Skip to content

fix(OMN-15103): install rsync in the omnibase-deploy runner image - #2434

Merged
jonahgabriel merged 1 commit into
devfrom
jonah/omn-15103-runner-image-add-rsync
Jul 25, 2026
Merged

jonahgabriel merged 1 commit into
devfrom
jonah/omn-15103-runner-image-add-rsync

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jul 25, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The omninode-deploy-runner container (shared omninode-runner:latest image, docker/runners/Dockerfile) is missing rsync. scripts/deploy-runtime.sh's BUILD_SOURCE=workspace path (invoked by refresh_stability_lane.sh / refresh_dev_lane.sh on the release-train-lab deploy path, OMN-14900) stages the deploy target via ~10 rsync -a --delete calls in sync_files(). The shared omnibase-ci fleet's build/test jobs never exercise that path, so this gap was never surfaced until the first live end-to-end release-train-lab run.

Boundary seams

  • docker/runners/Dockerfile: single apt-get install list (line ~62-79) -- added rsync alongside the existing OS-level deps (git, jq, tar, unzip, ...). No other file references this list; no contract/schema/topic seam involved.
  • Consumer: omninode-runner:latest image -> omninode-deploy-runner container (docker/docker-compose.runners.yml) -> deploy-runtime.sh's sync_files() (calls plain rsync from $PATH, no version/flag coupling beyond -a --delete).
  • No shape/field seam -- this is a missing OS package, not a data-contract change.

Proof

  • proof_class: code-only for this PR (Dockerfile diff, no runtime behavior to unit-test -- rsync presence is an OS-level fact, not something the Python test suite can assert without a container build).
  • Live evidence the defect is real (not speculative): docker exec omninode-deploy-runner sh -c 'which rsync; echo exit=$?' -> exit=1 (not found), confirmed on .201 (omninode-pc) 2026-07-25T05:2xZ.
  • Live evidence of the failure mode this fixes: release-train-lab run https://github.com/OmniNode-ai/omnibase_infra/actions/runs/30145411975, job Deploy triggering tag to its lane, step Refresh stability lane:
    [deploy] ERROR: 'rsync' is required (file synchronization) but not found in PATH.
    [deploy] === Validate Prerequisites ===
    [refresh-stability-lane] deploy-runtime.sh exited 1 -- proceeding to health-gate anyway
    
    Health-gate then correctly detected revision_match: false and rolled back to the prior (already-healthy, unrelated) revision -- FAILED_ROLLED_BACK. Rollback worked as designed; the code hop itself did not happen.
  • Next-step proof (post-merge, tracked in OMN-15103 acceptance): rebuild omninode-runner:latest, recreate omninode-deploy-runner, cut a fresh lab/stability/** tag, re-fire -- acceptance is a health-gate readback showing revision_match: true for all 4 core services, not a rollback.

OMN-15103 (child of OMN-14900).

Evidence-Ticket: OMN-15103
Evidence-Source: OCC#4792
Evidence-Commit: ab6a05be3585d4d0f8dbfc9e00a3e231e46753c2

deploy-runtime.sh's BUILD_SOURCE=workspace path stages the deploy target
via ~10 `rsync -a --delete` calls in sync_files(). The shared
omnibase-ci fleet's build/test jobs never exercise that path, so rsync
was never added to docker/runners/Dockerfile's apt-get install list.
The gap surfaced live: the first release-train-lab deploy run to reach
"Validate Prerequisites" died with "'rsync' is required ... but not
found in PATH", forcing a correct-but-unwanted rollback to the prior
revision.

Evidence: omninode-deploy-runner container, `which rsync` -> exit 1.
Run https://github.com/OmniNode-ai/omnibase_infra/actions/runs/30145411975.

OMN-15103 (child of OMN-14900).
@coderabbitai

coderabbitai Bot commented Jul 25, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 12 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3f46e2f6-979e-4a39-90ab-c504397a39fd

📥 Commits

Reviewing files that changed from the base of the PR and between db0e0e4 and af215d9.

📒 Files selected for processing (1)
  • docker/runners/Dockerfile
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-15103-runner-image-add-rsync

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Hostile Reviewer — DEGRADED (informational)

Blocking findings (critical): 0
Total findings: 0
Models succeeded: none

Note: All reviewer models failed or were unavailable. Degraded results are informational during the pilot phase (OMN-8468/OMN-8524) and do not block merge. Error: all review endpoints [192.168.86.201:8000 192.168.86.201:8001 ] unreachable — preflight short-circuit (no models available)


Gate semantics (pilot phase)

Verdict Meaning Blocks merge?
passed No critical findings No
blocked CRITICAL findings found Yes
degraded All models unavailable (infra) No (pilot)

Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524)

jonahgabriel added a commit to OmniNode-ai/onex_change_control that referenced this pull request Jul 25, 2026
#4792)

* evidence: OCC companion pass 1 for OmniNode-ai/omnibase_infra#2434

* evidence: OCC companion self-bind for #4792

---------

Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
@jonahgabriel
jonahgabriel merged commit 14b6f8c into dev Jul 25, 2026
153 of 159 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-15103-runner-image-add-rsync branch July 25, 2026 05:58
jonahgabriel added a commit that referenced this pull request Jul 26, 2026
…t catalog, T0/T1 readback, dev gotchas, prod pointer (#2454)

Extends docs/runbooks/release-train-lab.md (existing mechanism doc, not a
new file) with the operator-facing procedure proven live on run
30180376657 (2026-07-26, tag lab/stability/20260725T235956Z-87ec5b3165ce,
overall: PASS) — the terminal success of the six-iteration OMN-14900
hardening chain.

- Copy-paste tag-cut + watch procedure with expected output and a
  tag-content WARNING (never reuse a parked tag name).
- Preflight catalog: what each of the 6 landed fixes (#2450/#2446/#2444/
  #2452/#2434/#2448) catches, with pre-fix failure signatures.
- T0/T1 readback discipline: health 18085/18086, contract-count floor vs.
  regression, discovery_errors baseline, consumer groups, vcs_ref
  ancestry; FAILED_ROLLED_BACK equality-proof discipline.
- Dev-lane gotchas: stale workspace-build config YAML, OMN-14968 false
  FAILED on runtime-worker; pointer (not duplicate) to
  cold-lane-full-bringup.md for cold bring-up.
- Prod: pointer-only section citing CLAUDE.md rules 2a/12 and the
  onex_change_control#4892 prep-only grant-PR pattern; explicit
  raw-docker-mutation prohibition citing the no-raw-prod-bypass gate.
- Verification checklist + rollback section.

Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant