Validate candidate configuration before app release

This commit is contained in:
SimpleTest 2026-07-27 02:37:06 +03:00
parent 6c14531da3
commit ca715e2876
4 changed files with 15 additions and 4 deletions

View File

@ -953,7 +953,10 @@ The default `plan` action is read-only. It verifies the exact local and remote
commits, requires a fast-forward history, checks the production checkout, commits, requires a fast-forward history, checks the production checkout,
Compose scope and healthy containers, checks public readiness, opens a Compose scope and healthy containers, checks public readiness, opens a
read-only PostgreSQL connection, and runs the server-release environment read-only PostgreSQL connection, and runs the server-release environment
capability preflight. Before the first Google Play release, this preflight capability preflight. The candidate validator is streamed over SSH and checks
the existing server environment and Compose render before any bundle is
uploaded, so a validator change does not depend on the previously deployed
source tree. Before the first Google Play release, this preflight
allows only the absent Play App Signing certificate; the stricter allows only the absent Play App Signing certificate; the stricter
`check-environment-readiness.sh .env --require-release` remains the gate for `check-environment-readiness.sh .env --require-release` remains the gate for
publishing Android through Google Play. The plan neither uploads a bundle nor publishing Android through Google Play. The plan neither uploads a bundle nor

View File

@ -79,8 +79,6 @@ current_commit=$(git -C "$root" rev-parse --verify HEAD)
exit 2 exit 2
} }
"$root/scripts/validate-production-env.sh" \
"$env_file" "$expected_domain" --allow-pre-play >/dev/null
"$root/scripts/compose.sh" "$env_file" config --quiet "$root/scripts/compose.sh" "$env_file" config --quiet
case "$app_topology" in case "$app_topology" in

View File

@ -66,6 +66,12 @@ migration_policy=$(
plan_failed=0 plan_failed=0
if ! ssh -o BatchMode=yes "$ssh_target" \
"WNH_PROJECT_ROOT='$remote_root' bash -s -- '$remote_root/.env' '$expected_domain' --allow-pre-play" \
<"$ROOT/scripts/validate-production-env.sh"; then
plan_failed=1
fi
if ! ssh -o BatchMode=yes "$ssh_target" \ if ! ssh -o BatchMode=yes "$ssh_target" \
"bash -s -- plan '$remote_root' '$expected_domain'" \ "bash -s -- plan '$remote_root' '$expected_domain'" \
<"$ROOT/scripts/production-release-remote.sh"; then <"$ROOT/scripts/production-release-remote.sh"; then

View File

@ -1,7 +1,11 @@
#!/bin/bash #!/bin/bash
set -euo pipefail set -euo pipefail
if [[ -n "${WNH_PROJECT_ROOT:-}" ]]; then
ROOT=$(realpath --canonicalize-existing "$WNH_PROJECT_ROOT")
else
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd) ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
fi
env_file=${1:-} env_file=${1:-}
expected_domain=${2:-} expected_domain=${2:-}
android_release_mode=${3:-} android_release_mode=${3:-}