From cc0e1822626dc92406346c2c75e84fda7412c9cc Mon Sep 17 00:00:00 2001 From: Hussain Chinoy Date: Mon, 28 Sep 2026 19:23:11 +0000 Subject: [PATCH] feat(release): make release-gateway for gateway/CLI-only releases; CHANGELOG v0.1.1 (unreleased) make release-gateway VERSION=vX.Y.Z tags a release without rebuilding the serving images and refuses if deploy/cloudrun changed since the last release. CHANGELOG v0.1.1: PRs #18, #19, #22, #23; serving images stay v0.1.0. Runbook documents the gateway-only path. --- CHANGELOG.md | 17 ++++++++++++++++- Makefile | 14 +++++++++++++- docs-site/src/content/docs/operate/runbook.md | 5 +++++ docs/operate/runbook.md | 5 +++++ 4 files changed, 39 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 4bb1ee5..47abd63 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,22 @@ Releases of the `dgem` serving images (`dgem`, `dgem-weights`), gateway and CLI. Versioning: `vMAJOR.MINOR.PATCH`. **Major:** breaking API or response changes. **Minor:** vLLM runtime or model changes, new features. **Patch:** fixes. Images are published to `us-central1-docker.pkg.dev/dgem-diffusiongemma/dgem/` as `:` and `:`; `:latest` moves only after -a release is validated. Release process: [runbook](docs/operate/runbook.md#release-a-new-version). +a release is validated. Release process: [runbook](docs/operate/runbook.md#release-a-new-version). Gateway/CLI-only releases +(`make release-gateway`) reuse the previous serving images. + +## v0.1.1 (unreleased) + +Gateway, MCP and CLI only. **Serving images are unchanged**: the latest serving image is still `v0.1.0` +(`dgem@sha256:5fa4a866…`), and production Vertex and Cloud Run keep running it. + +- Security (#18): `POST /api/backend-config` and `/api/vertex/deploy|teardown` require `--enable-admin-api` + (off by default); request-supplied `vertex_url` limited to the configured endpoint or + `--allowed-vertex-endpoints`. Previously any signed-in user could change routing for everyone or deploy/tear down + the Vertex endpoint. +- Backend allow-list (#18): `--backends` / `DGEM_BACKENDS`, validated at startup; unknown or disabled backends + return 400 on every surface. Studio backend choice is per browser. +- MCP: `dgem mcp` over stdio honours `DGEM_VERTEX_URL` for the allow-list (#19), health and routing (#22); tool + schemas list only the configured backends (#23). ## v0.1.0 (2026-09-28) diff --git a/Makefile b/Makefile index f0449be..ba8094b 100644 --- a/Makefile +++ b/Makefile @@ -1,4 +1,4 @@ -.PHONY: help build run test fmt clean setup download serve stop gateway-up gateway-down local-up local-down local-status image image-weights release publish-latest bench bench-ecotone install docs-build docs-dev cloudrun-deploy gce-deploy gce-teardown check-public docs-sync-check +.PHONY: help build run test fmt clean setup download serve stop gateway-up gateway-down local-up local-down local-status image image-weights release release-gateway publish-latest bench bench-ecotone install docs-build docs-dev cloudrun-deploy gce-deploy gce-teardown check-public docs-sync-check .DEFAULT_GOAL := help @@ -143,6 +143,18 @@ release: ## Cut a release: make release VERSION=v0.2.0 (clean main, tests, CHANG @gcloud artifacts docker images describe $(REGISTRY)/dgem-weights:$(VERSION) --format='value(image_summary.digest)' @echo "Next: validate (docs/operate/runbook.md), then 'make publish-latest VERSION=$(VERSION)' and 'git push origin $(VERSION)'." +release-gateway: ## Tag a gateway/CLI-only release: make release-gateway VERSION=v0.1.1 (no serving image rebuild) + @echo "$(VERSION)" | grep -Eq '^v[0-9]+\.[0-9]+\.[0-9]+$$' || { echo "usage: make release-gateway VERSION=vMAJOR.MINOR.PATCH"; exit 1; } + @test -z "$$(git status --porcelain --untracked-files=no)" || { echo "working tree not clean"; exit 1; } + @test "$$(git rev-parse --abbrev-ref HEAD)" = main || { echo "releases are cut from main"; exit 1; } + @test "$$(git rev-parse HEAD)" = "$$(git rev-parse @{u} 2>/dev/null)" || { echo "push main first"; exit 1; } + @grep -q "^## $(VERSION)" CHANGELOG.md || { echo "add a '## $(VERSION)' section to CHANGELOG.md first"; exit 1; } + @! git rev-parse -q --verify "refs/tags/$(VERSION)" >/dev/null || { echo "tag $(VERSION) already exists"; exit 1; } + @git diff --quiet "$$(git describe --tags --match 'v*' --abbrev=0)" HEAD -- deploy/cloudrun || { echo "deploy/cloudrun changed since the last release: use 'make release' (serving images must be rebuilt)"; exit 1; } + go test ./cmd/ ./pkg/... + git tag -a $(VERSION) -m "dgem $(VERSION) (gateway/CLI; serving images unchanged)" + @echo "==> Tagged $(VERSION). Push it (git push origin $(VERSION)) and redeploy the gateway from the tag." + publish-latest: ## After validation: point dgem:latest and dgem-weights:latest at VERSION @test -n "$(VERSION)" || { echo "usage: make publish-latest VERSION=v0.2.0"; exit 1; } gcloud artifacts docker tags add $(REGISTRY)/dgem:$(VERSION) $(REGISTRY)/dgem:latest diff --git a/docs-site/src/content/docs/operate/runbook.md b/docs-site/src/content/docs/operate/runbook.md index 4279d07..68aa3d7 100644 --- a/docs-site/src/content/docs/operate/runbook.md +++ b/docs-site/src/content/docs/operate/runbook.md @@ -82,6 +82,11 @@ images carry `org.opencontainers.image.version`, and `dgem --version` prints it. [Public container images](/dgem/deploy/public-images/). 5. Deploy to your own endpoints by digest; record the version in your deployment log. +If only gateway, MCP or CLI code changed (nothing under `deploy/cloudrun/`), use +`make release-gateway VERSION=vX.Y.Z` instead of step 2: it tags the release without rebuilding the serving images, +then redeploy the gateway from the tag. Serving endpoints keep the previous image, and the CHANGELOG says which +serving image a release uses. + Builds between releases report `git describe` versions such as `v0.1.0-3-gabc1234`. ## Roll back diff --git a/docs/operate/runbook.md b/docs/operate/runbook.md index fda8052..92de19c 100644 --- a/docs/operate/runbook.md +++ b/docs/operate/runbook.md @@ -84,6 +84,11 @@ images carry `org.opencontainers.image.version`, and `dgem --version` prints it. [Public container images](../deploy/public-images.md). 5. Deploy to your own endpoints by digest; record the version in your deployment log. +If only gateway, MCP or CLI code changed (nothing under `deploy/cloudrun/`), use +`make release-gateway VERSION=vX.Y.Z` instead of step 2: it tags the release without rebuilding the serving images, +then redeploy the gateway from the tag. Serving endpoints keep the previous image, and the CHANGELOG says which +serving image a release uses. + Builds between releases report `git describe` versions such as `v0.1.0-3-gabc1234`. ## Roll back