From 260bf0b7526b97a0f1ea02100482aaca0c7cf463 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 25 Sep 2026 23:51:30 +0200 Subject: [PATCH] the spec names the resolver and the address MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit dns and ip were declared, validated, handed to the runtime — and part of no comparison, so their first deployment compared every container equal and changed nothing, silently. The same shape as 04-ISSUES/045: a field that is not in the spec is a field that can never reach a container that already runs. --- internal/apply/apply.go | 9 +++++++++ internal/apply/vocabulary_test.go | 16 ++++++++++++++++ 2 files changed, 25 insertions(+) diff --git a/internal/apply/apply.go b/internal/apply/apply.go index 549cf29..132fa8c 100644 --- a/internal/apply/apply.go +++ b/internal/apply/apply.go @@ -1314,6 +1314,15 @@ func containerSpecReading(r *declaration.Container, declares, reads map[string]s for _, a := range r.Args { b.WriteString("arg " + a + "\n") } + // The resolver and address are part of what was declared: a container whose dns or ip moved + // is a different container, or the fields could never reach one that already ran — which is + // exactly how their first deployment silently changed nothing. + for _, d := range r.Dns { + b.WriteString("dns " + d + "\n") + } + if r.IP != "" { + b.WriteString("ip " + r.IP + "\n") + } // The cadence is part of what was declared, so a changed schedule is a changed spec — the marker // moves and the install is reported "updated" and re-established. Added only when present, so no // ordinary container's or run-once step's digest moves for a field it does not set. diff --git a/internal/apply/vocabulary_test.go b/internal/apply/vocabulary_test.go index 4075ff2..cc14fd9 100644 --- a/internal/apply/vocabulary_test.go +++ b/internal/apply/vocabulary_test.go @@ -435,3 +435,19 @@ func TestAContainerIsGivenItsResolverAndItsAddress(t *testing.T) { } } } + +// The resolver and address are part of the spec — a container whose dns or ip moved is a +// different container, or the fields can never reach one that already runs. That is not +// hypothetical: their first deployment compared equal and changed nothing. +func TestAChangedResolverOrAddressIsAChangedContainer(t *testing.T) { + base := &declaration.Container{ID: "c", Name: "x", Image: "a@sha256:00"} + withDns := &declaration.Container{ID: "c", Name: "x", Image: "a@sha256:00", Dns: []string{"192.168.203.254"}} + withIP := &declaration.Container{ID: "c", Name: "x", Image: "a@sha256:00", IP: "192.168.203.254"} + plain := containerSpecReading(base, nil, nil) + if containerSpecReading(withDns, nil, nil) == plain { + t.Error("adding a resolver did not change the spec, so it can never reach a running container") + } + if containerSpecReading(withIP, nil, nil) == plain { + t.Error("adding an address did not change the spec, so it can never reach a running container") + } +} -- 2.54.0