Ask the container what it is running
Preflight's first check ran `--version` on --binary. A container-only host has no such file, so the check failed, and because it is first, nothing downstream ever ran — including every container check that exists to decide whether that container can be migrated at all. The container path was unreachable on exactly the hosts it is for. A host that happens to have a binary is the worse case, not the better one: a stray /usr/local/bin/stalwart from an older install answers confidently with a version nothing is running, and the whole migration plan is derived from that number. The source version now comes from running the image the container is on, by ID rather than by the tag it was started from, using the same command and the same fallback stage already uses for the target image — the two have to agree about what a Stalwart image reports or the source and target could be read by different rules. Verified against a real stalwartlabs/stalwart image, not only the fake. Deployment kind is detected once and shared, rather than asked again by the check that reports it. Two answers for one run is not a thing this should be able to produce. The same reasoning retires preserve-binary on a container: there is nothing on this host to move aside, and the equivalent is already guaranteed, since cutover renames the old container and never prunes the old image. Renaming a stray binary would have preserved something nothing was running.
This commit is contained in:
@@ -77,6 +77,47 @@ func VersionFromOutput(out string) (string, error) {
|
||||
return v.String(), nil
|
||||
}
|
||||
|
||||
// DetectContainerVersion reads the running version of a container
|
||||
// deployment, which is a property of its image rather than of anything on
|
||||
// this host.
|
||||
//
|
||||
// A container-only host has no Stalwart binary to ask, and a host that
|
||||
// happens to have one is worse than a host that does not: a stray
|
||||
// /usr/local/bin/stalwart left over from an older install answers
|
||||
// confidently with a version nothing is running. So this asks the image
|
||||
// the container is actually on, by ID rather than by the tag it was
|
||||
// started from.
|
||||
//
|
||||
// The command mirrors internal/stage's, including the fallback, because
|
||||
// the two have to agree about what a Stalwart image reports or the source
|
||||
// and target versions could be read by different rules.
|
||||
func DetectContainerVersion(ctx context.Context, containerName string) (string, error) {
|
||||
if containerName == "" {
|
||||
containerName = "stalwart"
|
||||
}
|
||||
out, err := exec.CommandContext(ctx, "docker", "inspect", "-f", "{{.Image}}", containerName).Output()
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("preflight: reading the image behind container %s: %w", containerName, err)
|
||||
}
|
||||
imageID := strings.TrimSpace(string(out))
|
||||
if imageID == "" {
|
||||
return "", fmt.Errorf("preflight: container %s reports no image", containerName)
|
||||
}
|
||||
|
||||
raw, runErr := exec.CommandContext(ctx, "docker", "run", "--rm", imageID, "--version").Output()
|
||||
if runErr != nil {
|
||||
raw, runErr = exec.CommandContext(ctx, "docker", "run", "--rm", "--entrypoint", "stalwart", imageID, "--version").Output()
|
||||
}
|
||||
if runErr != nil {
|
||||
return "", fmt.Errorf("preflight: asking image %s for its version: %w", shortID(imageID), runErr)
|
||||
}
|
||||
v, err := VersionFromOutput(string(raw))
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("preflight: image %s did not report a version this understands: %w", shortID(imageID), err)
|
||||
}
|
||||
return v, nil
|
||||
}
|
||||
|
||||
// DetectVersion runs the installed binary's --version flag and extracts a
|
||||
// semver from its output.
|
||||
func DetectVersion(ctx context.Context, binaryPath string) (string, error) {
|
||||
|
||||
Reference in New Issue
Block a user