Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 1cb09525e3 |
@@ -14,7 +14,7 @@ Preconditions and the plan, without side effects:
|
||||
Config is `.release.conf` here plus `make release-vars`. The process itself lives in
|
||||
`~/.claude/skills/release/`; why it is shaped this way is in README.md §Releasing.
|
||||
|
||||
Two things about this repo specifically:
|
||||
Three things about this repo specifically:
|
||||
|
||||
- **The image is scanned after it is published, not before.** `scan-image` runs trivy
|
||||
against the pushed image, because trivy cannot read a locally built one on this runner.
|
||||
@@ -25,6 +25,16 @@ Two things about this repo specifically:
|
||||
so `chart-bump` needs `--image "$IMAGE"` to know which one moves. That sidecar backs up
|
||||
SQLite; the Postgres move (#2) retires it in favour of a `postgresql` CR with a k8up
|
||||
`pg_dump` annotation, after which only the app image's tag is left.
|
||||
- **Two demos pin this image, and `chart-bump` moves neither.** `terdut-demo` in
|
||||
`Ryuvia/charts` is a `TerdutServer` CR that terdut-operator reconciles, and its
|
||||
`values.yaml` `image.tag` is meant to match production's pin (same digest). The kind demo
|
||||
in terdut-operator (`examples/demo/01-server.yaml`) pins a tag too. A release only bumps
|
||||
the `terdut-server` wrapper, so both drift silently: `terdut-demo` sat at v0.37.0 through
|
||||
v0.41.0-v0.43.0 until it was synced on 2026-10-08. After a release, bump `terdut-demo`'s
|
||||
tag to the same `image-digest` and its `Chart.yaml` `version:` (Flux reconciles on
|
||||
ChartVersion), as its own PR, and say in the release report whether you did. Neither
|
||||
demo has anything but the pin to change, but read the version range's migrations first:
|
||||
the demo's Postgres migrates forward at startup.
|
||||
|
||||
## Checks
|
||||
|
||||
|
||||
Reference in New Issue
Block a user