Repository navigation
ci: gate release publishers on tests - #259
Merged
Merged
Conversation
a failed tag build could still publish binaries while container publication was skipped. Keep both tag publishers behind one native test gate and restrict the privileged master publisher to trusted pushes.
'latest' let a linter release break the build: v2.13.0 flags four issues in existing code that v2.12.2 passes. Those are fixed separately.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
v1.7.0 shipped a GitHub release with binaries but no Docker images, and this fixes the pipeline hole that allowed it.
what happened: the build workflow on the v1.7.0 tag failed on a flaky test (run 29384701124).
docker.ymlgates onworkflow_run.conclusion == 'success', so it skipped.release.ymltriggered straight off the tag push with no such gate, so goreleaser ran anyway. Result was a release with binaries, Homebrew and packages updated, and no image on Docker Hub or ghcr.lateststill points at v1.6.0.what changed:
test.yml- the build/test/lint/coverage job, now aworkflow_callreusable. Content is unchangedci.yml- calls it for branches and PRs. No longer triggers on tagsdocker-publish.yml- the two-arch build and manifest flow, now a reusable takingsource_sha,image_tag,update_latestdocker.yml- master-only dispatcher calling the publisherrelease.yml- nativev*tag trigger, runs the test gate, then docker and goreleaser in parallel onneeds: testtags no longer travel through
workflow_runat all, which closes two more holes:v*used to passstartsWith(head_branch, 'v')indocker.yml, publishing a release-looking image and movinglatestmasterpassedhead_branch == 'master', so fork code could be built and pushed asumputun/reproxy:masterwith real credentials.docker.ymlnow also requiresworkflow_run.event == 'push'andhead_repository.full_name == github.repositoryimage namespace comes from
github.repository_ownerinstead ofgithub.actor, and the reusables take registry secrets explicitly rather thansecrets: inherit.publication is still not atomic. Docker and goreleaser run in parallel, so a registry outage can still produce binaries without images. That is deliberate: putting goreleaser behind the registries would turn a registry outage into a total release outage. The difference is the release run now goes red instead of failing quietly.
no Go code touched. The reusable wiring can only be checked by real runs, so this PR exercises the
ci.ymlpath, a master push exercisesdocker.yml, and a tag exercisesrelease.yml.