Skip to content

fix(serverless): describe env and secret changes as workload rolls - #124

Merged
Ryank90 merged 2 commits into
rc/serverlessfrom
fix/serverless-rollout-help
Sep 23, 2026
Merged

Ryank90 merged 2 commits into
rc/serverlessfrom
fix/serverless-rollout-help

Conversation

@Ryank90

@Ryank90 Ryank90 commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Correct deploy, apps env set/unset, and secrets help so they match the 0.6.0 control plane: an environment change records a new version and rolls a live app; attach, detach, and rotating a secret do the same.
  • Drop the old claim that apps env set never reaches a pod, and the claim that secrets attach is a metadata-only association.
  • Regenerate the command reference docs from the updated help text.

Test plan

  • runware serverless deploy --help says later env changes roll the workload, not that they stay off the pod
  • runware serverless apps env set --help and unset --help mention the version + roll, resume for stopped apps, and 409 during an in-flight rollout
  • runware serverless secrets attach --help says attach rolls the live deployment
  • runware serverless secrets detach --help and set --help describe the matching roll on detach and on rotating an existing secret

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. To trigger a review, include coderabbit-review in the PR description. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: a79cff7e-621a-48bf-b3f3-6643029ca679

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Help still said an environment update never reaches a pod and that attaching
a secret does not roll workers. On the 0.6.0 API both roll a live deployment.
@Ryank90
Ryank90 force-pushed the fix/serverless-rollout-help branch from 03824e6 to 2794281 Compare September 22, 2026 15:58
Prefer --value-file so the value is not visible in process lists; use
--value-file - to read from stdin.

A change records a new version with the same image and rolls the workload when

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

suggestion (non-blocking): The same rollout paragraph appears in apps env set, apps env unset and deploy. Put it in one shared const, or make deploy refer to apps env set --help.


This does not attach the secret to an application. Use 'secrets attach' for that.
Creating a secret does not attach it to an application. Use 'secrets attach' for that.
Updating an existing secret re-encrypts the value and rolls every live application

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

suggestion (non-blocking): Use one term for each concept across env and secrets: "rolls the workload" or "rolls the live deployment", and "app" or "application". Also define "live", because the env help lists statuses and the secrets help does not.

Comment thread internal/cmd/serverless/env.go Outdated
Comment thread internal/cmd/serverless/secrets.go Outdated
Comment thread internal/cmd/serverless/secrets.go Outdated
Comment thread internal/cmd/serverless/env.go Outdated

A delete records a new version with the same image and rolls the workload when
the app is active, initializing, or failed. A stopped or stopping app applies
it on resume. A delete during an in-flight rollout returns 409 and does not

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nitpick (non-blocking): An unset of a missing key returns 404, also during a rollout, because the not-found check runs before the busy check. Add this to the help if the 409 statement is to stay precise.

A failed app only rolls when the copied image is deployable. A secret change that misses an in-flight rollout waits for the next deploy, and a non-live attach is read on deploy or resume.
@Ryank90
Ryank90 merged commit 8d21874 into rc/serverless Sep 23, 2026
4 checks passed
@Ryank90
Ryank90 deleted the fix/serverless-rollout-help branch September 23, 2026 16:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants