Compare commits

...
3 Commits
Author SHA1 Message Date
devx-ci-bot f1dc00682d release: v0.55.0 [skip ci] 2026-09-19 19:49:53 +00:00
kireto af24a6a771 DEVX-172: feat(ci): retry dep-PR container verification until publish lands
Post-merge / detect-and-configure (push) Successful in 11s
Post-merge / release-and-maintain (push) Successful in 1m25s
2026-09-19 19:49:09 +00:00
gitea-actions-bot 457f52cba7 chore: update badge URLs to commit 9eabfdd8 [skip ci] 2026-09-19 19:31:24 +00:00
9 changed files with 151 additions and 47 deletions
+6
View File
@@ -2,6 +2,12 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
## [0.55.0] - 2026-09-19
### Features
- *(ci)* Retry dep-PR container verification until publish lands
## [0.54.0] - 2026-09-19 ## [0.54.0] - 2026-09-19
### Features ### Features
+9 -9
View File
@@ -16,12 +16,12 @@ quality badges.
[![CI](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions/workflows/ci.yml/badge.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions) [![CI](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions/workflows/ci.yml/badge.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
[![License: GPL-3.0](https://img.shields.io/badge/license-GPL--3.0-blue)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE) [![License: GPL-3.0](https://img.shields.io/badge/license-GPL--3.0-blue)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE)
[![Coverage](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/a281b56d1ab5db23f55813a38900549d740ea527/coverage.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions) [![Coverage](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/9eabfdd80f0a4232448178062a4dc63af23c84d4/coverage.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
[![Tests](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/a281b56d1ab5db23f55813a38900549d740ea527/tests.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions) [![Tests](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/9eabfdd80f0a4232448178062a4dc63af23c84d4/tests.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
[![Docs](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/a281b56d1ab5db23f55813a38900549d740ea527/docs.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki) [![Docs](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/9eabfdd80f0a4232448178062a4dc63af23c84d4/docs.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
[![Code Quality](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/a281b56d1ab5db23f55813a38900549d740ea527/quality.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions) [![Code Quality](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/9eabfdd80f0a4232448178062a4dc63af23c84d4/quality.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
[![Version](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/a281b56d1ab5db23f55813a38900549d740ea527/version.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases) [![Version](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/9eabfdd80f0a4232448178062a4dc63af23c84d4/version.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
[![Python](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/a281b56d1ab5db23f55813a38900549d740ea527/python.svg)](https://www.python.org/downloads/) [![Python](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/9eabfdd80f0a4232448178062a4dc63af23c84d4/python.svg)](https://www.python.org/downloads/)
## Why devx? ## Why devx?
@@ -87,7 +87,7 @@ extra index and list devx in your dependencies:
```toml ```toml
[project] [project]
dependencies = [ dependencies = [
"devx>=0.54.0", "devx>=0.55.0",
] ]
[tool.pip] [tool.pip]
@@ -101,8 +101,8 @@ pip install -e .
``` ```
> **Note:** If your project requires a specific devx version, pin it in > **Note:** If your project requires a specific devx version, pin it in
> `dependencies` (for example, `"devx==0.54.0"`) or use a version constraint > `dependencies` (for example, `"devx==0.55.0"`) or use a version constraint
> (for example, `"devx>=0.54.0,<0.55"`). > (for example, `"devx>=0.55.0,<0.56"`).
### Optional extras ### Optional extras
+8 -8
View File
@@ -12,12 +12,12 @@ project to be reusable across all oblachno-oss repositories.
[![CI](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions/workflows/ci.yml/badge.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions) [![CI](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions/workflows/ci.yml/badge.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
[![License: GPL-3.0](https://img.shields.io/badge/license-GPL--3.0-blue)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE) [![License: GPL-3.0](https://img.shields.io/badge/license-GPL--3.0-blue)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE)
[![Coverage](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/a281b56d1ab5db23f55813a38900549d740ea527/coverage.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions) [![Coverage](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/9eabfdd80f0a4232448178062a4dc63af23c84d4/coverage.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
[![Tests](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/a281b56d1ab5db23f55813a38900549d740ea527/tests.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions) [![Tests](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/9eabfdd80f0a4232448178062a4dc63af23c84d4/tests.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
[![Docs](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/a281b56d1ab5db23f55813a38900549d740ea527/docs.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki) [![Docs](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/9eabfdd80f0a4232448178062a4dc63af23c84d4/docs.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
[![Code Quality](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/a281b56d1ab5db23f55813a38900549d740ea527/quality.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions) [![Code Quality](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/9eabfdd80f0a4232448178062a4dc63af23c84d4/quality.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
[![Version](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/a281b56d1ab5db23f55813a38900549d740ea527/version.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases) [![Version](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/9eabfdd80f0a4232448178062a4dc63af23c84d4/version.svg)](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
[![Python](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/a281b56d1ab5db23f55813a38900549d740ea527/python.svg)](https://www.python.org/downloads/) [![Python](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/raw/commit/9eabfdd80f0a4232448178062a4dc63af23c84d4/python.svg)](https://www.python.org/downloads/)
## Overview ## Overview
@@ -74,14 +74,14 @@ Add devx to your `pyproject.toml` dependencies and configure the registry:
```toml ```toml
[project] [project]
dependencies = [ dependencies = [
"devx>=0.54.0", "devx>=0.55.0",
] ]
[tool.pip] [tool.pip]
extra-index-url = "https://git.oblachno.oblachno.fyi/api/packages/oblachno-oss/pypi/simple" extra-index-url = "https://git.oblachno.oblachno.fyi/api/packages/oblachno-oss/pypi/simple"
``` ```
Pin a specific version if needed: `"devx==0.54.0"` or `"devx>=0.54.0,<0.55"`. Pin a specific version if needed: `"devx==0.55.0"` or `"devx>=0.55.0,<0.56"`.
### Optional extras ### Optional extras
+32
View File
@@ -0,0 +1,32 @@
# DEVX-172: dep-PR retries container verification until publish lands
## Problem
Post-merge dep-PR runs concurrently with the producer's image-build
workflow. `--verify-container` hits HTTP 404 before the push lands and
skips PR creation — observed for sso-bridge v0.4.1 and v0.4.3.
## Approach
REQ-1: `resolve_container_digest(..., timeout_s)` retries a 404 lookup
every 15s until the deadline.
REQ-2: `--verify-timeout` CLI option (default 600s, 0 disables) wires the
retry into the dep-PR step.
## Test Plan
- Unit test: 404-then-200 resolves the digest without raising.
- Existing no-retry path (timeout_s=0) still fails immediately.
## Deploy Plan
devx release tag; producers inherit the 600s default on next pin bump.
## Rollback Plan
Revert; dep-PR verification fails fast on 404 again (status quo).
## Acceptance Criteria
- [x] REQ-1: 404 responses retry until `timeout_s` deadline.
- [x] REQ-2: `--verify-timeout` option exposed, default 600.
+2 -2
View File
@@ -48,12 +48,12 @@ Add devx to your `pyproject.toml`:
```toml ```toml
[project] [project]
dependencies = [ dependencies = [
"devx>=0.54.0", "devx>=0.55.0",
] ]
[project.optional-dependencies] [project.optional-dependencies]
dev = [ dev = [
"devx>=0.54.0", "devx>=0.55.0",
] ]
``` ```
+1 -1
View File
@@ -6,4 +6,4 @@ create_dependency_pr, auto_merge, release, publish), developer tooling
molecule testing helpers for Ansible projects. molecule testing helpers for Ansible projects.
""" """
__version__ = "0.54.0" __version__ = "0.55.0"
+56 -27
View File
@@ -22,6 +22,7 @@ from __future__ import annotations
import re import re
import subprocess # nosec B404 import subprocess # nosec B404
import tempfile import tempfile
import time
from datetime import UTC, datetime from datetime import UTC, datetime
from pathlib import Path from pathlib import Path
@@ -95,7 +96,7 @@ def update_pinned_version(file_path: str, package: str, old_version: str, new_ve
return changed return changed
def resolve_container_digest(api_url: str, owner: str, name: str, tag: str, token: str) -> str: def resolve_container_digest(api_url: str, owner: str, name: str, tag: str, token: str, timeout_s: int = 0) -> str:
"""Resolve the OCI digest for a container image tag via the packages API. """Resolve the OCI digest for a container image tag via the packages API.
Implements REQ-1: dependency PRs must only be opened after the producer Implements REQ-1: dependency PRs must only be opened after the producer
@@ -103,34 +104,52 @@ def resolve_container_digest(api_url: str, owner: str, name: str, tag: str, toke
the registry call fails, so the PR is never opened against an artifact the registry call fails, so the PR is never opened against an artifact
that has not been published. The sha256 of the stored ``manifest.json`` that has not been published. The sha256 of the stored ``manifest.json``
blob is the manifest content digest (what ``docker pull`` reports). blob is the manifest content digest (what ``docker pull`` reports).
Implements REQ-2: ``timeout_s`` > 0 retries the lookup every 15s until
the deadline — the dep-PR step races the producer's image-build
workflow, which pushes the tag concurrently.
""" """
url = f"{api_url}/packages/{owner}/container/{name}/{tag}/files" url = f"{api_url}/packages/{owner}/container/{name}/{tag}/files"
headers = {"Authorization": f"token {token}"} headers = {"Authorization": f"token {token}"}
try: deadline = time.monotonic() + timeout_s
resp = requests.get(url, headers=headers, timeout=30) # nosec B310 while True:
resp.raise_for_status() try:
except requests.HTTPError as e: resp = requests.get(url, headers=headers, timeout=30) # nosec B310
status = e.response.status_code if e.response is not None else "?" resp.raise_for_status()
raise click.ClickException( except requests.HTTPError as e:
_( if e.response is not None and e.response.status_code == 404 and time.monotonic() < deadline:
"Container artifact {owner}/{name}:{tag} not found or unreadable (HTTP {status}). " click.echo(
"Refusing to open a dependency PR for an unpublished artifact.", _(
owner=owner, "[dep-pr] {owner}/{name}:{tag} not published yet — retrying.",
name=name, owner=owner,
tag=tag, name=name,
status=status, tag=tag,
) )
) from e )
except requests.RequestException as e: time.sleep(15)
raise click.ClickException( continue
_( status = e.response.status_code if e.response is not None else "?"
"Registry lookup failed for {owner}/{name}:{tag}: {error}", raise click.ClickException(
owner=owner, _(
name=name, "Container artifact {owner}/{name}:{tag} not found or unreadable (HTTP {status}). "
tag=tag, "Refusing to open a dependency PR for an unpublished artifact.",
error=e, owner=owner,
) name=name,
) from e tag=tag,
status=status,
)
) from e
except requests.RequestException as e:
raise click.ClickException(
_(
"Registry lookup failed for {owner}/{name}:{tag}: {error}",
owner=owner,
name=name,
tag=tag,
error=e,
)
) from e
break
for f in resp.json(): for f in resp.json():
if f.get("name") == "manifest.json" and f.get("sha256"): if f.get("name") == "manifest.json" and f.get("sha256"):
return f"sha256:{f['sha256']}" return f"sha256:{f['sha256']}"
@@ -243,6 +262,15 @@ def create_vikunja_task(title: str, description: str, project_id: int = 0) -> st
"__version__ tag vs a release git tag." "__version__ tag vs a release git tag."
), ),
) )
@click.option(
"--verify-timeout",
type=int,
default=600,
help=_(
"Seconds to keep retrying --verify-container while the artifact returns 404 "
"(the image build races this step). 0 disables retries."
),
)
@click.option( @click.option(
"--task-project-id", "--task-project-id",
type=int, type=int,
@@ -263,6 +291,7 @@ def cli(
verify_container: str, verify_container: str,
source_ref: str, source_ref: str,
container_tag: str, container_tag: str,
verify_timeout: int,
task_project_id: int, task_project_id: int,
dry_run: bool, dry_run: bool,
) -> None: ) -> None:
@@ -283,7 +312,7 @@ def cli(
) )
c_owner, c_name = verify_container.split("/", 1) c_owner, c_name = verify_container.split("/", 1)
image_tag = container_tag or new_version image_tag = container_tag or new_version
image_digest = resolve_container_digest(GITEA_API_URL, c_owner, c_name, image_tag, token) image_digest = resolve_container_digest(GITEA_API_URL, c_owner, c_name, image_tag, token, verify_timeout)
click.echo( click.echo(
_( _(
"[dep-pr] Verified {container}:{version} -> {digest}", "[dep-pr] Verified {container}:{version} -> {digest}",
+16
View File
@@ -3159,6 +3159,14 @@
"ru": "SSH_PRIVATE_KEY не задан — пропуск настройки SSH-ключа", "ru": "SSH_PRIVATE_KEY не задан — пропуск настройки SSH-ключа",
"zh": "SSH_PRIVATE_KEY 未设置 — 跳过 SSH 密钥设置" "zh": "SSH_PRIVATE_KEY 未设置 — 跳过 SSH 密钥设置"
}, },
"Seconds to keep retrying --verify-container while the artifact returns 404 (the image build races this step). 0 disables retries.": {
"bg": "Секунди за повторни опити на --verify-container, докато артефактът връща 404 (компилацията на изображението е конкурентна). 0 изключва повторните опити.",
"de": "Sekunden, die --verify-container bei HTTP 404 weiter versucht wird (der Image-Build läuft parallel). 0 deaktiviert Wiederholungen.",
"en": "Seconds to keep retrying --verify-container while the artifact returns 404 (the image build races this step). 0 disables retries.",
"pl": "Sekundy ponawiania --verify-container, gdy artefakt zwraca 404 (budowa obrazu jest współbieżna). 0 wyłącza ponawianie.",
"ru": "Секунды повторных попыток --verify-container, пока артефакт возвращает 404 (сборка образа идёт параллельно). 0 отключает повторы.",
"zh": "当构件返回 404 时 --verify-container 的重试秒数(镜像构建与此步骤并行)。0 禁用重试。"
},
"Show what would be done without creating PR": { "Show what would be done without creating PR": {
"bg": "Покажи какво би било направено без създаване на PR", "bg": "Покажи какво би било направено без създаване на PR",
"de": "Zeigen, was getan würde, ohne PR zu erstellen", "de": "Zeigen, was getan würde, ohne PR zu erstellen",
@@ -3831,6 +3839,14 @@
"ru": "[dep-pr] Проверено {container}:{version} -> {digest}", "ru": "[dep-pr] Проверено {container}:{version} -> {digest}",
"zh": "[dep-pr] 已验证 {container}:{version} -> {digest}" "zh": "[dep-pr] 已验证 {container}:{version} -> {digest}"
}, },
"[dep-pr] {owner}/{name}:{tag} not published yet — retrying.": {
"bg": "[dep-pr] {owner}/{name}:{tag} още не е публикуван — повторен опит.",
"de": "[dep-pr] {owner}/{name}:{tag} noch nicht veröffentlicht — neuer Versuch.",
"en": "[dep-pr] {owner}/{name}:{tag} not published yet — retrying.",
"pl": "[dep-pr] {owner}/{name}:{tag} jeszcze nie opublikowano — ponawianie.",
"ru": "[dep-pr] {owner}/{name}:{tag} ещё не опубликован — повторная попытка.",
"zh": "[dep-pr] {owner}/{name}:{tag} 尚未发布 — 正在重试。"
},
"[dep-pr] {pkg} already at {version} — no PR needed.": { "[dep-pr] {pkg} already at {version} — no PR needed.": {
"bg": "[dep-pr] {pkg} вече е на {version} — не е нужен PR.", "bg": "[dep-pr] {pkg} вече е на {version} — не е нужен PR.",
"de": "[dep-pr] {pkg} bereits auf {version} — kein PR nötig.", "de": "[dep-pr] {pkg} bereits auf {version} — kein PR nötig.",
+21
View File
@@ -621,3 +621,24 @@ class TestBranchCreation:
# PR title carries the task ID # PR title carries the task ID
assert client.create_pr.call_args.kwargs["title"] == "OBL-INFRA-581: Bump sso_bridge to 0.9.1" assert client.create_pr.call_args.kwargs["title"] == "OBL-INFRA-581: Bump sso_bridge to 0.9.1"
mock_task.assert_called_once() mock_task.assert_called_once()
def test_retries_404_until_published(self) -> None:
import requests
from devx.ci.create_dependency_pr import resolve_container_digest
err = requests.HTTPError("404")
err.response = MagicMock(status_code=404)
fail = MagicMock()
fail.raise_for_status.side_effect = err
ok = MagicMock()
ok.raise_for_status = MagicMock()
ok.json.return_value = [{"name": "manifest.json", "sha256": "cafe"}]
with (
patch("devx.ci.create_dependency_pr.requests.get", side_effect=[fail, ok]),
patch("devx.ci.create_dependency_pr.time.sleep"),
):
digest = resolve_container_digest(
"https://git.example.com/api/v1", "oblachno", "sso-bridge", "0.9.1", "tok", timeout_s=60
)
assert digest == "sha256:cafe"