feat(deploy): roll production back when the post-deploy checks fail - #150
Merged
Merged
Conversation
Before upload, record the deployment production serves now through the shared cloudflare-pages module's read-only previous_production_deployment (no upload if it cannot be read). On a red live smoke: rollback(target) through the same module (it confirms Cloudflare's canonical deployment is the target), re-run the fresh smoke against https://aml-filter.com, and fail loudly either way: recovered, STILL BROKEN after rollback, or automatic rollback refused (roll back by hand). Both shared modules and CENTRAL_MODULE_SHA are pinned to hseshadr/ci#51 head e11bcef (dd19871 + the rollback commits only). Re-pin to the ci merge SHA after ci#51 merges. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
…8c14e A failed live identity verification (production serving the wrong commit or bundle after upload) now takes the same path as a red smoke: rollback to the recorded target, a recovery smoke against the live domain, and one loud failure. The smoke is skipped once identity fails, so a job rolls back at most once however many checks fail. Re-pin both shared modules and CENTRAL_MODULE_SHA to hseshadr/ci#51 head 468c14e (test cleanup only; same module behaviour). Still a draft: re-pin to the ci merge SHA after ci#51 merges. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
Both shared modules (foundation, cloudflare-pages), CENTRAL_MODULE_SHA and the pin contract tests now point at hseshadr/ci main 363be0b, the merge of ci#51 (verified Pages rollback). Same tree as the previously pinned PR head 468c14e. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TL;DR
When the post-deploy live smoke (#148) goes red, production now rolls itself back to the deployment that was live before the upload, then gets checked again in a real browser. The job still fails, and the error says which of three outcomes happened.
Claim touched: "a release that fails in a real browser does not stay live."
Flow
previous_production_deployment(token, account, "aml-filter"). It's read-only and records the target. If it can't be read, there's no upload, because a deploy we can't roll back is refused.rollback(token, account, "aml-filter", deployment_id=target)through the shared module, which confirms Cloudflare'scanonical_deploymentis now the target. Then the fresh smoke re-runs against https://aml-filter.com, without the SHA pin because the restored release is older.LiveSmokeFailedErroreither way:rolled production back from X to Y …; recovery smoke PASSED(production recovered, the release is still bad)recovery smoke FAILED … production is STILL BROKEN after rollbackautomatic rollback FAILED: <reason> … roll back … by hand now(no recheck)Rollback happens only through the shared module (
dag.cloudflare_pages()), so the contract that confines provider mutation still holds.Red → green
test_smoke.py: recovered / still broken / rollback refused)construct:deploy; no rollback on green; no upload if target unreadable; red smoke → rollback(recorded target) → recovery smoke; recovery also red → "STILL BROKEN"; rollback refused → manual, no recheck; recovery container = fresh, no SHA pin_live_verifyerror → rollback exactly once → recovery smoke, post-deploy smoke skipped; red smoke + red recovery → still exactly one rollbacktest_should_pin_both_shared_modules_to_exact_central_main)Gates:
.dagger180 passed / 1 skipped (includes the realdagger functions/--helpschema tests against the 363be0b modules); ruff, mypy, xenon A clean.Unverified
🤖 Generated with Claude Code
https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a