From c098807aa4d7e1495327ef2fdb6f1e475b740a10 Mon Sep 17 00:00:00 2001 From: mr-forust Date: Tue, 6 Oct 2026 16:03:53 +0200 Subject: [PATCH] fix(deploy): reject destructive per-file pruning before apply --- .gitea/workflows/deploy-lib.sh | 19 ++++++++++++++----- 1 file changed, 14 insertions(+), 5 deletions(-) diff --git a/.gitea/workflows/deploy-lib.sh b/.gitea/workflows/deploy-lib.sh index d96880e..d3cb30a 100644 --- a/.gitea/workflows/deploy-lib.sh +++ b/.gitea/workflows/deploy-lib.sh @@ -31,6 +31,16 @@ warn() { echo "WARNING: $*" >&2 } +# Prune needs the complete desired set in one invocation. Per-file pruning +# treats resources from the other files as absent and can delete them. +check_prune_mode() { + if [ "$APPLY_PRUNE" = "true" ]; then + echo "ERROR: APPLY_PRUNE=true is unsupported by the per-file deploy loop." >&2 + echo "Disable it; remove obsolete resources explicitly after review." >&2 + return 1 + fi +} + collect_k8s() { git -C "$REPO" ls-files -- "$1" \ | grep -E '\.ya?ml$' \ @@ -720,6 +730,7 @@ check_referenced_secrets() { } stage_validate() { + check_prune_mode || return 1 cd "$REPO" select_manifests local m k cf @@ -753,18 +764,16 @@ stage_validate() { } stage_apply_k8s() { + check_prune_mode || return 1 cd "$REPO" select_manifests >/dev/null - local ns_files=() other_files=() m k prune_opts=() + local ns_files=() other_files=() m k for m in ${K8S_MANIFESTS[@]+"${K8S_MANIFESTS[@]}"}; do case "$m" in */namespace.y?ml) ns_files+=("$m") ;; *) other_files+=("$m") ;; esac done - if [ "$APPLY_PRUNE" = "true" ]; then - prune_opts=(--prune -l app.kubernetes.io/managed-by=homelab-deploy) - fi # Record what is about to change, and publish it for the verify job, before # the first apply. Both are fatal on failure: see snapshot_dir. @@ -789,7 +798,7 @@ stage_apply_k8s() { if [ "${#other_files[@]}" -gt 0 ]; then log "Applying resources (${#other_files[@]} files, our images pinned to digests)" for m in "${other_files[@]}"; do - if ! render_pinned <"$m" | kubectl apply "${prune_opts[@]}" -f -; then + if ! render_pinned <"$m" | kubectl apply -f -; then echo "ERROR: apply failed for ${m#"$REPO"/}" >&2 exit 1 fi