feat: report the build version and aggregate the platform's; add release automation - #3
Merged
Merged
Conversation
Part of kube-workspaces/deploy#2. Adds a release workflow and the .github/release.yml categories used to generate notes, both identical across the five repositories so a reader moving between them sees the same structure. The note preamble comes from a shared generator in the deploy repo, which classifies the commits since the last tag. That matters here because this component often has nothing but CI and docs changes in a cycle and still gets tagged to hold the platform version line — in that case the notes say so explicitly rather than leaving someone to infer it from a list of CI commits. The workflow defaults to a dry run so the notes can be reviewed before anything is tagged.
Closes #2. Nothing recorded which version was running. The Dockerfile built with no -ldflags, there was no version variable, and no endpoint reported one — so the only signal was the image tag, which is `latest` in the default manifests and therefore says nothing. Version, commit and build date are now compiled in, defaulting to dev/unknown so a plain `go build` still works, and surfaced three ways: --version prints and exits startup log so a pod is identifiable from its logs alone GET /platform/version JSON The API is the natural place to answer "what is this cluster running?", so /platform/version aggregates: its own compiled-in build, plus the image each of the four components is actually running, read from their pod specs. Reading pod specs rather than calling each component's own /version avoids assuming the other components are healthy — which is precisely when you most want this endpoint. It is exempt from the auth middleware and from maintenance mode. Identifying a deployment is diagnostic, not privileged, and needing a session to read it defeats the purpose during an incident; it exposes nothing beyond component image tags. The maintenance exemption was broadened from /platform/config to /platform/ to cover both, since both are used to diagnose maintenance mode. debug.ReadBuildInfo() is not a substitute: it reports "(devel)" for a build not driven by `go install module@version`, which is the case for the container build. The workflow passes VERSION from docker/metadata-action rather than reconstructing it, so the image tag and the reported version cannot drift. Note: http.go and internal/auth/config.go have pre-existing gofmt deviations, left untouched rather than mixing unrelated formatting into this change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #2. Part of kube-workspaces/deploy#2.
Version at runtime
Nothing recorded which version was running. The Dockerfile built with no
-ldflags, there was no version variable, and no endpoint reported one — so theonly signal was the image tag, which is
latestin the default manifests andtherefore says nothing.
--versionv0.3.0 (commit abc1234, built …, linux/amd64, go1.26.7)GET /platform/versionDefaults are
dev/unknown, so a plaingo buildstill works./platform/versionaggregates the whole platformThe API is the natural place to answer "what is this cluster running?", so the
endpoint reports its own compiled-in build plus the image each of the four
components is actually running:
{ "api": { "version": "v0.3.0", "commit": "abc1234", "buildDate": "…", "go": "go1.26.7", "platform": "linux/amd64" }, "images": { "controller": "ghcr.io/kube-workspaces/controller:v0.3.0", "api": "ghcr.io/kube-workspaces/api:v0.3.0", "proxy": "ghcr.io/kube-workspaces/proxy:v0.3.0", "frontend": "ghcr.io/kube-workspaces/frontend:v0.3.0" } }It reads pod specs rather than calling each component's own
/version, whichavoids assuming the other components are healthy — precisely the situation in
which you most want this endpoint.
Auth
Exempt from the auth middleware and from maintenance mode. Identifying a
deployment is diagnostic, not privileged, and needing a session to read it
defeats the purpose during an incident; it exposes nothing beyond component image
tags.
The maintenance exemption was broadened from
/platform/configto/platform/to cover both, since both are used to diagnose maintenance mode.
The workflow passes
VERSIONfromdocker/metadata-actionrather thanreconstructing it, so the image tag and the reported version cannot drift.
Release automation
Adds the release workflow and
.github/release.ymlcategories, identical acrossthe five repositories. The note preamble comes from a shared generator in the
deploy repo which states explicitly when a release has no functional changes —
relevant here, since this component is often tagged only to hold the platform
version line. Defaults to a dry run.
Verification
go build,go vet,go test ./cmd/... ./internal/...all pass--versionverified locallyNote
cmd/kube_workspaces/http.goandinternal/auth/config.gohave pre-existinggofmt deviations. I left them untouched rather than mixing unrelated formatting
churn into this diff, but they are worth a separate cleanup.