@@ -126,8 +126,11 @@ jobs:
126126 # stays manual. See ChainSafe/infrastructure-general#1353.
127127 if : needs.build-push.outputs.deploy_devnet == 'true'
128128 env :
129- DIR : definitions/canton/validator-dev1
130- FILE : canton-dapp-ui-values.yml
129+ # app-chart values file, read by ArgoCD. The legacy definitions/ block is
130+ # enabled: false and renders nothing.
131+ DIR : clusters/dev/apps/canton/canton-dapp-ui
132+ FILE : values.yaml
133+ IMAGE_REPO : ghcr.io/chainsafe/canton-dapp
131134 steps :
132135 - name : Checkout infra-kubernetes
133136 uses : actions/checkout@v4
@@ -140,7 +143,17 @@ jobs:
140143 env :
141144 VERSION : ${{ needs.build-push.outputs.version }}
142145 run : |
143- yq e '.["canton-dapp-ui"].image.tag = strenv(VERSION)' -i "${DIR}/${FILE}"
146+ set -euo pipefail
147+ yq e '.deployments["canton-dapp-ui"].spec.template.spec.containers[0].image = strenv(IMAGE_REPO) + ":" + strenv(VERSION)' -i "${DIR}/${FILE}"
148+
149+ # yq strips blank lines before top-level keys. Fail rather than commit a
150+ # reformat the infra repo's linters would not catch.
151+ CHANGED=$(git diff --numstat -- "${DIR}/${FILE}" | awk '{print $1"/"$2}')
152+ if [ "${CHANGED}" != "1/1" ]; then
153+ echo "::error::expected exactly one line changed in ${DIR}/${FILE}, got ${CHANGED:-nothing}"
154+ git diff -- "${DIR}/${FILE}"
155+ exit 1
156+ fi
144157
145158 - name : Create signed commit and open PR
146159 env :
@@ -181,10 +194,11 @@ jobs:
181194 # Commit the bump unless the branch already has it (idempotent
182195 # re-run). Everything after this block always runs, so a re-run
183196 # repairs a missing PR instead of exiting early.
184- BRANCH_TAG =$(gh api "repos/${REPO}/contents/${DIR}/${FILE}?ref=${BRANCH}" \
197+ BRANCH_IMAGE =$(gh api "repos/${REPO}/contents/${DIR}/${FILE}?ref=${BRANCH}" \
185198 -H "Accept: application/vnd.github.raw" 2>/dev/null \
186- | yq e '.["canton-dapp-ui"].image.tag' - 2>/dev/null || echo "")
187- if [ "$BRANCH_TAG" = "$VERSION" ]; then
199+ | yq e '.deployments["canton-dapp-ui"].spec.template.spec.containers[0].image' - \
200+ 2>/dev/null || echo "")
201+ if [ "$BRANCH_IMAGE" = "${IMAGE_REPO}:${VERSION}" ]; then
188202 echo "Branch already at tag ${VERSION}, skipping commit"
189203 else
190204 # Commits via createCommitOnBranch are automatically signed by
0 commit comments