fix: plan secret graph transitions - #108
Merged
Merged
Conversation
Read the active generation against the deployed release snapshot instead of the incoming secret graph. This preserves partial-state detection while allowing workloads to enter or leave the secret graph during a normal deploy.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Failure reproduced
A deployed release had one secret-consuming workload. The next project added a second workload with an isolated SOPS file. Planning inspected the old runtime using the new two-workload graph and rejected the intentionally unlabeled newcomer as
runtime workloads only partially select a secret generation.Approach
The immutable
ob.snapshot.ymlis already the authority for rollback and secret push. Deployment planning now loads that snapshot to identify the old affected workload set, reads the old generation against that set, and stages the incoming graph under a fresh generation when inputs differ.Validation
just checkpasses, including tidy, vet, all Go tests, binary/doc generation, Astro check/build, and table checksgit diff --checkpass