diff --git a/docs/operations.md b/docs/operations.md index e2f2ecc..c7e575e 100644 --- a/docs/operations.md +++ b/docs/operations.md @@ -953,7 +953,10 @@ The default `plan` action is read-only. It verifies the exact local and remote commits, requires a fast-forward history, checks the production checkout, Compose scope and healthy containers, checks public readiness, opens a read-only PostgreSQL connection, and runs the server-release environment -capability preflight. Before the first Google Play release, this preflight +capability preflight. The candidate validator is streamed over SSH and checks +the existing server environment and Compose render before any bundle is +uploaded, so a validator change does not depend on the previously deployed +source tree. Before the first Google Play release, this preflight allows only the absent Play App Signing certificate; the stricter `check-environment-readiness.sh .env --require-release` remains the gate for publishing Android through Google Play. The plan neither uploads a bundle nor diff --git a/scripts/production-release-remote.sh b/scripts/production-release-remote.sh index a245eff..4508aea 100755 --- a/scripts/production-release-remote.sh +++ b/scripts/production-release-remote.sh @@ -79,8 +79,6 @@ current_commit=$(git -C "$root" rev-parse --verify HEAD) exit 2 } -"$root/scripts/validate-production-env.sh" \ - "$env_file" "$expected_domain" --allow-pre-play >/dev/null "$root/scripts/compose.sh" "$env_file" config --quiet case "$app_topology" in diff --git a/scripts/production-release.sh b/scripts/production-release.sh index 1e09fc3..7c6a634 100755 --- a/scripts/production-release.sh +++ b/scripts/production-release.sh @@ -66,6 +66,12 @@ migration_policy=$( plan_failed=0 +if ! ssh -o BatchMode=yes "$ssh_target" \ + "WNH_PROJECT_ROOT='$remote_root' bash -s -- '$remote_root/.env' '$expected_domain' --allow-pre-play" \ + <"$ROOT/scripts/validate-production-env.sh"; then + plan_failed=1 +fi + if ! ssh -o BatchMode=yes "$ssh_target" \ "bash -s -- plan '$remote_root' '$expected_domain'" \ <"$ROOT/scripts/production-release-remote.sh"; then diff --git a/scripts/validate-production-env.sh b/scripts/validate-production-env.sh index dd3b5b8..3b785aa 100755 --- a/scripts/validate-production-env.sh +++ b/scripts/validate-production-env.sh @@ -1,7 +1,11 @@ #!/bin/bash set -euo pipefail -ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd) +if [[ -n "${WNH_PROJECT_ROOT:-}" ]]; then + ROOT=$(realpath --canonicalize-existing "$WNH_PROJECT_ROOT") +else + ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd) +fi env_file=${1:-} expected_domain=${2:-} android_release_mode=${3:-}