feat: pin the database container to PostgreSQL 18.6 (E00-S03-T01)

- compose.yaml: db.image pinned to postgres:18.6-bookworm (exact 18.6 minor,
  same bookworm flavor, no Alpine drift) so the database container is
  reproducible and exposes the expected PostgreSQL version; document the
  rollback (revert image to postgres:18-bookworm)
- .gitea/workflows/ci.yml: new compose-config job runs
  tests/compose-config.test.mjs on every PR so the pinned-version criterion
  gates merges (docker-gated real-stack probes skip cleanly without a daemon)
This commit is contained in:
implementer
2026-08-29 10:45:00 +00:00
parent 38c17f0e7a
commit 4cd68c9193
2 changed files with 24 additions and 4 deletions
+17
View File
@@ -36,3 +36,20 @@ jobs:
node-version: '24' node-version: '24'
- name: Run secrets-not-embedded test suite - name: Run secrets-not-embedded test suite
run: node --test tests/secrets-not-embedded.test.mjs run: node --test tests/secrets-not-embedded.test.mjs
# E00-S03-T01: the static assertions of tests/compose-config.test.mjs (db
# image pinned to postgres:18.6-bookworm, health gate, volume persistence,
# build platforms) gate every PR (the docker-gated real-stack probes inside
# the same file run where a Docker daemon is available and skip cleanly
# otherwise).
compose-config:
name: Compose config (E00-S03-T01)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Node.js 24
uses: actions/setup-node@v4
with:
node-version: '24'
- name: Run compose-config test suite
run: node --test tests/compose-config.test.mjs
+7 -4
View File
@@ -1,4 +1,4 @@
# EPPP Docker Compose baseline — [E00-S02-T01..T08] # EPPP Docker Compose baseline — [E00-S02-T01..T08] + [E00-S03-T01]
# #
# `docker compose up -d` starts both the database (PostgreSQL) and the # `docker compose up -d` starts both the database (PostgreSQL) and the
# application (@personal-blog/server). Rollback: `docker compose down`. # application (@personal-blog/server). Rollback: `docker compose down`.
@@ -53,9 +53,12 @@
services: services:
db: db:
# PostgreSQL 18 on Debian bookworm — the documented runtime target # PostgreSQL 18.6 on Debian bookworm — the documented runtime target
# (Technology-Stack §5.2/§5.4/§6.2, golden tuple §7; no Alpine drift). # (Technology-Stack §5.2/§5.4/§6.2, golden tuple §7; no Alpine drift),
image: postgres:18-bookworm # pinned to the exact 18.6 minor (E00-S03-T01) so the database container
# is reproducible and exposes the expected PostgreSQL version. Rollback:
# revert `image` to `postgres:18-bookworm`.
image: postgres:18.6-bookworm
environment: environment:
POSTGRES_DB: ${POSTGRES_DB:-eppp} POSTGRES_DB: ${POSTGRES_DB:-eppp}
POSTGRES_USER: ${POSTGRES_USER:-eppp} POSTGRES_USER: ${POSTGRES_USER:-eppp}