Pin prod config-repo installs to the deployed platform commit
Status summary: Closes the gap that broke the iterate project's config builds for ~5h on 2026-09-02: previews sha-pin every iterate/iterate pkg.pr.new spec (APP_CONFIG_ITERATE_REPO_PKG_REF, set from the PR head sha), but prod installs literal @main — a mutable URL the dynamic worker host caches, so freshly-merged package exports weren't resolvable ("the installed 'iterate' package does not provide this entry") and every config commit silently failed to build while the stale worker kept serving.
Change#
deploy-os.ymlexportsPLATFORM_DEPLOY_HEAD_SHA="$(git rev-parse HEAD)"on prd deploys (workspace HEAD, not github.sha — dispatch honors inputs.ref).apps/os/scripts/deploy.tssetsAPP_CONFIG_ITERATE_REPO_PKG_REFfromPREVIEW_PULL_REQUEST_HEAD_SHA(unchanged) or, failing that,PLATFORM_DEPLOY_HEAD_SHA— and awaits the sha-pinned pkg.pr.new URLs the same way preview deploys already do, closing the deploy-races-publish window.- Dev/local deploys stay unpinned (no sha build exists for uncommitted state).
Effects: prod dynamic builds install iterate@<deployed-sha> (immutable URL — the stale-cache failure class is structurally gone), and config workers move in lockstep with platform deploys: the pinned ref rides the dynamic-build key, so each prd deploy lazily invalidates config-worker builds on next touch.
Checklist#
- deploy.ts: ref fallback + URL await for the prd sha (PLATFORM_DEPLOY_HEAD_SHA fallback; the existing await block keys off the ref regardless of source; preview-named helpers renamed to pinned*)
- deploy-os.yml: pass the sha (rev-parsed from the workspace, not github.sha — dispatch honors inputs.ref)
- Tests (depot-workflows guard pins the workflow export; deploy.test.ts passes with the renames)
Post-merge#
- After the next prd deploy, re-mount the flake dashboard in the live iterate config (reverted during the incident) and verify via
worker-updated(NOT just absence of failure — checkworker-update-failedtoo)