#!/bin/sh # Build only; this never starts services. # # The revision is validated and baked into the image (BUILD_ID + the OCI # revision label), so the result can always be traced back to a commit and # /api/build can report it at runtime. Plain `docker compose build` does not set # GIT_REVISION and produces an image labelled "unknown" — which is why this is # the supported way to build. # # The image is tagged twice: ped-ai-local: is immutable and is what a # deploy should name, ped-ai-local:latest is the convenience pointer. set -eu cd "$(dirname "$0")/.." if [ -e .git ]; then GIT_REVISION=$(env -i PATH="$PATH" HOME="${HOME:-}" git rev-parse --verify 'HEAD^{commit}') printf '%s\n' "$GIT_REVISION" | grep -Eq '^[0-9a-f]{40}$' || { echo 'Expected a full lowercase Git SHA' >&2 exit 1 } else GIT_REVISION=unknown echo 'Unversioned development build: revision unknown' >&2 fi export GIT_REVISION # A local build always writes the local tag, even when .env pins PED_AI_IMAGE to # a deployed registry image — otherwise building here would quietly overwrite # the tag a deploy is pinned to. PED_AI_IMAGE=ped-ai-local:latest export PED_AI_IMAGE docker compose build "$@" pediatric-scribe if [ "$GIT_REVISION" != unknown ]; then docker tag ped-ai-local:latest "ped-ai-local:$GIT_REVISION" echo "Built ped-ai-local:$GIT_REVISION (also tagged :latest)" >&2 else echo 'Built ped-ai-local:latest with no recorded revision' >&2 fi # A deploy runs `docker compose up`, which reads PED_AI_IMAGE from .env — not # the tag just built. A pin left behind from an earlier deploy therefore starts # that older image, and `up` reports success either way: the build looks done, # the health check passes, and the running app is silently an older revision. # That has already cost a session — it rolled the app back far enough to remove # a feature, and the missing feature was read as a new bug. # # Not corrected automatically: the pin is how a deploy names a revision on # purpose, including a deliberate rollback. Said loudly instead. if [ "$GIT_REVISION" != unknown ] && [ -f .env ]; then PINNED=$(sed -n 's/^PED_AI_IMAGE=//p' .env | tail -1) case "$PINNED" in '') ;; *"$GIT_REVISION") ;; *) echo >&2 echo "WARNING: .env pins PED_AI_IMAGE=$PINNED" >&2 echo " which is NOT the image just built." >&2 echo " 'docker compose up -d --no-build' will start the pinned image," >&2 echo " not this build. To deploy what was just built:" >&2 echo >&2 echo " sed -i 's|^PED_AI_IMAGE=.*|PED_AI_IMAGE=ped-ai-local:$GIT_REVISION|' .env" >&2 echo >&2 echo " Then confirm after starting it:" >&2 echo " curl -fsS http://127.0.0.1:3552/api/build" >&2 echo >&2 ;; esac fi