Skip to content

feat(out): add concourse_url source field to override ATC_EXTERNAL_URL - #20

Merged
ujala-singh merged 1 commit into
mainfrom
feat/concourse-url-override
Sep 19, 2026
Merged

ujala-singh merged 1 commit into
mainfrom
feat/concourse-url-override

Conversation

@ujala-singh

Copy link
Copy Markdown
Owner

Concourse's externalUrl Helm value may be locked to an STS WebIdentity OIDC issuer hostname that differs from the URL users actually reach builds through (e.g. via a Teleport proxy). When concourse_url is set in the resource source, it overrides ATC_EXTERNAL_URL at the start of Out() so that both safeExpandEnv and the auto-generated commit status target URL in UpdateCommitStatus point to the correct public hostname.

Concourse's externalUrl Helm value may be locked to an STS WebIdentity
OIDC issuer hostname that differs from the URL users actually reach builds
through (e.g. via a Teleport proxy). When concourse_url is set in the
resource source, it overrides ATC_EXTERNAL_URL at the start of Out() so
that both safeExpandEnv and the auto-generated commit status target URL
in UpdateCommitStatus point to the correct public hostname.
@ujala-singh
ujala-singh merged commit bc50020 into main Sep 19, 2026
3 checks passed
@ujala-singh
ujala-singh deleted the feat/concourse-url-override branch September 19, 2026 19:00
ujala-singh added a commit that referenced this pull request Oct 3, 2026
Replaces the single cursor-wide comment watermark with a per-PR table,
removing a real limitation: Concourse's check protocol only ever hands
this resource back the one version it considers "latest," not a per-PR
history, so the previous design could only reliably track whichever
single PR happened to be that version. The moment the cursor moved to a
different PR (e.g. that PR got a new commit), every other PR's
comment-trigger watermark was gone -- a later comment on it looked
exactly like a PR being checked for the first time, silently
re-establishing a baseline instead of firing.

Adds Version.CommentWatermarks (wire field comment_watermarks): a
map[string]int64 of PR number -> highest matching comment ID seen for
it. Since Concourse always hands back whatever version this resource
last emitted, stamping the complete, current table onto EVERY version
(not just the one it's "about") means the table survives regardless of
which PR ends up being remembered as "latest" next -- turning Concourse's
own replay mechanism into the storage, with no new external dependency.

prlist.Check now scans every path-matching PR (filteredPRs) plus every
PR with an existing watermark entry that's still open
(commentTriggerScope), instead of just the single recovered cursor PR
from the previous fix. Entries for PRs no longer in the open-PR list are
pruned each check, bounding the table to roughly the current open-PR
count. commentWatermarks() falls back to the legacy single-PR
CommentID/CommentBaseline fields when CommentWatermarks is empty, so
upgrading from an older version carries the one watermark that WAS
reliable forward instead of resetting it.

encoding/json sorts map[string]T keys when marshaling, so the same
watermark content always produces identical bytes -- essential here,
since nondeterministic output would make every version carrying this
field look "new" to Concourse's ATC on every check, regardless of
whether anything actually changed. Added a dedicated test asserting this
across 20 repeated marshals of the same map.

Adds TestCheck_CommentWatermarks_SurviveCursorMovingToADifferentPR:
PR #20 is the cursor, PR #5 (excluded from commit-triggering via
source.paths, so the only way its version appears is through the
comment trigger) has an established watermark from an earlier check and
gets a new comment. Verified it fails against the old single-cursor
logic (confirming it actually exercises the fix, not just incidental
stamping of an already-matching commit version) and passes with the
per-PR table. Also verifies pruning: the stale cursor's own now-gone
entry is dropped from the output.

Updates Version's existing MarshalJSON/UnmarshalJSON/round-trip tests
for the new field (map fields aren't comparable with !=, switched to
reflect.DeepEqual) and the protocol-compliance test suite.

Documents comment_watermarks in README's Comment Triggers section and
the check behavior field explanation, replacing the now-outdated
"best-effort, single cursor" caveat for PR list mode.
ujala-singh added a commit that referenced this pull request Oct 3, 2026
Replaces the single cursor-wide comment watermark with a per-PR table,
removing a real limitation: Concourse's check protocol only ever hands
this resource back the one version it considers "latest," not a per-PR
history, so the previous design could only reliably track whichever
single PR happened to be that version. The moment the cursor moved to a
different PR (e.g. that PR got a new commit), every other PR's
comment-trigger watermark was gone -- a later comment on it looked
exactly like a PR being checked for the first time, silently
re-establishing a baseline instead of firing.

Adds Version.CommentWatermarks (wire field comment_watermarks): a
map[string]int64 of PR number -> highest matching comment ID seen for
it. Since Concourse always hands back whatever version this resource
last emitted, stamping the complete, current table onto EVERY version
(not just the one it's "about") means the table survives regardless of
which PR ends up being remembered as "latest" next -- turning Concourse's
own replay mechanism into the storage, with no new external dependency.

prlist.Check now scans every path-matching PR (filteredPRs) plus every
PR with an existing watermark entry that's still open
(commentTriggerScope), instead of just the single recovered cursor PR
from the previous fix. Entries for PRs no longer in the open-PR list are
pruned each check, bounding the table to roughly the current open-PR
count. commentWatermarks() falls back to the legacy single-PR
CommentID/CommentBaseline fields when CommentWatermarks is empty, so
upgrading from an older version carries the one watermark that WAS
reliable forward instead of resetting it.

encoding/json sorts map[string]T keys when marshaling, so the same
watermark content always produces identical bytes -- essential here,
since nondeterministic output would make every version carrying this
field look "new" to Concourse's ATC on every check, regardless of
whether anything actually changed. Added a dedicated test asserting this
across 20 repeated marshals of the same map.

Adds TestCheck_CommentWatermarks_SurviveCursorMovingToADifferentPR:
PR #20 is the cursor, PR #5 (excluded from commit-triggering via
source.paths, so the only way its version appears is through the
comment trigger) has an established watermark from an earlier check and
gets a new comment. Verified it fails against the old single-cursor
logic (confirming it actually exercises the fix, not just incidental
stamping of an already-matching commit version) and passes with the
per-PR table. Also verifies pruning: the stale cursor's own now-gone
entry is dropped from the output.

Updates Version's existing MarshalJSON/UnmarshalJSON/round-trip tests
for the new field (map fields aren't comparable with !=, switched to
reflect.DeepEqual) and the protocol-compliance test suite.

Documents comment_watermarks in README's Comment Triggers section and
the check behavior field explanation, replacing the now-outdated
"best-effort, single cursor" caveat for PR list mode.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant