ci(release): run the release in the toolchain image #33

Merged
ryangr0 merged 1 commit from ci/semrel-toolchain-image into development 2026-07-30 20:30:06 +00:00
Owner

ploeg is the trial for webgrip/workflows ADR-0005: the release toolchain becomes
an image instead of an install. Run 122 is the before picture — 413 packages in
2m, 15 more in 21s, an npm audit summary nobody reads, and a yq download, all to
spend ~25s cutting v0.2.0-rc.9. None of it locked, so that release and the next
one were not guaranteed to run the same plugin versions.

harbor.webgrip.dev/webgrip/semantic-release:0.1.2 carries node, git, yq,
semantic-release 25 and @webgrip/semantic-release-config from a committed
lockfile, and exports SEMREL_PREBAKED — which is all the composite needs to skip
installing entirely. Built in webgrip/infrastructure.

Two deliberate limits on this commit:

The container is on the release job ONLY. checks needs go and helm, which this
image does not carry, and gluing them in would make the release toolchain a
build farm — the thing rust-releaser already is and this family exists not to be.

The composite is pinned to a COMMIT on the semrel branch, not @main and not the
branch name. @main still installs at release time and would ignore the image;
pinning the branch would let a later push change what this release runs. Flip it
back to @main once that PR merges — this pin is not meant to outlive the trial.

This is the first time the container path runs anywhere. If the image is missing
something ploeg's config reaches for, this is where it surfaces: the config is
makeConfig({manifest:'helm'}) with the dependency-free Chart.yaml bump, which
needs nothing outside the image, so the honest expectation is a clean release
with no npm output at all.

Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com

ploeg is the trial for webgrip/workflows ADR-0005: the release toolchain becomes an image instead of an install. Run 122 is the before picture — 413 packages in 2m, 15 more in 21s, an npm audit summary nobody reads, and a yq download, all to spend ~25s cutting v0.2.0-rc.9. None of it locked, so that release and the next one were not guaranteed to run the same plugin versions. harbor.webgrip.dev/webgrip/semantic-release:0.1.2 carries node, git, yq, semantic-release 25 and @webgrip/semantic-release-config from a committed lockfile, and exports SEMREL_PREBAKED — which is all the composite needs to skip installing entirely. Built in webgrip/infrastructure. Two deliberate limits on this commit: The container is on the release job ONLY. `checks` needs go and helm, which this image does not carry, and gluing them in would make the release toolchain a build farm — the thing rust-releaser already is and this family exists not to be. The composite is pinned to a COMMIT on the semrel branch, not @main and not the branch name. @main still installs at release time and would ignore the image; pinning the branch would let a later push change what this release runs. Flip it back to @main once that PR merges — this pin is not meant to outlive the trial. This is the first time the container path runs anywhere. If the image is missing something ploeg's config reaches for, this is where it surfaces: the config is makeConfig({manifest:'helm'}) with the dependency-free Chart.yaml bump, which needs nothing outside the image, so the honest expectation is a clean release with no npm output at all. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
ci(release): run the release in the toolchain image
Some checks failed
On Pull Request / checks (pull_request) Failing after 4m36s
dbf4414b8c
ploeg is the trial for webgrip/workflows ADR-0005: the release toolchain becomes
an image instead of an install. Run 122 is the before picture — 413 packages in
2m, 15 more in 21s, an npm audit summary nobody reads, and a yq download, all to
spend ~25s cutting v0.2.0-rc.9. None of it locked, so that release and the next
one were not guaranteed to run the same plugin versions.

harbor.webgrip.dev/webgrip/semantic-release:0.1.2 carries node, git, yq,
semantic-release 25 and @webgrip/semantic-release-config from a committed
lockfile, and exports SEMREL_PREBAKED — which is all the composite needs to skip
installing entirely. Built in webgrip/infrastructure.

Two deliberate limits on this commit:

The container is on the release job ONLY. `checks` needs go and helm, which this
image does not carry, and gluing them in would make the release toolchain a
build farm — the thing rust-releaser already is and this family exists not to be.

The composite is pinned to a COMMIT on the semrel branch, not @main and not the
branch name. @main still installs at release time and would ignore the image;
pinning the branch would let a later push change what this release runs. Flip it
back to @main once that PR merges — this pin is not meant to outlive the trial.

This is the first time the container path runs anywhere. If the image is missing
something ploeg's config reaches for, this is where it surfaces: the config is
makeConfig({manifest:'helm'}) with the dependency-free Chart.yaml bump, which
needs nothing outside the image, so the honest expectation is a clean release
with no npm output at all.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
ryangr0 merged commit c78d2e9322 into development 2026-07-30 20:30:06 +00:00
Commenting is not possible because the repository is archived.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/ploeg!33
No description provided.