feat(out): add concourse_url source field to override ATC_EXTERNAL_URL - #20
Merged
Merged
Conversation
Concourse's externalUrl Helm value may be locked to an STS WebIdentity OIDC issuer hostname that differs from the URL users actually reach builds through (e.g. via a Teleport proxy). When concourse_url is set in the resource source, it overrides ATC_EXTERNAL_URL at the start of Out() so that both safeExpandEnv and the auto-generated commit status target URL in UpdateCommitStatus point to the correct public hostname.
ujala-singh
added a commit
that referenced
this pull request
Oct 3, 2026
Replaces the single cursor-wide comment watermark with a per-PR table, removing a real limitation: Concourse's check protocol only ever hands this resource back the one version it considers "latest," not a per-PR history, so the previous design could only reliably track whichever single PR happened to be that version. The moment the cursor moved to a different PR (e.g. that PR got a new commit), every other PR's comment-trigger watermark was gone -- a later comment on it looked exactly like a PR being checked for the first time, silently re-establishing a baseline instead of firing. Adds Version.CommentWatermarks (wire field comment_watermarks): a map[string]int64 of PR number -> highest matching comment ID seen for it. Since Concourse always hands back whatever version this resource last emitted, stamping the complete, current table onto EVERY version (not just the one it's "about") means the table survives regardless of which PR ends up being remembered as "latest" next -- turning Concourse's own replay mechanism into the storage, with no new external dependency. prlist.Check now scans every path-matching PR (filteredPRs) plus every PR with an existing watermark entry that's still open (commentTriggerScope), instead of just the single recovered cursor PR from the previous fix. Entries for PRs no longer in the open-PR list are pruned each check, bounding the table to roughly the current open-PR count. commentWatermarks() falls back to the legacy single-PR CommentID/CommentBaseline fields when CommentWatermarks is empty, so upgrading from an older version carries the one watermark that WAS reliable forward instead of resetting it. encoding/json sorts map[string]T keys when marshaling, so the same watermark content always produces identical bytes -- essential here, since nondeterministic output would make every version carrying this field look "new" to Concourse's ATC on every check, regardless of whether anything actually changed. Added a dedicated test asserting this across 20 repeated marshals of the same map. Adds TestCheck_CommentWatermarks_SurviveCursorMovingToADifferentPR: PR #20 is the cursor, PR #5 (excluded from commit-triggering via source.paths, so the only way its version appears is through the comment trigger) has an established watermark from an earlier check and gets a new comment. Verified it fails against the old single-cursor logic (confirming it actually exercises the fix, not just incidental stamping of an already-matching commit version) and passes with the per-PR table. Also verifies pruning: the stale cursor's own now-gone entry is dropped from the output. Updates Version's existing MarshalJSON/UnmarshalJSON/round-trip tests for the new field (map fields aren't comparable with !=, switched to reflect.DeepEqual) and the protocol-compliance test suite. Documents comment_watermarks in README's Comment Triggers section and the check behavior field explanation, replacing the now-outdated "best-effort, single cursor" caveat for PR list mode.
ujala-singh
added a commit
that referenced
this pull request
Oct 3, 2026
Replaces the single cursor-wide comment watermark with a per-PR table, removing a real limitation: Concourse's check protocol only ever hands this resource back the one version it considers "latest," not a per-PR history, so the previous design could only reliably track whichever single PR happened to be that version. The moment the cursor moved to a different PR (e.g. that PR got a new commit), every other PR's comment-trigger watermark was gone -- a later comment on it looked exactly like a PR being checked for the first time, silently re-establishing a baseline instead of firing. Adds Version.CommentWatermarks (wire field comment_watermarks): a map[string]int64 of PR number -> highest matching comment ID seen for it. Since Concourse always hands back whatever version this resource last emitted, stamping the complete, current table onto EVERY version (not just the one it's "about") means the table survives regardless of which PR ends up being remembered as "latest" next -- turning Concourse's own replay mechanism into the storage, with no new external dependency. prlist.Check now scans every path-matching PR (filteredPRs) plus every PR with an existing watermark entry that's still open (commentTriggerScope), instead of just the single recovered cursor PR from the previous fix. Entries for PRs no longer in the open-PR list are pruned each check, bounding the table to roughly the current open-PR count. commentWatermarks() falls back to the legacy single-PR CommentID/CommentBaseline fields when CommentWatermarks is empty, so upgrading from an older version carries the one watermark that WAS reliable forward instead of resetting it. encoding/json sorts map[string]T keys when marshaling, so the same watermark content always produces identical bytes -- essential here, since nondeterministic output would make every version carrying this field look "new" to Concourse's ATC on every check, regardless of whether anything actually changed. Added a dedicated test asserting this across 20 repeated marshals of the same map. Adds TestCheck_CommentWatermarks_SurviveCursorMovingToADifferentPR: PR #20 is the cursor, PR #5 (excluded from commit-triggering via source.paths, so the only way its version appears is through the comment trigger) has an established watermark from an earlier check and gets a new comment. Verified it fails against the old single-cursor logic (confirming it actually exercises the fix, not just incidental stamping of an already-matching commit version) and passes with the per-PR table. Also verifies pruning: the stale cursor's own now-gone entry is dropped from the output. Updates Version's existing MarshalJSON/UnmarshalJSON/round-trip tests for the new field (map fields aren't comparable with !=, switched to reflect.DeepEqual) and the protocol-compliance test suite. Documents comment_watermarks in README's Comment Triggers section and the check behavior field explanation, replacing the now-outdated "best-effort, single cursor" caveat for PR list mode.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Concourse's externalUrl Helm value may be locked to an STS WebIdentity OIDC issuer hostname that differs from the URL users actually reach builds through (e.g. via a Teleport proxy). When concourse_url is set in the resource source, it overrides ATC_EXTERNAL_URL at the start of Out() so that both safeExpandEnv and the auto-generated commit status target URL in UpdateCommitStatus point to the correct public hostname.