perf: reuse a deploy-key proof instead of asking the server twice
A key rotation verified the candidate with `git ls-remote`, then immediately ran preflightCandidate, which threw that result away and ran the same command over a second SSH connection. Nothing happens between the two calls that could change the answer, and the proof was already being passed in. preflightCandidate now uses a proof that established a remote commit and falls back to verifying when it is handed nothing usable, so it still works as a standalone gate. Every ssh.exec opens its own connection, so this removes a full TCP, key exchange and authentication round trip from a rotation. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
d77643c058
commit
beeafdcba7
@@ -50,7 +50,10 @@ class UnraidDeployKeyHost {
|
||||
const f = parseMarker((await this.execute(server, script, { timeout: 45_000, maxOutput: 256 * 1024 })).stdout, marker);
|
||||
return { ready: /^[0-9a-f]{40}$/i.test(f.remoteSha || ""), remoteSha: f.remoteSha || null, fingerprint: f.fingerprint || null, hostFingerprint: f.hostFingerprint || null };
|
||||
}
|
||||
async preflightCandidate(context) { const proof = await this.verifyCandidate(context); if (!proof.ready) throw new Error("Candidate preflight did not prove the remote branch."); return proof; }
|
||||
// A caller that just verified this candidate passes its proof in. Re-running
|
||||
// `git ls-remote` would open a second SSH connection to ask the same question,
|
||||
// with nothing in between that could change the answer.
|
||||
async preflightCandidate(context) { const proof = context?.proof?.remoteSha ? context.proof : await this.verifyCandidate(context); if (!proof.ready) throw new Error("Candidate preflight did not prove the remote branch."); return proof; }
|
||||
async promote({ repository, server, candidate }) {
|
||||
const p = this.paths(repository, server); const c = candidate.paths;
|
||||
await this.execute(server, `test -s ${shellQuote(c.privateKey)}; test -s ${shellQuote(c.publicKey)}; test -s ${shellQuote(c.knownHosts)}; cp -p ${shellQuote(c.privateKey)} ${shellQuote(p.privateKey)}.new; cp -p ${shellQuote(c.publicKey)} ${shellQuote(p.publicKey)}.new; cp -p ${shellQuote(c.knownHosts)} ${shellQuote(p.knownHosts)}.new; mv ${shellQuote(p.privateKey)}.new ${shellQuote(p.privateKey)}; mv ${shellQuote(p.publicKey)}.new ${shellQuote(p.publicKey)}; mv ${shellQuote(p.knownHosts)}.new ${shellQuote(p.knownHosts)}`);
|
||||
|
||||
Reference in New Issue
Block a user