Routing allowlists travel in the workflow env, not with the image: a self-heal can recreate Maui with a list its image cannot serve
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 65/100
- Issue 类型
- 重构
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- dockerfile, typescript
调研方向
Examine backend-ts/Dockerfile to add ARG declarations for the routing lists and convert them to ENV. Remove WORKWELL_OFFICIAL_MEASURES and WORKWELL_DERIVED_MEASURES from the deploy and reconcile workflow env arrays. Update official-flip-config.test.ts to read these values from build args instead of jq arrays, and revise docs/DEPLOY.md to describe the new build args approach. Done when the reconciler no longer sets these keys and the parity test confirms the image carries its own routing lists.
由索引模型根据 Issue 内容生成。
描述
The hazard
WORKWELL_OFFICIAL_MEASURES and WORKWELL_DERIVED_MEASURES live in the deploy workflow's env array and are mirrored by the reconciler (reconcile-maui-mieweb.yml), which recreates the container from maui-latest with main's env whenever an in-place restart fails. The lists therefore describe what main expects, while the image describes what the container can serve. The two drift in one realistic sequence, with no operator action:
- A merge adds an id to a list (a newly vendored official measure, or a translation under
measures/derived/). - The first deploy after it fails before its image is built (a VSAC outage at the vendor step is enough; deploys depend on VSAC).
maui-lateststays the older image. The next health event makes the reconciler recreate it withmain's env.- The router refuses at construction (
no executable translation is committedfor a translation; the artifact-not-committed sentence for an official id), the worker logsOFFICIAL_ROUTING_MISCONFIGUREDand still boots, and every evaluating route answers 500 for all routed measures while/actuator/healthstays 200, so nothing heals it.
The same state follows a deliberate rollback to an older image while the key stays on main. Both paths are documented in docs/DEPLOY.md (Step 1 and the rollback section, since #767) with the manual check: confirm the post-merge deploy promoted maui-latest, or unset the key on main. That is a checklist, not a guard.
The fix to decide
Make the routing lists travel with the image, so an image can never be started with a list it cannot serve:
backend-ts/Dockerfile:ARG WORKWELL_OFFICIAL_MEASURES/ARG WORKWELL_DERIVED_MEASURES→ENV, the same reasoning the Dockerfile already gives forWORKWELL_BUILD_SHA; the deploy passes them as build args from one place.- Drop both keys from the deploy and reconcile env arrays; the reconciler then needs no copy to keep in step.
official-flip-config.test.tsreads the build args instead of the jq arrays (the agreement, subset, TWH/staging-none and vendoring-before-build tests keep their meaning; the deploy↔reconcile parity test becomes "the reconciler sets neither key").- CI's
e2e-mauikeeps its plain env (it runs from source, not from the image); the parity test compares it with the build args. docs/DEPLOY.md: the "routing lists are workflow edits only, reconcile must match" trap becomes "routing lists are build args".
Alternative, smaller: the reconciler reads the image's baked build sha and drops a key whose artifact that sha predates. More moving parts for the same outcome.
Why it is not in #767
#767 turned the first translation on; widening it to move both allowlists into the image would have mixed two topics. The hazard class pre-exists for the official list and has been handled by convention; the translation adds one more way the first deploy can fail before the image builds.
Found by the adversarial review of #767 (finding 1).
- 主要语言
- TypeScript
- 星标
- 0
- 派生
- 0
- 平均合并
- 3 小时 6 分钟
- 30 天内合并 PR
- 113
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
Taleef7/workwell 的其他 Issue
-
documentation owner-ops waiting
难度 1/5 1-3 小时 新手友好度 86/100
维护者通常 1 天内回复
-
owner-ops waiting
难度 1/5 1-3 小时 新手友好度 85/100
维护者通常 1 天内回复
-
backend bug
难度 5/5 一周以上 新手友好度 35/100
维护者通常 1 天内回复
-
cql-engine pilot-trust
难度 3/5 1-2 天 新手友好度 72/100
维护者通常 1 天内回复
-
backend enhancement
难度 5/5 一周以上 新手友好度 35/100
维护者通常 1 天内回复
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 85/100
farbenmeer/tapi#531 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
naver/egjs-flicking#971 ·
-
难度 1/5 1 小时以内 新手友好度 85/100
维护者通常 1 天内回复
-
Tenant
难度 2/5 1-3 小时 新手友好度 66/100
MTES-MCT/Dossier-Facile-Frontend#2061 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 85/100
backnotprop/plannotator#1784 ·
维护者通常 1 天内回复