fix(release): publish to webgrip/unfold and fail fast on dead addresses #164
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/fix/release-publisher-unfold-identity"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
rc.34 (run 750) built and signed every image, including
de-vloer-agent(the #163 VEX statement worked), but Vloer - Verify and publish all destinations hung until its 30-minute timeout. Forgejo's log shows what happened:POST /api/v1/repos/webgrip/glide/releases/14726/assets→ 301 (repo renamed). Python's redirect handler replayed it as aGETof the asset list, sorelease-artifacts-vloer.jsonwas never attached and nothing failed.git ls-remote https://github.com/webgrip/glide.git: that GitHub repo is gone (404) since the history purge recreated it aswebgrip/unfold. Git waited on a credential prompt until the job was killed.POST .../packages/.../unlink→ 500 forde-vloer-agentandcharts/de-vloer:link_packagecompares againstwebgrip/glide, so it re-links packages that are already linked towebgrip/unfold.Ploeg's distribution would hit the same wall, and
release_preflight.pychecks the signing identity againstwebgrip/glide.Change
verify_image, workflowEXPECTED_SOURCE, OCIsource/urllabels (both apps' Dockerfiles and the index annotations) and charthome/sourcesnamewebgrip/unfold.SafeRedirectraises on a redirected non-GET/HEAD request instead of silently turning a write into a read (new test).publish_release.git()always setsGIT_TERMINAL_PROMPT=0, so an unreachable remote fails in seconds.Verification
mise run verify: all gates pass, including the 22 release distribution tests andrelease-check(39/0).webgrip/unfoldalready carriesunfold-v0.4.0-rc.33andrc.34at the Forgejo commits.After merge
rc.35 should publish end to end. rc.33 and rc.34 Vloer evidence and GitHub release drafts were never written; re-running
on_release_publishedfor them (workflow_dispatch with the tag) uses the tag's old scripts and would hang the same way, so let them be superseded.🤖 Generated with Claude Code