From 25368547cbda62e1cc34d99a363635dbd0c988b1 Mon Sep 17 00:00:00 2001 From: Grant Whitmer Date: Thu, 13 Aug 2026 23:28:57 -0400 Subject: [PATCH] =?UTF-8?q?docs:=20runbook=20=E2=80=94=20never=20pull=20-q?= =?UTF-8?q?,=20never=20force-push=20a=20deployed=20branch?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two deploy traps paid for on 2026-08-14: 'git pull -q' hid a divergent-branch error so a deploy ran against stale code while reporting success, and the divergence came from amending a commit a deploy checkout already tracked. Co-Authored-By: Claude (Fable 5) --- docs/RUNBOOK-VERON.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/docs/RUNBOOK-VERON.md b/docs/RUNBOOK-VERON.md index b915e02..ad16a2c 100644 --- a/docs/RUNBOOK-VERON.md +++ b/docs/RUNBOOK-VERON.md @@ -47,6 +47,17 @@ sudo -E docker compose up -d --build curl -s https://api.windygit.com/version # MUST equal git rev-parse HEAD ``` +⚠️ **Never `git pull -q` in a deploy script.** `-q` hides *errors*, not just +noise. On 2026-08-14 a divergent branch made `pull -q` fail silently and the +"deploy" ran for 20 minutes against stale code while reporting success. Use +`git fetch && git merge --ff-only` (or `reset --hard origin/main` on THIS +checkout only, which holds no local work) and read the output. + +⚠️ **Never force-push a branch a deploy checkout tracks.** An earlier +`git commit --amend` + `--force-with-lease` rewrote history `/srv/windygit/src` +was already sitting on, orphaning it. If you must amend, re-point the deploy +checkout in the same breath. + ⚠️ **Never put `COMMIT_SHA` in `.env`.** It does nothing here — the sha is baked into the image and a runtime override is ignored with a warning (I-12). That env pin is the documented root cause of nine sibling services misreporting their