fix: soft-delete stale workspace agents on new build (#25207)

This commit is contained in:
Garrett Delfosse
2026-05-18 08:33:29 -04:00
committed by GitHub
parent 159089686a
commit 78d4cf9e47
16 changed files with 723 additions and 3 deletions
+9
View File
@@ -615,6 +615,15 @@ func (b *Builder) buildTx(authFunc func(action policy.Action, object rbac.Object
}); err != nil {
return BuildError{http.StatusInternalServerError, "mark workspace as deleted", err}
}
// Soft-delete any agents tied to this workspace so the
// aws-instance-identity handler doesn't keep seeing
// orphaned rows. Mirrors the path in
// provisionerdserver.CompleteJob. See #25155.
//nolint:gocritic // System-restricted: bookkeeping inside an already-authorized delete transaction.
if err := store.SoftDeleteWorkspaceAgentsByWorkspaceID(dbauthz.AsSystemRestricted(b.ctx), b.workspace.ID); err != nil {
return BuildError{http.StatusInternalServerError, "soft-delete workspace agents on orphan delete", err}
}
}
return nil
+6 -1
View File
@@ -1513,7 +1513,9 @@ func expectUpdateProvisionerJobWithCompleteWithStartedAtByID(assertions func(par
}
// expectUpdateWorkspaceDeletedByID asserts a call to UpdateWorkspaceDeletedByID
// and runs the provided assertions against it.
// and runs the provided assertions against it. It also expects the follow-up
// SoftDeleteWorkspaceAgentsByWorkspaceID call that wsbuilder.Builder.Build now
// issues inside the same orphan-delete transaction.
func expectUpdateWorkspaceDeletedByID(assertions func(params database.UpdateWorkspaceDeletedByIDParams)) func(mTx *dbmock.MockStore) {
return func(mTx *dbmock.MockStore) {
mTx.EXPECT().UpdateWorkspaceDeletedByID(gomock.Any(), gomock.Any()).
@@ -1524,6 +1526,9 @@ func expectUpdateWorkspaceDeletedByID(assertions func(params database.UpdateWork
return nil
},
)
mTx.EXPECT().SoftDeleteWorkspaceAgentsByWorkspaceID(gomock.Any(), gomock.Any()).
Times(1).
Return(nil)
}
}