From f541eb3d683c65c1ee02459d8f9b77a47c8d9418 Mon Sep 17 00:00:00 2001 From: ali Date: Mon, 24 Aug 2026 07:20:11 +0330 Subject: [PATCH 1/2] fix(deploy): use docker compose v2 for staging NC deploy; stop masking failures MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The staging deploy called `docker-compose` v1.29.2, which crashes with `KeyError: 'ContainerConfig'` when recreating a BuildKit-format image (it choked recreating the `redis-all` dependency). That left notification-center stopped and never restarted — yet the run went GREEN, because the failing `up` was not the last command: the trailing `docker image prune` (exit 0) masked it (no `set -e`). NC was silently down on staging from ~Aug 21 until manually restarted. Switch to `docker compose` v2 (already installed on the host as v2.40.0, and what the prod/main pipeline already uses), add `set -e` so a failed deploy fails RED, pin `-f docker-compose.staging.yml` for a deterministic image tag, and `--no-deps` so the deploy doesn't churn the redis-all container. Co-Authored-By: Claude Opus 4.8 --- .github/workflows/staging-pipeline.yml | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/.github/workflows/staging-pipeline.yml b/.github/workflows/staging-pipeline.yml index 59ae8c2..84cbcff 100644 --- a/.github/workflows/staging-pipeline.yml +++ b/.github/workflows/staging-pipeline.yml @@ -92,8 +92,16 @@ jobs: key: ${{ secrets.STAGING_PRIVATE_KEY_ALL }} port: ${{ secrets.SSH_PORT }} script: | + set -e cd giveth-all - docker-compose stop notification-center - docker-compose pull notification-center - docker-compose up -d notification-center + # Use docker compose v2 (host has v2.40.0). The old `docker-compose` + # v1.29.2 crashes with `KeyError: 'ContainerConfig'` when recreating a + # BuildKit-format image (it choked on the redis-all dep), which left NC + # stopped-and-not-restarted while the run still went green — the failure + # was masked by the trailing `prune` (last command, exit 0). `set -e` + # makes a failed deploy fail RED; `-f docker-compose.staging.yml` pins the + # staging image tag deterministically; `--no-deps` avoids churning + # redis-all. Mirrors the prod (main) pipeline, which already uses v2. + docker compose -f docker-compose.staging.yml pull notification-center + docker compose -f docker-compose.staging.yml up -d --no-deps notification-center docker image prune -a --force From 72947c9243672325495afee0f7f75aff7d15b4a5 Mon Sep 17 00:00:00 2001 From: ali Date: Mon, 24 Aug 2026 21:34:25 +0330 Subject: [PATCH 2/2] =?UTF-8?q?fix(deploy):=20address=20review=20=E2=80=94?= =?UTF-8?q?=20best-effort=20prune=20+=20least-privilege=20token=20permissi?= =?UTF-8?q?ons?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Guard `docker image prune` (|| echo) so a cleanup failure can't fail an already-successful deploy under `set -e`. - Add least-privilege GITHUB_TOKEN permissions: workflow-level `{}`, test `contents:read`, publish `contents:read`+`packages:write`, deploy `{}`. Both per CodeRabbit review on PR #138. Co-Authored-By: Claude Opus 4.8 --- .github/workflows/staging-pipeline.yml | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/.github/workflows/staging-pipeline.yml b/.github/workflows/staging-pipeline.yml index 84cbcff..a517045 100644 --- a/.github/workflows/staging-pipeline.yml +++ b/.github/workflows/staging-pipeline.yml @@ -7,9 +7,16 @@ on: pull_request: branches: - staging + +# Least-privilege GITHUB_TOKEN: deny everything at the workflow level, then grant +# only what each job actually needs (see per-job `permissions` below). +permissions: {} + jobs: test: runs-on: ubuntu-latest + permissions: + contents: read services: # Label used to access the service container redis: @@ -56,6 +63,9 @@ jobs: publish: needs: test runs-on: ubuntu-latest + permissions: + contents: read + packages: write if: github.event_name == 'push' steps: - name: Check out the repo @@ -83,6 +93,8 @@ jobs: deploy: needs: publish runs-on: ubuntu-latest + # No GITHUB_TOKEN needed: the SSH action authenticates with a deploy key. + permissions: {} steps: - name: SSH and Redeploy uses: appleboy/ssh-action@v1.0.0 @@ -104,4 +116,6 @@ jobs: # redis-all. Mirrors the prod (main) pipeline, which already uses v2. docker compose -f docker-compose.staging.yml pull notification-center docker compose -f docker-compose.staging.yml up -d --no-deps notification-center - docker image prune -a --force + # Best-effort cleanup — never fail an already-successful deploy if prune + # errors (e.g. an image still in use); `set -e` would otherwise turn it red. + docker image prune -a --force || echo "Image cleanup failed (non-fatal)" >&2