Skip to content

fix(deploy): recover webhook rollouts from checkout drift - #253

Merged
LucasSantana-Dev merged 2 commits into
mainfrom
fix/deploy-checkout-hygiene-v2
Mar 15, 2026
Merged

LucasSantana-Dev merged 2 commits into
mainfrom
fix/deploy-checkout-hygiene-v2

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Mar 15, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Replace webhook deploy checkout sync from git pull to deterministic archive+reset hygiene
  • Classify deploy webhook CI failures into lock contention, checkout recovery, and runtime precheck buckets
  • Enable webhook command output passthrough so CI grep patterns can classify failures
  • Guard repoRoot spread in policy-lib to prevent /.env false positive

Changes

  • scripts/deploy.sh: archive drift state before origin sync; classify failures (LOCK_CONTENTION / CHECKOUT_RECOVERY_FAILED / MIGRATION_FAILED / RUNTIME_PRECHECK_FAILED); fix brittle stash verification with git stash list | grep -qF
  • .github/workflows/deploy.yml: annotate webhook failures by response body pattern
  • deploy/hooks.json: enable include-command-output-in-response so CI grep patterns see real output
  • .opencode/plugins/lucky-policy-lib.mjs: guard repoRoot with non-empty non-root check; add cwd+home params to commandTouchesSensitivePath
  • .cursor/skills/lucky-deploy-recovery/SKILL.md: new deterministic incident triage and rerun policy
  • .cursor/skills/lucky-ci-gate-recovery/SKILL.md: add deploy-checkout-drift bucket and rerun policy

Verification

  • bash -n scripts/deploy.sh
  • npm run lint
  • npm run type:check

Replaces #250 (which had unresolvable merge conflicts after #248 squash-merge).

Summary by CodeRabbit

  • New Features

    • Added structured error classification for deployments with improved recovery guidance for lock contention, checkout synchronization, and runtime prechecks.
  • Improvements

    • Enhanced webhook resilience with increased retry attempts and optimized timeout behavior.
    • Refined deployment state tracking and synchronization mechanisms for improved reliability.

…ixes

- scripts/deploy.sh: archive drift state before origin sync, classify failures into
  LOCK_CONTENTION / CHECKOUT_RECOVERY_FAILED / MIGRATION_FAILED / RUNTIME_PRECHECK_FAILED;
  replace brittle stash Saved* check with git stash list | grep -qF
- .github/workflows/deploy.yml: classify webhook failure annotations by response body pattern
- deploy/hooks.json: enable include-command-output-in-response so CI grep patterns see real output
- .opencode/plugins/lucky-policy-lib.mjs: guard repoRoot spread with non-empty non-root check
  to prevent /.env false positive; add cwd+home params to commandTouchesSensitivePath
- .cursor/skills/lucky-deploy-recovery/SKILL.md: new deterministic incident triage and rerun policy
- .cursor/skills/lucky-ci-gate-recovery/SKILL.md: add deploy-checkout-drift bucket and rerun policy
@netlify

netlify Bot commented Mar 15, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for regal-bunny-0c8efe ready!

Name Link
🔨 Latest commit bf0a73c
🔍 Latest deploy log https://app.netlify.com/projects/regal-bunny-0c8efe/deploys/69b6430e6da4760008cc9d38
😎 Deploy Preview https://deploy-preview-253--regal-bunny-0c8efe.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@vercel

vercel Bot commented Mar 15, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment Mar 15, 2026 5:26am

Request Review

@coderabbitai

coderabbitai Bot commented Mar 15, 2026 •

Copy link
Copy Markdown

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

This PR restructures deployment recovery and CI gate handling by introducing standardized failure classifications (LOCK_CONTENTION, CHECKOUT_RECOVERY_FAILED, RUNTIME_PRECHECK_FAILED), adding checkout archive-and-sync functions, adjusting webhook retry parameters and logic, and refactoring recovery guidance documentation with concrete command examples.

Changes

Cohort / File(s) Summary
Deploy Recovery Skills
.cursor/skills/lucky-ci-gate-recovery/SKILL.md, .cursor/skills/lucky-deploy-recovery/SKILL.md
Added failure bucket classifications and rerun policies; restructured guidance from narrative descriptions to action-oriented steps with embedded shell commands and explicit failure triage sequences.
Workflow and Webhook
.github/workflows/deploy.yml
Removed concurrency block; increased webhook retries from 2 to 8 with shortened timeout (20s) and adjusted backoff (4s); expanded retry conditions to include 5xx and network errors; added failure body normalization and error classification mapping.
Deploy Script Refactoring
scripts/deploy.sh
Added archive_local_checkout_state and sync_checkout_to_origin_main functions; replaced compose-based preparation with checkout synchronization workflow; updated healthcheck logic to use hardcoded nginx endpoints; removed legacy env-file and preflight helper functions; unified error classification tagging.
Plugin and Configuration
.opencode/plugins/lucky-policy-lib.mjs, deploy/hooks.json
Conditional sensitive-path candidate assignment in commandTouchesSensitivePath; single-line JSON payload formatting simplification.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

Suggested labels

ci, infra, size/l

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately and specifically describes the main change: fixing deploy webhook rollouts by recovering from checkout drift through a deterministic archive+reset hygiene flow.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/deploy-checkout-hygiene-v2
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@sonarqubecloud

Copy link
Copy Markdown

@sonarqubecloud

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit ef512a1 into main Mar 15, 2026
14 of 15 checks passed
LucasSantana-Dev pushed a commit that referenced this pull request Mar 15, 2026
PR #253 inadvertently changed deploy.sh from mode 100755 to 100644.
The almir/webhook binary requires execute-command targets to be
executable; without it, the hook returns HTTP 500 with an empty body.

Restores the +x bit so the deploy webhook can invoke the script.
LucasSantana-Dev added a commit that referenced this pull request Mar 15, 2026
PR #253 inadvertently changed scripts/deploy.sh from mode 100755 to 100644.\nThe almir/webhook binary requires execute permission, causing HTTP 500 with empty body on every deploy trigger.\n\nRestores the executable bit so the webhook can invoke the script directly.
LucasSantana-Dev added a commit that referenced this pull request Mar 15, 2026
Bumps version to 2.6.17 and promotes CHANGELOG entries for PRs #253-#256:\n- fix(deploy): restore executable bit on deploy.sh\n- feat(bot): harden queue snapshot restore with staleness guard\n- feat(bot): enforce provider health cooldown ordering in search fallback\n- fix(deploy): recover webhook rollouts from checkout drift
@LucasSantana-Dev
LucasSantana-Dev deleted the fix/deploy-checkout-hygiene-v2 branch March 15, 2026 14:07
LucasSantana-Dev added a commit that referenced this pull request May 13, 2026
- Archive local drift state before origin sync via git stash with labeled stash
- Enforce archive-reset checkout hygiene to prevent stale checkout artifacts
- Classify deployment failures into LOCK_CONTENTION, CHECKOUT_RECOVERY_FAILED,
  MIGRATION_FAILED, RUNTIME_PRECHECK_FAILED categories in deploy.yml
- Add hooks.json output capture so CI grep patterns see real webhook response
- Guard repoRoot in lucky-policy-lib.mjs to prevent /.env false positive
- Add lucky-deploy-recovery skill for deterministic incident triage
LucasSantana-Dev added a commit that referenced this pull request May 13, 2026
PR #253 inadvertently changed scripts/deploy.sh from mode 100755 to 100644.\nThe almir/webhook binary requires execute permission, causing HTTP 500 with empty body on every deploy trigger.\n\nRestores the executable bit so the webhook can invoke the script directly.
LucasSantana-Dev added a commit that referenced this pull request May 13, 2026
Bumps version to 2.6.17 and promotes CHANGELOG entries for PRs #253-#256:\n- fix(deploy): restore executable bit on deploy.sh\n- feat(bot): harden queue snapshot restore with staleness guard\n- feat(bot): enforce provider health cooldown ordering in search fallback\n- fix(deploy): recover webhook rollouts from checkout drift

This branch was successfully deployed

1 active deployment
Preview — bf0a73c7 Deployed Mar 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant