Files
plex-playlist/scripts/gitea-actions/rollout-one-runner.xsh
Cliff Hill d02039a22e
Some checks failed
CICD Start / Sanity and Base Decision (push) Successful in 18s
Runner Canary / Canary Heavy (ubuntu-act-8gb) (push) Has been skipped
Runner Canary / Canary Heavy (ubuntu-act-4gb) (push) Has been skipped
Runner Canary / Canary Burst (ubuntu-act (push) Failing after 11m10s
Runner Canary / Canary (ubuntu-latest) (push) Failing after 12m39s
Runner Canary / Canary (ubuntu-act) (push) Failing after 12m42s
Backend runtime upgraded to Python 3.14 with exact dependency pinning (#57)
Signed-off-by: Cliff Hill <xlorep@darkhelm.org>

## Summary

Upgrades backend runtime baseline and dependency management for issue #10.

### Changes

1. **Python Baseline**: Updated from 3.13 to 3.14
   - Updated `backend/pyproject.toml` requires-python constraint
   - Updated `backend/pyrightconfig.json` pythonVersion
   - Updated all Dockerfile and CI references

2. **Dependency Pinning**: Switched to exact version pins in `backend/pyproject.toml`
   - All dev and runtime dependencies now use `==` instead of `>=`
   - `fastapi==0.120.2`, `uvicorn==0.38.0`
   - ruff, pyright, pytest suite pinned to current resolved versions
   - Regenerated `backend/uv.lock` under Python 3.14

3. **Startup Compatibility Guard** (TDD via RED→GREEN)
   - New `compatibility_status()` function evaluates runtime and pinned deps
   - Startup raises `RuntimeError` if policy fails
   - Implemented via FastAPI lifespan (non-deprecated) handler

4. **Compatibility Status Endpoint**
   - New `GET /compatibility` returns policy status, runtime version, and package checks
   - Shares single source of truth with startup validation

5. **Integration Tests**
   - Added failing-then-passing tests for startup guard and endpoint behavior
   - 100% coverage maintained

6. **Direnv Configuration**
   - Added `UV_PYTHON="3.14"` pin to repo `.envrc`
   - Ensures direnv creates/recreates venv with correct Python version

### Validation

-  ruff format/check
-  pyright strict (0 errors)
-  pytest: 8 passed, 100% coverage (>=95 gate)
-  pydoclint: pass
-  xdoctest: pass

### Notes

- SQLAlchemy/SQLModel introduction deferred to next pass per scope
- Compatibility logic currently validates fastapi/uvicorn pins (runtime deps)
- Ready for container build validation and Renovate bot testing

Co-authored-by: copilotcoder <copilotcoder@darkhelm.org>
Reviewed-on: #57
Co-authored-by: Cliff Hill <xlorep@darkhelm.org>
Co-committed-by: Cliff Hill <xlorep@darkhelm.org>
2026-06-18 11:19:24 -04:00

104 lines
3.4 KiB
Plaintext
Executable File

#!/usr/bin/env xonsh
"""Roll out one-runner stabilization on a target host (runner1 active, runner2 removed)."""
import sys
from datetime import datetime
HOST_PATHS = {
"kankali.darkhelm.lan": "/home/darkhelm/Projects/DarkHelm.org/gitea",
"zhokq.darkhelm.lan": "/home/darkhelm/Projects/DarkHelm.org/gitea-runner",
"urtzul.darkhelm.lan": "/home/darkhelm/Projects/DarkHelm.org/gitea-runner",
"pi-desktop.darkhelm.lan": "/home/darkhelm/Projects/DarkHelm.org/gitea-runner",
}
def usage(exit_code=1):
print("Usage: xonsh rollout-one-runner.xsh <host> [--batch]")
print("Hosts:")
for host in HOST_PATHS:
print(f" - {host}")
raise SystemExit(exit_code)
if len(sys.argv) < 2:
usage()
host = sys.argv[1]
if host not in HOST_PATHS:
print(f"Unknown host: {host}")
usage()
batch_mode = "--batch" in sys.argv[2:]
root = HOST_PATHS[host]
ts = datetime.now().strftime("%Y%m%d_%H%M%S")
def ssh(cmd):
if batch_mode:
out = !(ssh -o BatchMode=yes -o ConnectTimeout=20 -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o ControlMaster=auto -o ControlPersist=2h -o ControlPath=~/.ssh/cm-%r@%h:%p @(host) @(cmd))
else:
out = !(ssh -o ConnectTimeout=60 -o ServerAliveInterval=30 -o ServerAliveCountMax=6 -o ControlMaster=auto -o ControlPersist=2h -o ControlPath=~/.ssh/cm-%r@%h:%p @(host) @(cmd))
return out.returncode, str(out.out).rstrip("\n")
print(f"Host: {host}")
print(f"Path: {root}")
print(f"SSH mode: {'batch' if batch_mode else 'interactive'}")
print("Phase 1: pre-change snapshot")
rc, out = ssh(f"docker compose -f {root}/compose.yml config --services")
print(out)
rc, out = ssh("docker inspect gitea-act-runner-1 --format 'runner1 restart={{.RestartCount}} oom={{.State.OOMKilled}} status={{.State.Status}}'")
print(out if rc == 0 else "runner1-missing")
rc, out = ssh("docker inspect gitea-act-runner-2 --format 'runner2 restart={{.RestartCount}} oom={{.State.OOMKilled}} status={{.State.Status}}'")
print(out if rc == 0 else "runner2-missing")
print("Phase 2: backup compose and env")
for backup_step in [
f"mkdir -p {root}/backups",
f"cp -f {root}/compose.yml {root}/backups/compose.yml.{ts}",
f"cp -f {root}/.env {root}/backups/.env.{ts}",
]:
rc, out = ssh(backup_step)
if out:
print(out)
if rc != 0:
print("Backup failed. Aborting.")
raise SystemExit(2)
print("backups-created")
print("Phase 3: switch to one runner")
for may_fail in [
f"docker compose -f {root}/compose.yml stop act_runner_2",
f"docker compose -f {root}/compose.yml rm -f act_runner_2",
]:
rc, out = ssh(may_fail)
if out:
print(out)
rc, out = ssh(f"docker compose -f {root}/compose.yml up -d act_runner_1")
if out:
print(out)
if rc != 0:
print("Runner switch failed.")
raise SystemExit(3)
print("Phase 4: verify")
for verify_cmd in [
"docker ps -a --format 'table {{.Names}}\t{{.Status}}' | grep -E 'NAMES|gitea-act-runner'",
"docker inspect gitea-act-runner-1 --format 'runner1 restart={{.RestartCount}} oom={{.State.OOMKilled}} status={{.State.Status}} started={{.State.StartedAt}}'",
"docker logs --tail=30 gitea-act-runner-1 | tail -n 30",
]:
rc, out = ssh(verify_cmd)
print(out)
rc, out = ssh("docker inspect gitea-act-runner-2 --format 'runner2 status={{.State.Status}}'")
print(out if rc == 0 else "runner2-removed")
print("One-runner rollout complete for host")
print(f"Backup files: {root}/backups/compose.yml.{ts} and {root}/backups/.env.{ts}")