fix(serverless): describe env and secret changes as workload rolls - #124
Conversation
|
Important Review skippedAuto reviews are disabled on this repository. To trigger a review, include ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Help still said an environment update never reaches a pod and that attaching a secret does not roll workers. On the 0.6.0 API both roll a live deployment.
03824e6 to
2794281
Compare
| Prefer --value-file so the value is not visible in process lists; use | ||
| --value-file - to read from stdin. | ||
|
|
||
| A change records a new version with the same image and rolls the workload when |
There was a problem hiding this comment.
suggestion (non-blocking): The same rollout paragraph appears in apps env set, apps env unset and deploy. Put it in one shared const, or make deploy refer to apps env set --help.
|
|
||
| This does not attach the secret to an application. Use 'secrets attach' for that. | ||
| Creating a secret does not attach it to an application. Use 'secrets attach' for that. | ||
| Updating an existing secret re-encrypts the value and rolls every live application |
There was a problem hiding this comment.
suggestion (non-blocking): Use one term for each concept across env and secrets: "rolls the workload" or "rolls the live deployment", and "app" or "application". Also define "live", because the env help lists statuses and the secrets help does not.
|
|
||
| A delete records a new version with the same image and rolls the workload when | ||
| the app is active, initializing, or failed. A stopped or stopping app applies | ||
| it on resume. A delete during an in-flight rollout returns 409 and does not |
There was a problem hiding this comment.
nitpick (non-blocking): An unset of a missing key returns 404, also during a rollout, because the not-found check runs before the busy check. Add this to the help if the 409 statement is to stay precise.
A failed app only rolls when the copied image is deployable. A secret change that misses an in-flight rollout waits for the next deploy, and a non-live attach is read on deploy or resume.
Summary
apps env set/unset, and secrets help so they match the 0.6.0 control plane: an environment change records a new version and rolls a live app; attach, detach, and rotating a secret do the same.apps env setnever reaches a pod, and the claim thatsecrets attachis a metadata-only association.Test plan
runware serverless deploy --helpsays later env changes roll the workload, not that they stay off the podrunware serverless apps env set --helpandunset --helpmention the version + roll, resume for stopped apps, and 409 during an in-flight rolloutrunware serverless secrets attach --helpsays attach rolls the live deploymentrunware serverless secrets detach --helpandset --helpdescribe the matching roll on detach and on rotating an existing secret