Skip to content

ci: gate release publishers on tests - #259

Merged
umputun merged 2 commits into
masterfrom
release-pipeline
Aug 20, 2026
Merged

umputun merged 2 commits into
masterfrom
release-pipeline

Conversation

@umputun

@umputun umputun commented Aug 20, 2026

Copy link
Copy Markdown
Owner

v1.7.0 shipped a GitHub release with binaries but no Docker images, and this fixes the pipeline hole that allowed it.

what happened: the build workflow on the v1.7.0 tag failed on a flaky test (run 29384701124). docker.yml gates on workflow_run.conclusion == 'success', so it skipped. release.yml triggered straight off the tag push with no such gate, so goreleaser ran anyway. Result was a release with binaries, Homebrew and packages updated, and no image on Docker Hub or ghcr. latest still points at v1.6.0.

what changed:

  • test.yml - the build/test/lint/coverage job, now a workflow_call reusable. Content is unchanged
  • ci.yml - calls it for branches and PRs. No longer triggers on tags
  • docker-publish.yml - the two-arch build and manifest flow, now a reusable taking source_sha, image_tag, update_latest
  • docker.yml - master-only dispatcher calling the publisher
  • release.yml - native v* tag trigger, runs the test gate, then docker and goreleaser in parallel on needs: test

tags no longer travel through workflow_run at all, which closes two more holes:

  • a branch named v* used to pass startsWith(head_branch, 'v') in docker.yml, publishing a release-looking image and moving latest
  • a fork PR branch named master passed head_branch == 'master', so fork code could be built and pushed as umputun/reproxy:master with real credentials. docker.yml now also requires workflow_run.event == 'push' and head_repository.full_name == github.repository

image namespace comes from github.repository_owner instead of github.actor, and the reusables take registry secrets explicitly rather than secrets: inherit.

publication is still not atomic. Docker and goreleaser run in parallel, so a registry outage can still produce binaries without images. That is deliberate: putting goreleaser behind the registries would turn a registry outage into a total release outage. The difference is the release run now goes red instead of failing quietly.

no Go code touched. The reusable wiring can only be checked by real runs, so this PR exercises the ci.yml path, a master push exercises docker.yml, and a tag exercises release.yml.

a failed tag build could still publish binaries while container publication was skipped. Keep both tag publishers behind one native test gate and restrict the privileged master publisher to trusted pushes.
Copilot AI lite review requested due to automatic review settings August 20, 2026 02:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

'latest' let a linter release break the build: v2.13.0 flags four issues
in existing code that v2.12.2 passes. Those are fixed separately.
@umputun
umputun merged commit 35cbdf7 into master Aug 20, 2026
4 checks passed
@umputun
umputun deleted the release-pipeline branch August 20, 2026 02:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants