ci(release): run the release in the toolchain image #33
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ci/semrel-toolchain-image"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
ploeg is the trial for webgrip/workflows ADR-0005: the release toolchain becomes
an image instead of an install. Run 122 is the before picture — 413 packages in
2m, 15 more in 21s, an npm audit summary nobody reads, and a yq download, all to
spend ~25s cutting v0.2.0-rc.9. None of it locked, so that release and the next
one were not guaranteed to run the same plugin versions.
harbor.webgrip.dev/webgrip/semantic-release:0.1.2 carries node, git, yq,
semantic-release 25 and @webgrip/semantic-release-config from a committed
lockfile, and exports SEMREL_PREBAKED — which is all the composite needs to skip
installing entirely. Built in webgrip/infrastructure.
Two deliberate limits on this commit:
The container is on the release job ONLY.
checksneeds go and helm, which thisimage does not carry, and gluing them in would make the release toolchain a
build farm — the thing rust-releaser already is and this family exists not to be.
The composite is pinned to a COMMIT on the semrel branch, not @main and not the
branch name. @main still installs at release time and would ignore the image;
pinning the branch would let a later push change what this release runs. Flip it
back to @main once that PR merges — this pin is not meant to outlive the trial.
This is the first time the container path runs anywhere. If the image is missing
something ploeg's config reaches for, this is where it surfaces: the config is
makeConfig({manifest:'helm'}) with the dependency-free Chart.yaml bump, which
needs nothing outside the image, so the honest expectation is a clean release
with no npm output at all.
Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com
ploeg is the trial for webgrip/workflows ADR-0005: the release toolchain becomes an image instead of an install. Run 122 is the before picture — 413 packages in 2m, 15 more in 21s, an npm audit summary nobody reads, and a yq download, all to spend ~25s cutting v0.2.0-rc.9. None of it locked, so that release and the next one were not guaranteed to run the same plugin versions. harbor.webgrip.dev/webgrip/semantic-release:0.1.2 carries node, git, yq, semantic-release 25 and @webgrip/semantic-release-config from a committed lockfile, and exports SEMREL_PREBAKED — which is all the composite needs to skip installing entirely. Built in webgrip/infrastructure. Two deliberate limits on this commit: The container is on the release job ONLY. `checks` needs go and helm, which this image does not carry, and gluing them in would make the release toolchain a build farm — the thing rust-releaser already is and this family exists not to be. The composite is pinned to a COMMIT on the semrel branch, not @main and not the branch name. @main still installs at release time and would ignore the image; pinning the branch would let a later push change what this release runs. Flip it back to @main once that PR merges — this pin is not meant to outlive the trial. This is the first time the container path runs anywhere. If the image is missing something ploeg's config reaches for, this is where it surfaces: the config is makeConfig({manifest:'helm'}) with the dependency-free Chart.yaml bump, which needs nothing outside the image, so the honest expectation is a clean release with no npm output at all. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>