Repository navigation
fix(OMN-15103): install rsync in the omnibase-deploy runner image - #2434
Conversation
deploy-runtime.sh's BUILD_SOURCE=workspace path stages the deploy target via ~10 `rsync -a --delete` calls in sync_files(). The shared omnibase-ci fleet's build/test jobs never exercise that path, so rsync was never added to docker/runners/Dockerfile's apt-get install list. The gap surfaced live: the first release-train-lab deploy run to reach "Validate Prerequisites" died with "'rsync' is required ... but not found in PATH", forcing a correct-but-unwanted rollback to the prior revision. Evidence: omninode-deploy-runner container, `which rsync` -> exit 1. Run https://github.com/OmniNode-ai/omnibase_infra/actions/runs/30145411975. OMN-15103 (child of OMN-14900).
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 12 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
| Verdict | Meaning | Blocks merge? |
|---|---|---|
passed |
No critical findings | No |
blocked |
CRITICAL findings found | Yes |
degraded |
All models unavailable (infra) | No (pilot) |
Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524)
#4792) * evidence: OCC companion pass 1 for OmniNode-ai/omnibase_infra#2434 * evidence: OCC companion self-bind for #4792 --------- Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
…t catalog, T0/T1 readback, dev gotchas, prod pointer (#2454) Extends docs/runbooks/release-train-lab.md (existing mechanism doc, not a new file) with the operator-facing procedure proven live on run 30180376657 (2026-07-26, tag lab/stability/20260725T235956Z-87ec5b3165ce, overall: PASS) — the terminal success of the six-iteration OMN-14900 hardening chain. - Copy-paste tag-cut + watch procedure with expected output and a tag-content WARNING (never reuse a parked tag name). - Preflight catalog: what each of the 6 landed fixes (#2450/#2446/#2444/ #2452/#2434/#2448) catches, with pre-fix failure signatures. - T0/T1 readback discipline: health 18085/18086, contract-count floor vs. regression, discovery_errors baseline, consumer groups, vcs_ref ancestry; FAILED_ROLLED_BACK equality-proof discipline. - Dev-lane gotchas: stale workspace-build config YAML, OMN-14968 false FAILED on runtime-worker; pointer (not duplicate) to cold-lane-full-bringup.md for cold bring-up. - Prod: pointer-only section citing CLAUDE.md rules 2a/12 and the onex_change_control#4892 prep-only grant-PR pattern; explicit raw-docker-mutation prohibition citing the no-raw-prod-bypass gate. - Verification checklist + rollback section. Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
Summary
The
omninode-deploy-runnercontainer (sharedomninode-runner:latestimage,docker/runners/Dockerfile) is missingrsync.scripts/deploy-runtime.sh'sBUILD_SOURCE=workspacepath (invoked byrefresh_stability_lane.sh/refresh_dev_lane.shon the release-train-lab deploy path, OMN-14900) stages the deploy target via ~10rsync -a --deletecalls insync_files(). The sharedomnibase-cifleet's build/test jobs never exercise that path, so this gap was never surfaced until the first live end-to-end release-train-lab run.Boundary seams
docker/runners/Dockerfile: singleapt-get installlist (line ~62-79) -- addedrsyncalongside the existing OS-level deps (git,jq,tar,unzip, ...). No other file references this list; no contract/schema/topic seam involved.omninode-runner:latestimage ->omninode-deploy-runnercontainer (docker/docker-compose.runners.yml) ->deploy-runtime.sh'ssync_files()(calls plainrsyncfrom$PATH, no version/flag coupling beyond-a --delete).Proof
rsyncpresence is an OS-level fact, not something the Python test suite can assert without a container build).docker exec omninode-deploy-runner sh -c 'which rsync; echo exit=$?'->exit=1(not found), confirmed on.201(omninode-pc) 2026-07-25T05:2xZ.Deploy triggering tag to its lane, stepRefresh stability lane:revision_match: falseand rolled back to the prior (already-healthy, unrelated) revision --FAILED_ROLLED_BACK. Rollback worked as designed; the code hop itself did not happen.omninode-runner:latest, recreateomninode-deploy-runner, cut a freshlab/stability/**tag, re-fire -- acceptance is a health-gate readback showingrevision_match: truefor all 4 core services, not a rollback.OMN-15103 (child of OMN-14900).
Evidence-Ticket: OMN-15103
Evidence-Source: OCC#4792
Evidence-Commit: ab6a05be3585d4d0f8dbfc9e00a3e231e46753c2