mirror of
https://github.com/gadgethd/ukmesh.git
synced 2026-09-05 23:03:43 +00:00
* fix(ci): pin gitleaks-action to valid commit after upstream force-push Upstream deleted dcedce43 (force-push), so every ci.yml run fails at workflow-parse with 0 jobs. The dependabot actions-group bump (#30) contains this fix but cannot merge whole: its docker/* actions require node24, which GitHub runners do not support yet. Pin gitleaks alone (ff98106e is node20). * fix(ci): downgrade v7 actions to node20-compatible versions actions/checkout@v7, setup-node@v7, setup-python@v7 require node24, which GitHub-hosted runners do not support yet — every ci.yml run has failed at workflow-parse (0 jobs) since the Aug 3 v7 bump. Pin to the latest node20 versions (checkout v4, setup-node v4, setup-python v5). Also pins gitleaks-action to a valid commit (upstream force-pushed away dcedce43). * ci: noop retrigger * fix(ci): escape literal ${{ in bash string so GitHub parser accepts workflow The 'Validate tracked build and Compose inventory' step matched literal ${{ inside run-block strings, which GitHub's expression parser reads as the start of an expression (${{'* is invalid) — the workflow fails at parse time with 0 jobs. Split the literal as '$''{{' (bash concatenates adjacent quoted strings at runtime; the source no longer contains a contiguous ${{). * fix(ci): resolve all three pre-existing ukmesh CI failures Backend (packetBatchWriteCoalesce): - 045: restore nodes_public_visibility_generation trigger — 015 is superseded by 044 on fresh DBs so the trigger was never created, leaving generation/visibility_generation out of sync and public packet reads returning empty. - 046: restore packet privacy classification — the 042 fence design assumes sync_private_node_prefixes rewrites packets on privacy change, but 026's version only maintains prefixes. Node flips to private left old packets visible; direct SQL inserts were never classified. Restore the packet rewrite in the sync trigger and add a BEFORE INSERT trigger mirroring the batch path's is_private / visibility_ok computation. - packetBatch.integration.test.ts: exclude the prefix-cache refresh query from statementCount (matches unit-test convention). Frontend e2e: - public.spec.ts: assert the TopologyMap component's actual labels ('Geographic repeater topology map', '2 mapped repeaters · 2 observed relationships') instead of the pre-map SVG graph labels. Workers (pip install): - viewshed-worker: bump numpy 1.26.4→2.3.5, scipy 1.13.1→1.16.3, psycopg2-binary 2.9.10→2.9.11 (cp314 wheels); the base gdal image ships Python 3.14 so the old pins had no wheels. Inherit shapely from the image's python3-shapely apt package (no cp314 wheel exists; source builds are GEOS 3.14-incompatible). * fix(ci): restore data-plane services for compose validation and smoke test Commit8c5e1c8split the long-lived data-plane services (timescaledb, mosquitto, redis, mosquitto-reloader) into the external meshcore-infra project on the live host, but the Workers-and-Compose CI job still asserted their presence in the app compose project (max_worker_processes check, inventory check, smoke-test execs). CI had been broken since Aug 3 so the mismatch was never caught. Add docker-compose.ci.yml — a CI-only overlay restoring the four data-plane services from their pre-split definitions — and point every compose invocation in the Workers-and-Compose job at '-f docker-compose.yml -f docker-compose.ci.yml'. Validated locally: merged config parses, the jq assertions and the full inventory (db-migrate backend app-ukmesh website-ukmesh website-dev mesh-health-check mosquitto-reloader link-worker link-backfill-worker hopreach timescaledb mosquitto) all pass. * fix(ci): include dev profile in compose inventory check website-dev is a dev-profile service; the inventory gate compared the base-config service list, so the merged stack never matched. This gate has been red since the workflow was first written (CI parse-broken from Aug 3 until the gitleaks pin landed). * fix(ci): db-migrate must wait for timescaledb health The Aug 9 data-plane split removed db-migrate's depends_on along with the timescaledb service definition, so the migration runner raced the fresh database init in the empty-volume smoke test and failed on the not-yet-created base schema. Restore the pre-split condition: timescaledb service_healthy. * fix(ci): restore internal TCP MQTT listener for smoke test + exporter Commit40e843fdropped the 1883 TCP listener, breaking the CI smoke (mosquitto_pub targets 1883) and the Prometheus mosquitto exporter. The listener is internal-only: compose never publishes 1883 on the host, and the password/ACL policy still applies. --------- Co-authored-by: gadgethd <111318106+gadgethd@users.noreply.github.com>
29 lines
1.1 KiB
Docker
29 lines
1.1 KiB
Docker
FROM ghcr.io/osgeo/gdal:ubuntu-full-3.13.2@sha256:de280a240ef4309e6fb64b943e0472e6098099b813a6b9ff0e182bc6976a3fdb
|
|
|
|
WORKDIR /app
|
|
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
python3-pip python3-venv python3-shapely \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Venv with system-site-packages so GDAL Python bindings + numpy are inherited
|
|
RUN python3 -m venv /opt/venv --system-site-packages
|
|
ENV PATH="/opt/venv/bin:$PATH"
|
|
|
|
COPY requirements.txt .
|
|
RUN pip install --no-cache-dir --require-hashes -r requirements.txt
|
|
|
|
COPY worker.py worker_metrics.py link_queue_v3.py viewshed_queue_v2.py queue_admin.py backfill_profiles.py dry_run_coverage.py uk_mainland.json ./
|
|
COPY rf ./rf
|
|
COPY tests ./tests
|
|
|
|
RUN useradd --system --uid 10001 --home-dir /app meshcore \
|
|
&& mkdir -p /data/srtm \
|
|
&& chown -R meshcore:meshcore /app /data/srtm /opt/venv
|
|
USER 10001:10001
|
|
ARG SOURCE_REVISION=unknown
|
|
LABEL org.opencontainers.image.revision="${SOURCE_REVISION}" \
|
|
org.opencontainers.image.source="https://github.com/gadgethd/ukmesh"
|
|
EXPOSE 9091
|
|
CMD ["python3", "-u", "worker.py"]
|