Skip to content

build(bench): add hosted Fly qualification path - #1003

Merged
DecisionNerd merged 3 commits into
mainfrom
fix/958-hosted-image-build
Aug 30, 2026
Merged

DecisionNerd merged 3 commits into
mainfrom
fix/958-hosted-image-build

Conversation

@DecisionNerd

@DecisionNerd DecisionNerd commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • add protected manual workflows for hosted build(bench): provide the disposable Fly ladder adapter #958 qualification and receipt-bound orphan recovery
  • build and push the commit-pinned Fly image with hosted Docker on Blacksmith Linux instead of the failing provider builder
  • bind cleanup authority to an exact commit plus a fresh 128-bit app-name nonce
  • split execution and recovery into independent jobs with separate timeout budgets
  • scope FLY_API_TOKEN only to Fly operations and isolate temporary Docker credentials
  • preserve immutable registry digest, private Machine, bounded evidence, and typed teardown contracts

Why

The merged provider-builder path repeatedly failed before image resolution with provider_build_unknown; the engine, volume, Machine, and smoke never ran. Fly documents --local-only --build-only --push as the supported path for building with a caller-owned Docker daemon and pushing to the same Fly registry. Running that command on the hosted Linux runner removes the opaque provider builder without changing the qualified runtime.

Independent review also identified cleanup hazards in the first revision. The hardened design refuses deletion without the schema-v3 app/commit/nonce receipt, runs manual recovery code from trusted current main, shares concurrency with the source workflow, and preserves teardown_failed diagnostics.

Verification

  • benchmark controller: 90 passed
  • focused controller/recovery suite: 36 passed
  • Ruff: passed
  • CI storage policy: passed (29 bounded artifact producers, 23 consumers)
  • git diff --check: passed
  • two independent agent reviews: no remaining correctness/security blocker

The live qualification remains manual, environment-protected, exact-current-main only, and requires explicit disposable-resource authorization plus FLY_API_TOKEN. This PR creates no Fly resources and does not close #958; one post-merge live tiny qualification and verified teardown are still required.

Related to #958.

@coderabbitai

coderabbitai Bot commented Aug 30, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 668aaecc-9f9c-4a0a-8e60-178b8a36c067

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption.


Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added documentation Improvements or additions to documentation ci-cd CI/CD configuration changes tooling Developer tooling and automation release:none No release note or version impact labels Aug 30, 2026
@DecisionNerd
DecisionNerd enabled auto-merge (squash) August 30, 2026 19:25
@DecisionNerd
DecisionNerd merged commit baed3e5 into main Aug 30, 2026
21 checks passed
@DecisionNerd
DecisionNerd deleted the fix/958-hosted-image-build branch September 17, 2026 18:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-cd CI/CD configuration changes documentation Improvements or additions to documentation release:none No release note or version impact tooling Developer tooling and automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

build(bench): provide the disposable Fly ladder adapter

1 participant