Skip to content

fix(ci): rebuild service images when their workspace packages change - #171

Open
MarkAlex1234 wants to merge 1 commit into
reloop-labs:mainfrom
MarkAlex1234:fix/ci-docker-workflow-package-paths
Open

MarkAlex1234 wants to merge 1 commit into
reloop-labs:mainfrom
MarkAlex1234:fix/ci-docker-workflow-package-paths

Conversation

@MarkAlex1234

@MarkAlex1234 MarkAlex1234 commented Oct 5, 2026 •

Copy link
Copy Markdown

Summary

Each be-* / fe-* Docker workflow builds with context: ., and the images copy /app/packages (e.g. apps/backend/api-key/Dockerfile). But most workflows' paths: only list the app's own directory. So a change merged to main that touches only a shared package (packages/db, packages/auth, packages/bus, packages/cache, …) doesn't rebuild or push any service image, and the published images keep running the old package code until something else in each app changes. This PR adds each app's transitive workspace dependencies under packages/ to both its push and pull_request path lists. Nothing else in the workflows changes.

The lists come from each app's package.json workspace:* dependencies, followed transitively. For example, be-api-key depends on @reloop/db, cache, auth, bus and code-samples, and auth pulls in dns and webhook-events. be-inbound, be-smtp and be-spam were already complete and are untouched.

Linked issue

None. This is a small CI fix (path filters only), so I skipped opening an issue first; happy to open one if you prefer.

Type of change

  • fix — bug fix
  • chore — tooling, CI, dependencies

Affected areas

  • .github/workflows/be-*.yml (16 files), .github/workflows/fe-*.yml (5 files)

How tested

  • All workflow files parse as YAML; the diff is insertions only (302 lines added across 21 files, all inside on.*.paths).
  • I recomputed the dependency closure for every app after the change: each workflow now covers all packages/* its app (transitively) depends on.

Not covered on purpose: bun.lock / root package.json. Adding them would rebuild every image on any dependency bump. fe-dashboard.yml already does this, so say if you want it everywhere.

Trade-off: shared packages like db/auth sit under most services, so a change there will now rebuild most images. That is the correct result, but it is more CI than today. If that becomes a cost problem, the alternative is a single workflow that computes the affected services and builds them as a matrix. Disclosure: I maintain a GitHub Action that does that, dynamic-monorepo, and its dependency graph is how I found these gaps. This PR doesn't use it.

Deploy / breaking notes

None.

Checklist

  • Linked the related issue above (or noted why none is needed)
  • bun run check passes (lint + format): not applicable, YAML-only change outside the linted sources
  • No secrets, API keys, tokens, or PII in the diff
  • Docs updated if behaviour, setup, ports, or env vars changed (or N/A)

Summary by CodeRabbit

  • Chores
    • Backend build workflows now run when changes affect shared packages used by those services, alongside existing app-specific triggers.
    • Frontend build workflows now also run for changes to shared packages used by the console, dashboard, docs, links, and web apps.
    • Existing workflow triggers for application files and other configured paths remain in place.

RetriggerConfidence Score: 3/5

The PR is not safe to merge until fork PRs can build without Docker Hub secrets and service pushes cannot publish older images last.

Findings

  1. P1 Fork PR checks fail ▶
  2. P1 Older images can deploy ▶

Summary

The PR adds transitive workspace-package paths to service image workflows so package-only changes start rebuilds.

  • Backend paths apply to pushes and PRs; frontend paths apply to pushes.
  • The new triggers expose failing fork-PR logins and allow overlapping pushes to publish older images last.

MarkAlex1234 acknowledged that shared-package changes will rebuild many images and described the extra CI work as the intended trade-off.

Reviews (1) · Last reviewed commit: "fix(ci): rebuild service images when the..."

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 9fce2ef5-342e-4497-bc74-ed9050c232d8
📥 Commits

Reviewing files that changed from the base of the PR and between 08b9b5b and a960eed.

📒 Files selected for processing (21)
  • .github/workflows/be-admin.yml
  • .github/workflows/be-api-key.yml
  • .github/workflows/be-auth.yml
  • .github/workflows/be-campaigns.yml
  • .github/workflows/be-contacts.yml
  • .github/workflows/be-credits.yml
  • .github/workflows/be-domain.yml
  • .github/workflows/be-email.yml
  • .github/workflows/be-inbox.yml
  • .github/workflows/be-logs.yml
  • .github/workflows/be-mail.yml
  • .github/workflows/be-template.yml
  • .github/workflows/be-tools.yml
  • .github/workflows/be-upload.yml
  • .github/workflows/be-webhook.yml
  • .github/workflows/be-workflow.yml
  • .github/workflows/fe-console.yml
  • .github/workflows/fe-dashboard.yml
  • .github/workflows/fe-docs.yml
  • .github/workflows/fe-links.yml
  • .github/workflows/fe-web.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Backend and frontend Docker workflow path filters now include additional shared package directories. Existing path filters remain.

Changes

Shared-package workflow triggers

Layer / File(s) Summary
Backend workflow filters
.github/workflows/be-*.yml
Backend Docker workflow push and pull-request filters now include additional shared package paths.
Frontend workflow filters
.github/workflows/fe-*.yml
Frontend Docker workflow push filters now include additional shared package paths.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: pranavp10

Merge Risk: ⚪ Minimal · up to a960e

No concrete merge-blocking risk was identified in the workflow trigger updates.

Security Architecture Review

Security architecture risk: 🔵 Low · up to a960e

The change broadens existing build and deployment triggers without changing permissions or pull-request publication gates. No introduced vulnerability was established, but secret-access policy and downstream rollout recovery could not be confirmed.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A shared-package push can activate multiple service image publications and deployment requests. The affected surface is the existing repository CI-to-registry-to-deployment chain; credential reach, deployed environments and tenant exposure cannot be bounded from the available configuration.

Trust Boundaries and Controls

  • inferred — Package-only pull requests now enter additional existing build jobs, but no new pull-request registry-publication or deployment path was found. Login alone does not prove credential theft: publication gates and the absence of explicit build-secret forwarding are counterevidence. Secret availability and build-to-runner isolation remain unresolved.

Hardening Proposals

  • proposed — Consider applying the mail workflow's pull-request login exclusion consistently, so build-only validation does not authenticate to the registry unnecessarily. This is a hardening proposal, not a verified credential-exposure finding.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: service images rebuild when their workspace packages change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

- 'packages/bus/**'
- 'packages/cache/**'
- 'packages/code-samples/**'
- 'packages/db/**'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Fork PR checks fail

A fork PR that changes only packages/db now starts this workflow. Fork PRs do not receive the Docker Hub secrets, but docker/login-action runs before the build and needs them. The check fails before it can build the image. Skip login on PR runs that do not push an image.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

- 'packages/bus/**'
- 'packages/cache/**'
- 'packages/code-samples/**'
- 'packages/db/**'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Older images can deploy

Two close pushes to main that change packages/db now start overlapping builds of this service. Both write the same latest tag without a run-order guard. If the older build finishes last, it replaces the newer image and its deploy request can leave the service running old package code. Run each service’s pushes in order or deploy by image digest.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant