Backend runtime upgraded to Python 3.14 with exact dependency pinning (#57)
CICD Start / Sanity and Base Decision (push) Successful in 18s
Runner Canary / Canary Heavy (ubuntu-act-8gb) (push) Has been skipped
Runner Canary / Canary Heavy (ubuntu-act-4gb) (push) Has been skipped
Runner Canary / Canary Burst (ubuntu-act (push) Failing after 11m10s
Runner Canary / Canary (ubuntu-latest) (push) Failing after 12m39s
Runner Canary / Canary (ubuntu-act) (push) Failing after 12m42s

Signed-off-by: Cliff Hill <xlorep@darkhelm.org>

## Summary

Upgrades backend runtime baseline and dependency management for issue #10.

### Changes

1. **Python Baseline**: Updated from 3.13 to 3.14
   - Updated `backend/pyproject.toml` requires-python constraint
   - Updated `backend/pyrightconfig.json` pythonVersion
   - Updated all Dockerfile and CI references

2. **Dependency Pinning**: Switched to exact version pins in `backend/pyproject.toml`
   - All dev and runtime dependencies now use `==` instead of `>=`
   - `fastapi==0.120.2`, `uvicorn==0.38.0`
   - ruff, pyright, pytest suite pinned to current resolved versions
   - Regenerated `backend/uv.lock` under Python 3.14

3. **Startup Compatibility Guard** (TDD via RED→GREEN)
   - New `compatibility_status()` function evaluates runtime and pinned deps
   - Startup raises `RuntimeError` if policy fails
   - Implemented via FastAPI lifespan (non-deprecated) handler

4. **Compatibility Status Endpoint**
   - New `GET /compatibility` returns policy status, runtime version, and package checks
   - Shares single source of truth with startup validation

5. **Integration Tests**
   - Added failing-then-passing tests for startup guard and endpoint behavior
   - 100% coverage maintained

6. **Direnv Configuration**
   - Added `UV_PYTHON="3.14"` pin to repo `.envrc`
   - Ensures direnv creates/recreates venv with correct Python version

### Validation

-  ruff format/check
-  pyright strict (0 errors)
-  pytest: 8 passed, 100% coverage (>=95 gate)
-  pydoclint: pass
-  xdoctest: pass

### Notes

- SQLAlchemy/SQLModel introduction deferred to next pass per scope
- Compatibility logic currently validates fastapi/uvicorn pins (runtime deps)
- Ready for container build validation and Renovate bot testing

Co-authored-by: copilotcoder <copilotcoder@darkhelm.org>
Reviewed-on: #57
Co-authored-by: Cliff Hill <xlorep@darkhelm.org>
Co-committed-by: Cliff Hill <xlorep@darkhelm.org>
This commit was merged in pull request #57.
This commit is contained in:
2026-06-18 11:19:24 -04:00
committed by darkhelm
co-authored by copilotcoder
parent 5d74dd8d8f
commit d02039a22e
52 changed files with 4480 additions and 966 deletions
+12 -4
View File
@@ -16,6 +16,7 @@ NC='\033[0m' # No Color
BASE_IMAGE_TAG="cicd-base:local"
COMPLETE_IMAGE_TAG="cicd:local"
PROJECT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
BASE_HASH_HELPER="$PROJECT_DIR/scripts/compute-cicd-base-hash.sh"
TEMP_SSH_KEY="/tmp/cicd_build_ssh_key"
# Functions
@@ -93,6 +94,11 @@ check_requirements() {
exit 1
fi
if [[ ! -x "$BASE_HASH_HELPER" ]]; then
log_error "Base hash helper is missing or not executable: $BASE_HASH_HELPER"
exit 1
fi
log_success "Requirements check passed"
}
@@ -107,8 +113,8 @@ build_base_image() {
local start_time=$(date +%s)
# Calculate base Dockerfile hash for tagging
local base_hash=$(sha256sum "$PROJECT_DIR/Dockerfile.cicd-base" | cut -d' ' -f1 | head -c16)
# Calculate the canonical base hash used by CI and local builds.
local base_hash=$("$BASE_HASH_HELPER")
log_info "Base Dockerfile hash: $base_hash"
# Build base image
@@ -129,7 +135,9 @@ build_base_image() {
# Show image size
local image_size=$(docker images --format "table {{.Repository}}:{{.Tag}}\t{{.Size}}" | grep "$BASE_IMAGE_TAG" | awk '{print $2}')
log_info "Base image size: $image_size (includes Playwright browsers)"
}build_complete_image() {
}
build_complete_image() {
log_info "Building CICD complete image..."
# Check if base image exists
@@ -194,7 +202,7 @@ test_images() {
if [[ "$BUILD_BASE" == "true" ]] && docker image inspect "$BASE_IMAGE_TAG" &> /dev/null; then
log_info "Testing base image..."
if docker run --rm "$BASE_IMAGE_TAG" python3.13 --version && \
if docker run --rm "$BASE_IMAGE_TAG" python3.14 --version && \
docker run --rm "$BASE_IMAGE_TAG" node --version && \
docker run --rm "$BASE_IMAGE_TAG" yarn --version && \
docker run --rm "$BASE_IMAGE_TAG" uv --version && \