deploy: refuse to build a dirty tree !114

merged merged by cmc on 2026-08-30 02:07 UTC · krz/gitbay:deploy-clean-tree into main

Discussion

cmc

make deploy and make deploy-runner compile the working tree, not HEAD, so whatever is on disk ships. migrations/ is embedded, which makes that worse than shipping stray code: a migration file that exists only on disk still runs against the production database on restart.

That is not hypothetical. 0027_body_format reached gitbay.org inside the unrelated go-org include-fix deploy (!111), an hour before !113 merged it. No data was harmed — every row in all five tables is still md — but production spent that hour on a binary built from an unreviewed tree, and nothing said so.

preflight now refuses a dirty tree. The check is git status --porcelain, so untracked files count: go:embed does not consult the index, and an untracked migration is exactly what got through. ALLOW_DIRTY=1 ships an uncommitted build on purpose.

Verified: clean tree passes, untracked-file-only fails, staged-but-uncommitted fails, ALLOW_DIRTY=1 bypasses.

Ref #28.