Repository navigation
feat(deploy): add shared-networks input for cross-stack networks - #100
Conversation
Stacks that talk across Compose projects (Traefik and every routed service) have relied on a network owned by one project: piwine's `dockge_default` belongs to the dockge stack. That makes deploy order load-bearing on a fresh host and lets the owner's `down` try to remove a network every other stack is attached to. `shared-networks` lists bridge networks that deploy and rollback create (if missing) before any `up`, via scripts/deployment/ensure-shared-networks.sh. They belong to no Compose project, and a `com.compose-workflow.shared` label exempts them from docker-prune's network prune. Both jobs check out the scripts at job.workflow_sha only when the input is set: deploy's own target checkout runs `git clean -ffdx`, so prepare's copy never survives into it, and rollback had no checkout at all. Empty by default, so existing callers are unaffected.
Reviewer's GuideThe PR adds an opt-in shared-network lifecycle: deploy and rollback provision validated, unowned bridge networks before stacks start, while a shared label preserves them from pruning; workflow checkout handling and project documentation are updated accordingly. Sequence diagram for shared-network provisioning during deploy and rollbacksequenceDiagram
participant Workflow
participant ComposeWorkflow as compose-workflow checkout
participant Ensure as ensure-shared-networks.sh
participant Docker
participant Stacks
Workflow->>Workflow: Read shared-networks
alt shared-networks is set
Workflow->>ComposeWorkflow: Checkout at job.workflow_sha
Workflow->>Ensure: Run with network names
loop Each network
Ensure->>Docker: network inspect
alt Network missing
Ensure->>Docker: network create --driver bridge --label
else Network exists
Ensure-->>Workflow: Reuse network
end
end
Workflow->>Stacks: Start deploy or rollback stacks
else shared-networks is empty
Workflow->>Stacks: Continue without provisioning
end
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 2 issues
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path=".github/workflows/deploy.yml" line_range="971-972" />
<code_context>
+ # The checkout above cleans the workspace; re-fetch the scripts, pinned
+ # to this workflow's commit as in the prepare job.
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
+ if: |
+ steps.skip-gate.outputs.skipped == 'false'
</code_context>
<issue_to_address>
**Rollback recovery stops before restoring prior state**
When the rollback helper checkout or shared-network validation or setup fails, the rollback job skips `Resolve rollback plan` and its recovery steps, leaving the failed target tree deployed and removed stacks offline.
Run rollback planning and restoration even when helper checkout or network setup fails, since recovery does not require network setup.
Also at `.github/workflows/deploy.yml:537`, `.github/workflows/deploy.yml:978-979`, `.github/workflows/deploy.yml:983`, `scripts/deployment/ensure-shared-networks.sh:29-32`.
</issue_to_address>
### Comment 2
<location path="scripts/deployment/ensure-shared-networks.sh" line_range="39" />
<code_context>
+ if [[ -n "$project" ]]; then
+ echo "::warning::shared network $net is owned by Compose project '$project'; its 'down' will try to remove it"
+ fi
+ log_success "$net exists"
+ else
+ docker network create --driver bridge --label "$SHARED_LABEL" "$net" >/dev/null
</code_context>
<issue_to_address>
**Shared networks disappear after pruning**
When a configured shared network already exists without the shared label and has no attached containers when post-deploy pruning runs, the ensure script logs success without making the reused network exempt from the label-filtered prune, so Docker removes it and later external Compose starts fail; recreating it as a plain bridge can also lose existing network configuration.
Ensure reused shared networks are protected from the label-filtered prune, either by applying the shared label or otherwise excluding them from pruning.
Also at `.github/workflows/deploy.yml:916`.
</issue_to_address>Sourcery assessment
Needs a human reviewer. 2 findings to address first, and if the workflow or network handling is wrong, deployments may fail or create shared bridge networks that remain after reverting the change. The networks are bounded and can be inspected and removed manually, but reverting alone does not undo them.
Blocking findings: .github/workflows/deploy.yml:972, scripts/deployment/ensure-shared-networks.sh:39
…on unlabelled shared networks Addresses Sourcery review on #100: - rollback: continue-on-error on the scripts checkout and Ensure shared networks, so a failure there cannot skip the plan/restore steps. - ensure-shared-networks.sh: warn when a pre-existing network lacks the shared label (prune would remove it while idle). Labels are immutable, so it is reused, never recreated automatically.
Why
piwine's Traefik-routed stacks all join
dockge_default, a network owned by the dockge Compose project (being retired). A project-owned shared network makes deploy order load-bearing on a fresh host, and the owner'sdowntries to remove a network every other stack is attached to.What
shared-networks(space-separated, default empty → no-op for existing callers).scripts/deployment/ensure-shared-networks.sh: idempotently creates each missing network as a plain bridge labelledcom.compose-workflow.shared=true; warns if an existing one is owned by a Compose project; validates names.up).job.workflow_sha, gated on the input. Deploy's target checkout runsgit clean -ffdx, so prepare's.compose-workflownever survives into it; rollback had no checkout.docker-prunenetwork prune now skips the shared label.Testing
job.workflow_sha(older local binary; also on prepare's existing checkout).First consumer: docker-piwine (
shared-networks: "proxy backup"), after Renovate bumps its pin.Summary by Sourcery
Support Compose stacks that rely on external cross-stack networks by provisioning and preserving shared networks throughout deployment and rollback.
New Features:
shared-networksdeployment input for creating cross-stack bridge networks before deployments and rollbacks.Bug Fixes:
Enhancements:
Deployment:
Documentation: