fix(zdeploy): stop mirroring the build stamp into the local checkout (#51)

Mirrors evomedia-net/evo.scripts#62. Every python-kind deploy wrote
build-version.json locally, leaving the tree dirty; committing it hit
branch protection, so a deploy either tripped the next deploy's
clean-tree guard or bypassed the rule.

The build number is bumped in the container, written to .build_version
on the server, and proven by /api/build-version. The repo file records
the stage baseline only.
This commit is contained in:
Kelly Michels 2026-08-16 21:42:55 -05:00 committed by GitHub
parent 91bbaca0e7
commit d99f8a1312
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -384,7 +384,18 @@ function Invoke-PythonDeploy {
}
if (-not $BuildVersion) { throw "Build version bump failed after 5 attempts" }
python $versionTool set $BuildVersion | Out-Null
# The local stamp is deliberately NOT mirrored back. Writing it
# left build-version.json dirty after every deploy, and committing
# that hit branch protection ("Changes must be made through a pull
# request") — so each deploy either tripped the NEXT deploy's
# clean-tree guard or bypassed the rule. Neither is acceptable as
# routine behaviour.
#
# The repo file now records the STAGE baseline only (it changes on
# a stage bump, through a normal PR). The live build number lives
# in the container, is written to .build_version below, and is
# proven by the /api/build-version check — which is the thing that
# actually establishes what is deployed.
ssh @SSH_OPTS -i $PEM_KEY $SSH_TARGET "echo '$BuildVersion' | sudo tee $remotePath/.build_version > /dev/null"
$changelogTool = Join-Path $root "scripts\build_changelog_tool.py"
if (Test-Path -LiteralPath $changelogTool) {