v0.234.0: seed installed_images at startup, so the label appears on an app nobody touched
gates / gates (push) Successful in 13s

The operator looked at demo-felhom the morning after v0.233.0 and found OpenGist
- up 15 hours, running exactly the catalog pin - showing no badge at all.
v0.233.0 wrote the record only from the four bring-up paths, so an app nobody
restarts carried no record indefinitely. On a quiet box that is every app, which
is the box we most want to see. The known limitation WAS the feature not working.

BackfillInstalledImages runs once at startup, beside BackfillDesiredState and
before the boot reconciler. It READS containers: starts nothing, restarts
nothing, writes no compose file. It never overwrites an existing record.

And it REFUSES to seed a partial observation, which is why this is not a
three-line loop: the badge reads a service-count mismatch as BEHIND, so seeding a
degraded app from what is visible would render 'Frissites elerheto' over an app
that is perfectly current. The bring-up paths may write a partial because they
follow a successful up -d where a gap is real news; a backfill meets any state.
Same data, two writers, two admission rules - deliberately.

Also fixes a calendar bomb of mine: the render test hardcoded catalog_since and
the string '46 napja', but the render path reads time.Now(), so it was green on
the day it was written and red the next morning. Now derived. Filed as R-457
with six other candidate files named as unchecked, not accused.

+5 tests (1724 -> 1729), 28 packages green. Red-proof of the partial guard run
and reverted; the wiring and its ORDER pinned by an AST walk.
This commit is contained in:
2026-09-03 11:56:43 +02:00
parent 32da46cd64
commit 38d28b5b62
8 changed files with 402 additions and 5 deletions
+104
View File
@@ -436,3 +436,107 @@ func summariseInstalled(m map[string]InstalledImage) string {
}
return strings.Join(parts, ", ")
}
// BackfillInstalledImages records what every deployed app is ALREADY running, for apps that have no
// record yet. Call ONCE at startup, after ScanStacks and after the recoveries.
//
// ── WHY THIS EXISTS AT ALL ───────────────────────────────────────────────────────────────────
//
// v0.233.0 wrote the record only from the four bring-up paths, so an app nobody restarts carried no
// record — and no badge — INDEFINITELY. On a quiet box that is every app, which is the box we most
// want to be able to see. The operator found it on demo-felhom the day after the release: OpenGist,
// up 15 hours, running exactly what the catalog pins, and showing nothing at all.
//
// Reading a container is a pure OBSERVATION: it starts nothing, restarts nothing, upgrades nothing
// and writes no compose file. That is what makes a backfill safe here and is why it is the same
// shape as BackfillDesiredState — with one deliberate difference, below.
//
// ── NEVER OVERWRITES AN EXISTING RECORD ──────────────────────────────────────────────────────
//
// Apps with a record are skipped entirely. The bring-up paths own updates; this only seeds absences.
//
// ── AND IT REFUSES TO SEED A PARTIAL OBSERVATION ─────────────────────────────────────────────
//
// THE TRAP, and it is the whole reason this is not a three-line loop: web.compareInstalledToTemplate
// reads a service-count mismatch as BEHIND. A crash-looping or degraded app can have fewer live
// containers than the template has services, so seeding what we can see would render
// "Frissítés elérhető" over an app that is perfectly current — a confident WRONG answer to the
// customer, which is worse than the silence it replaces.
//
// The bring-up paths do not have this problem: they run immediately after a SUCCESSFUL `compose up
// -d`, where a missing container is real news and is already logged as a WARN. A backfill runs over
// whatever state a box happens to be in at boot, so it must be stricter. An app it cannot observe
// COMPLETELY is left with no record — unknown, which renders nothing, which is the honest answer.
func (m *Manager) BackfillInstalledImages() int {
backfilled, skippedHaveRecord, skippedIncomplete := 0, 0, 0
for _, s := range m.GetStacks() {
if !s.Deployed || s.Protected || s.Deploying {
continue
}
if s.AppConfig != nil && len(s.AppConfig.InstalledImages) > 0 {
skippedHaveRecord++
continue
}
stackDir := filepath.Dir(s.ComposePath)
tpl, err := ParseComposeImages(s.ComposePath)
if err != nil || len(tpl) == 0 {
// Cannot tell what a complete observation would even BE. Leave it unknown.
skippedIncomplete++
continue
}
observed, err := m.observeInstalledImages(stackDir, m.stackEnv(stackDir))
if err != nil {
m.logger.Printf("[WARN] [stacks] installed-images backfill: %s: %v", s.Name, err)
skippedIncomplete++
continue
}
if !observationCoversTemplate(observed, tpl) {
// Stopped, degraded, crash-looping, or mid-anything. See the comment above: a partial
// seed would render as "behind" on an app that is current.
skippedIncomplete++
continue
}
cfg := LoadAppConfig(stackDir)
if cfg == nil {
skippedIncomplete++
continue
}
cfg.InstalledImages = observed
meta := LoadMetadata(stackDir)
if err := SaveAppConfig(stackDir, cfg, m.encKey, SensitiveEnvVars(&meta)); err != nil {
m.logger.Printf("[ERROR] [stacks] installed-images backfill: %s: %v", s.Name, err)
continue
}
m.mu.Lock()
if st, ok := m.stacks[s.Name]; ok && st.AppConfig != nil {
st.AppConfig.InstalledImages = observed
}
m.mu.Unlock()
backfilled++
m.logger.Printf("[INFO] [stacks] installed-images backfill: %s recorded %d service(s) (%s)",
s.Name, len(observed), summariseInstalled(observed))
}
// A POSITIVE OBSERVABLE EITHER WAY (standing rule 3): "0 backfilled" and "the backfill never ran"
// must not look the same in a log.
m.logger.Printf("[INFO] [stacks] installed-images backfill: %d app(s) recorded, %d already had a record, %d left unrecorded (could not be observed completely — unknown, which renders nothing)",
backfilled, skippedHaveRecord, skippedIncomplete)
return backfilled
}
// observationCoversTemplate reports whether EVERY compose service the template declares was observed.
// Extra observed services are fine (a stray container is not a missing one); a missing one is not.
func observationCoversTemplate(observed map[string]InstalledImage, tpl map[string]string) bool {
if len(observed) == 0 {
return false
}
for svc := range tpl {
if _, ok := observed[svc]; !ok {
return false
}
}
return true
}