Repository navigation
ci(deploy): skip docker-publish wait for non-image commits - #462
Conversation
When a commit only touches docs, tests, or CI config, docker-publish.yml does not trigger (it path-filters on packages/**, Dockerfile*, etc). The deploy was hard-aborting after 60s waiting for a run that will never appear, causing every docs/test/chore commit to fail deployment. Fix: when no docker-publish run is found and the commit did not touch any Docker-relevant paths, skip the image wait and proceed with the existing latest images. The ::notice annotation makes the skip visible in the run log. Also improves the error message when a docker-publish run IS expected but missing — now lists which changed files triggered the expectation. Fixes deploy failures on: docs/testing-release-metadata-sync (#457), chore/shared-test-lane (#460), and similar non-image commits.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 6 minutes and 42 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe deployment workflow's "Wait for Docker images" step now includes a pre-check that queries which files changed in the current commit. When Docker image verification is pending, it filters the changed files for Docker-relevant paths (e.g., Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Possibly related PRs
Suggested labels
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/deploy.yml:
- Around line 80-82: The docker_relevant regex used to set the docker_relevant
variable against changed_files does not match the exact trigger paths in
.github/workflows/docker-publish.yml and is duplicated; update the grep pattern
used when computing docker_relevant to exactly mirror the path triggers from
docker-publish.yml (so it matches the same files like the exact package, prisma,
Dockerfile, nginx, package.json/package-lock.json patterns) and replace both
occurrences where docker_relevant is set (the docker_relevant=$(echo
"$changed_files" | grep -E ...) occurrences) so the matcher is identical and not
duplicated with a differing pattern.
- Around line 76-78: The workflow currently silences errors from the gh api call
that populates changed_files, causing an empty result to be treated as “no
changes” and potentially skipping rebuilds; change the logic around the gh api
invocation that assigns changed_files (the command using commit_sha and gh api)
to detect failure instead of swallowing stderr — if the gh api request fails or
returns an empty/invalid value due to an error, fail the job (exit non-zero) or
set a distinct failure flag so the subsequent skip path is not taken; ensure the
gh api call’s exit status is inspected and any error is logged via echo or
github action logging before exiting.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: c3e019f9-0890-42a7-950b-bdb7cd6f954e
📒 Files selected for processing (1)
.github/workflows/deploy.yml
📜 Review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
- GitHub Check: SonarCloud Scan
- GitHub Check: Quality Gates
🧰 Additional context used
📓 Path-based instructions (7)
**/{.github/workflows,}/*.{yml,yaml}
📄 CodeRabbit inference engine (.cursor/rules/ci-cd.mdc)
**/{.github/workflows,}/*.{yml,yaml}: CI pipeline must include setup step (node install, environment)
CI pipeline must include lint step (TypeScript typecheck + linter)
CI pipeline must include build step (production build)
CI pipeline must include test step (unit + integration) with coverage report
CI pipeline must include quality step (static analysis, vulnerability scan)
Files:
.github/workflows/deploy.yml
**/{.github/workflows,dependabot.yml}/*.{yml,yaml}
📄 CodeRabbit inference engine (.cursor/rules/ci-cd.mdc)
Configure dependency update bot with PR templates and tests (recommended)
Files:
.github/workflows/deploy.yml
**/.github/workflows/*.{yml,yaml}
📄 CodeRabbit inference engine (.cursor/rules/ci-cd.mdc)
**/.github/workflows/*.{yml,yaml}: Configure SAST / secrets scan on PRs (recommended)
Publish artifacts only from protected pipeline steps
Files:
.github/workflows/deploy.yml
{jest.config.*,*.coverage.*,.nycrc*,nyc.config.*,coveragerc,.github/workflows/*.yml,.github/workflows/*.yaml}
📄 CodeRabbit inference engine (.cursor/rules/testing-quality.mdc)
Minimum recommended coverage threshold: 85% (raise per project risk)
Files:
.github/workflows/deploy.yml
{.github/workflows/*.{yml,yaml},*.github/workflows/*.{yml,yaml},.gitlab-ci.yml,.circleci/config.yml,bitbucket-pipelines.yml}
📄 CodeRabbit inference engine (.cursor/rules/testing-quality.mdc)
CI must run in order: lint → build → test → quality checks
Files:
.github/workflows/deploy.yml
{.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}
📄 CodeRabbit inference engine (.cursor/rules/workflow.mdc)
{.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}: CI/CD pipeline must include in order: Setup (Node install, env config) → Lint (TypeScript typecheck, linter) → Build (production build, artifacts) → Test (unit, integration, coverage) → Quality (static analysis, vulnerability scan)
Publish artifacts only from protected pipeline steps in CI/CD
Files:
.github/workflows/deploy.yml
{**/scripts/**,scripts/**,.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}
📄 CodeRabbit inference engine (.cursor/rules/workflow.mdc)
{**/scripts/**,scripts/**,.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}: Use cross-platform environment handling in scripts, cross-platform deletion utilities instead of OS-specific commands, pass non-interactive flags (--yes, --ci) by default in automation, and avoid OS-specific commands
Ensure logs are stream-friendly (no pagers) in scripts; when a pager might be used, pipe to cat
Files:
.github/workflows/deploy.yml
🔇 Additional comments (1)
.github/workflows/deploy.yml (1)
84-87: Good early-exit behavior for non-image commits.This skip path is a solid fix for the original deploy dead-end and keeps deploys moving when no Docker-triggering files changed.
Addressed: single docker_path_pattern variable used consistently, gh api failure now detected and exits non-zero instead of silently proceeding
|
* ci(deploy): skip docker-publish wait for non-image commits When a commit only touches docs, tests, or CI config, docker-publish.yml does not trigger (it path-filters on packages/**, Dockerfile*, etc). The deploy was hard-aborting after 60s waiting for a run that will never appear, causing every docs/test/chore commit to fail deployment. Fix: when no docker-publish run is found and the commit did not touch any Docker-relevant paths, skip the image wait and proceed with the existing latest images. The ::notice annotation makes the skip visible in the run log. Also improves the error message when a docker-publish run IS expected but missing — now lists which changed files triggered the expectation. Fixes deploy failures on: docs/testing-release-metadata-sync (#457), chore/shared-test-lane (#460), and similar non-image commits. * ci(deploy): address review — consolidate path pattern, detect gh api failure



Problem
Deploy was failing on every commit that didn't touch Docker-relevant files.
docker-publish.ymlonly triggers whenpackages/**,prisma/**,Dockerfile*,nginx/**, orpackage*.jsonare changed. For docs, test, CI, or chore commits none of these paths change, so docker-publish never runs.The "Wait for Docker images" step would poll for 60s, find nothing, and hard-abort:
This broke deployment for:
docs: sync TESTING.md and README with current test matrix(docs: sync TESTING.md and README with current test matrix #457)chore: add shared package test lane and wire into test:all(chore: add shared package test lane and wire into test:all #460)Fix
When no docker-publish run is found after the detection window, query the GitHub API to check which files the commit actually changed. If none of the changed files match the docker-publish trigger paths, the commit genuinely does not need new images — skip the wait and proceed with the existing
latestimages.If Docker-relevant files were changed but no docker-publish run was found, the existing hard-abort is preserved (now with better diagnostic output showing which files triggered the expectation).
What this does NOT change
FORCE_UNVERIFIED_DEPLOYescape hatch is unchangedVerification
python3 -c "import yaml; yaml.safe_load(...)")Summary by CodeRabbit