Skip to content

fix(ci): create init Secret and NetworkPolicies once - #2834

Merged
DerekRoberts merged 1 commit into
mainfrom
fix/init-create-once
Sep 3, 2026
Merged

DerekRoberts merged 1 commit into
mainfrom
fix/init-create-once

Conversation

@DerekRoberts

@DerekRoberts DerekRoberts commented Sep 3, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Init (common/openshift.init.yml) used overwrite: true, so every PR/TEST/PROD deploy oc applyd Secret quickstart-openshift-${ZONE}-database. postgres:17 only sets POSTGRES_PASSWORD on empty PGDATA, so Flyway could log in with a restamped Secret while Postgres still had the first-boot password (28P01).
  • Init is now overwrite: false (oc create). Existing Secret and NetworkPolicies are left alone. New NetworkPolicy names in the template still get created; existing NP specs are not updated.
  • Database/backend/frontend deploys are unchanged (overwrite defaults to true). Password passing ($DB_PASSWORD) is unchanged.

Test plan

  • New PR namespace: Secret and NetworkPolicies are created; migrations authenticate.
  • Re-deploy of that PR: init reports AlreadyExists for Secret/NPs; migrations still authenticate.
  • After TEST volume wipe (empty PGDATA): first merge creates/keeps Secret; backend rollout completes (no progress deadline from Flyway 28P01).
  • Adding a new NetworkPolicy object to init: it is created; existing NPs are not rewritten.

Thanks for the PR!

Deployments, as required, will be available below:

Please create PRs in draft mode. Mark as ready to enable:

After merge, new images are deployed in:

Postgres only honors POSTGRES_PASSWORD on empty PGDATA. oc apply of the
database Secret on every merge desynced Flyway (28P01). NetworkPolicy
specs are stable; new names still oc create.
Copilot AI balanced review requested due to automatic review settings September 3, 2026 08:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Creation errors are suppressed, and existing NetworkPolicy updates can no longer deploy.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Changes init resources to create-only deployment, preventing database password desynchronization.

Changes:

  • Uses overwrite: false for the init template.
  • Documents Secret and NetworkPolicy behavior.
File summaries
File Description
.github/workflows/reusable-deploy.yml Makes init resources create-only.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 2
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/reusable-deploy.yml
Comment thread .github/workflows/reusable-deploy.yml
@DerekRoberts DerekRoberts self-assigned this Sep 3, 2026
@DerekRoberts
DerekRoberts merged commit 21b5367 into main Sep 3, 2026
22 checks passed
@DerekRoberts
DerekRoberts deleted the fix/init-create-once branch September 3, 2026 08:10
@github-project-automation github-project-automation Bot moved this from New to Done in DevOps (NR) Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

2 participants