From 81500b508713844739e2596068e86c23c9d173f7 Mon Sep 17 00:00:00 2001 From: KellyMichels Date: Sun, 16 Aug 2026 20:24:17 -0500 Subject: [PATCH] fix(zdeploy): stop mirroring the build stamp into the local checkout Mirrors evomedia-net/evo.scripts#62. Every python-kind deploy wrote build-version.json locally, leaving the tree dirty; committing it hit branch protection, so a deploy either tripped the next deploy's clean-tree guard or bypassed the rule. The build number is bumped in the container, written to .build_version on the server, and proven by /api/build-version. The repo file records the stage baseline only. --- zdeploy.ps1 | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/zdeploy.ps1 b/zdeploy.ps1 index ab60b85..0637a94 100644 --- a/zdeploy.ps1 +++ b/zdeploy.ps1 @@ -384,7 +384,18 @@ function Invoke-PythonDeploy { } if (-not $BuildVersion) { throw "Build version bump failed after 5 attempts" } - python $versionTool set $BuildVersion | Out-Null + # The local stamp is deliberately NOT mirrored back. Writing it + # left build-version.json dirty after every deploy, and committing + # that hit branch protection ("Changes must be made through a pull + # request") — so each deploy either tripped the NEXT deploy's + # clean-tree guard or bypassed the rule. Neither is acceptable as + # routine behaviour. + # + # The repo file now records the STAGE baseline only (it changes on + # a stage bump, through a normal PR). The live build number lives + # in the container, is written to .build_version below, and is + # proven by the /api/build-version check — which is the thing that + # actually establishes what is deployed. ssh @SSH_OPTS -i $PEM_KEY $SSH_TARGET "echo '$BuildVersion' | sudo tee $remotePath/.build_version > /dev/null" $changelogTool = Join-Path $root "scripts\build_changelog_tool.py" if (Test-Path -LiteralPath $changelogTool) {