaude Opus 4.8 48b37d7d6c Pin Testcontainers to 1.x and skip rebuilds for config-only commits
build-and-publish / build (push) Successful in 1m17s
Testcontainers 2.0 renamed the postgresql/junit-jupiter module artifacts, so the major
bump can't even be resolved — disable it rather than let a bot PR reopen it each run.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XXKjx7FNyRVAjU8dgB5KhN
2026-07-22 21:22:43 -05:00
austinandClaude Opus 4.8 2b772d2931 Pin platform 0.1.0 release and wire up automatic propagation
build-and-publish / build (push) Failing after 1m17s
- parent/BOM now point at the immutable 0.1.0 release instead of a SNAPSHOT
- declare the Gitea Maven registry so Renovate can discover new platform versions
- renovate.json: group platform bumps into one automerged PR
- CI: drop --no-cache (releases are immutable, so caching is safe again) and add
  workflow_dispatch so rebuild-all-apps.sh can force an urgent rebuild

Co-Authored-By: Claude Opus 4.8 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XXKjx7FNyRVAjU8dgB5KhN
2026-07-22 21:03:06 -05:00
austinandClaude Opus 4.8 2a0dd1ae6b Restore the app files (prior commit mis-scoped its tar)
build-and-publish / build (push) Failing after 8s
Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-07-22 20:50:58 -05:00
austinandClaude Opus 4.8 eaad7b916e Add admin UI + MinIO image uploads
- Admin API: list/edit posts (incl. drafts, raw markdown), moderate comments, subscribers,
  author bio/links, and presigned image upload to MinIO (bucket is public-read for covers).
- Admin UI at /admin: post editor with cover-image upload, comment moderation, subscriber list.
- Public security switched to authenticated-paths so static assets (/images, /data) stay public.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-07-22 20:50:45 -05:00
austinandClaude Opus 4.8 cbe8a764b0 Rewrite as a Spring Boot app on the Bennett platform
build-and-publish / build (push) Successful in 1m38s
Restores the real backend lost with Supabase (posts, authors, comments, subscriptions, admin) in
Postgres, seeds the existing markdown posts, and rebuilds the site as a Vite/React SPA served by
Spring — keeping the original styling (serif + tan accent) and content.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-07-22 20:35:51 -05:00