Guard deploys against a broken migration
Program.cs: wrap the boot-time MigrateAsync in try/catch (was an unhandled exception into a restart:unless-stopped crash-loop), log critical and exit(1) on failure, and add a --migrate-only flag that applies migrations then exits 0 without starting the web host. deploy.sh: run migrations as a preflight via the new --migrate-only image against the live novelly-data volume, before the running (old-image) stack is touched. A failing migration now aborts the deploy with the old containers still serving traffic, instead of swapping to a crash-looping new container first and finding out from the health-check timeout.
This commit is contained in:
@@ -34,6 +34,20 @@ services:
|
||||
ports:
|
||||
- "${WEB_PORT:-6173}:80"
|
||||
|
||||
# Preflight migration check, run by deploy.sh via `--profile tools run --rm migrate`
|
||||
# against the newly pulled image before the running stack is touched. Excluded from
|
||||
# `up -d` by the tools profile.
|
||||
migrate:
|
||||
image: ${API_IMAGE}:latest
|
||||
command: ["dotnet", "Novelly.Api.dll", "--migrate-only"]
|
||||
environment:
|
||||
ConnectionStrings__Novel: "Data Source=/data/novel.db"
|
||||
volumes:
|
||||
- novelly-data:/data
|
||||
networks:
|
||||
- novelly
|
||||
profiles: ["tools"]
|
||||
|
||||
networks:
|
||||
novelly:
|
||||
name: novelly-net
|
||||
|
||||
Reference in New Issue
Block a user