Skip to content

Scope the transient-target policy to role-matched targets

Placeholder ppxd requested to merge fix/transient-policy-role-scope into main

Summary

  • The project "Transient Deployment Targets" policy (unavailable target → fail or skip the deployment) was applied to every target in the environment, before any role filtering. An unavailable target whose role no step targets — i.e. not a deployment target for this release — wrongly triggered "Fail deployment" and blocked an otherwise-valid deployment.
  • Reproduced from the release preview: the steps preview correctly showed 1 target(s) matched (the role-matched target was available), yet the banner read 2 deployment target(s) are unavailable … 'Fail deployment' listing two machines with unrelated roles.
  • The bug affected both the preview (DeploymentService.Preview) and the real pipeline (4_PrepareDeploymentPhase applied the policy in FindTargetsAsync, before PreFilterTargetsByRoles).

Fix

  • Add a shared role-aware overload TransientDeploymentTargetEvaluator.ApplyProjectPolicy(candidates, requiredRoles, settingsJson) that narrows the candidate set to targets matching at least one step role (the same DeploymentTargetFinder.CollectAllTargetRoles the pipeline already uses) before applying the policy. Both call sites now use it, so preview and pipeline stay converged.
  • A target matching no step role is ignored by the policy (neither fails the deployment nor is reported excluded). A target matching a step role still fails the deployment when unavailable. An empty role set (some step targets all machines) means no narrowing — unchanged behaviour.

Non-breaking + generic

  • FilterByRoles with an empty role set returns all candidates, so projects/processes without explicit step roles behave exactly as before.
  • Pure narrowing of the policy's input; no policy semantics changed. The convergence guard (preview ⇄ deploy) is preserved — both compute roles via the same CollectAllTargetRoles + ResolveScope.

Test plan

  • Unit PrepareDeploymentPhaseTransientTargetTests — new: FailDeployment_UnavailableTargetWithUnmatchedRole_DoesNotFail (the reported bug) + FailDeployment_UnavailableTargetWithMatchedRole_StillFails (policy still fires for real deployment targets). Verified red→green: the unmatched-role test fails (db-down blocks the deploy) when the overload ignores roles, passes with the fix.
  • Existing transient-target / preview / planner / target-finder / convergence sweep: 153/153, no regression. dotnet build (Core + Api) 0 errors.

Merge request reports

Loading