fix(release): publish to webgrip/unfold and fail fast on dead addresses #164

Merged
ryangr0 merged 1 commit from ryangr0/fix/release-publisher-unfold-identity into development 2026-10-03 11:53:39 +00:00 AGit
Owner

Why

rc.34 (run 750) built and signed every image, including de-vloer-agent (the #163 VEX statement worked), but Vloer - Verify and publish all destinations hung until its 30-minute timeout. Forgejo's log shows what happened:

  • POST /api/v1/repos/webgrip/glide/releases/14726/assets → 301 (repo renamed). Python's redirect handler replayed it as a GET of the asset list, so release-artifacts-vloer.json was never attached and nothing failed.
  • git ls-remote https://github.com/webgrip/glide.git: that GitHub repo is gone (404) since the history purge recreated it as webgrip/unfold. Git waited on a credential prompt until the job was killed.
  • POST .../packages/.../unlink → 500 for de-vloer-agent and charts/de-vloer: link_package compares against webgrip/glide, so it re-links packages that are already linked to webgrip/unfold.

Ploeg's distribution would hit the same wall, and release_preflight.py checks the signing identity against webgrip/glide.

Change

  • Release scripts, preflight, verify_image, workflow EXPECTED_SOURCE, OCI source/url labels (both apps' Dockerfiles and the index annotations) and chart home/sources name webgrip/unfold.
  • SafeRedirect raises on a redirected non-GET/HEAD request instead of silently turning a write into a read (new test).
  • publish_release.git() always sets GIT_TERMINAL_PROMPT=0, so an unreachable remote fails in seconds.
  • ADR-0013: the repository and its mirror are no longer pending external names.

Verification

  • mise run verify: all gates pass, including the 22 release distribution tests and release-check (39/0).
  • Not provable before a release: the next tag's distribute jobs. GitHub webgrip/unfold already carries unfold-v0.4.0-rc.33 and rc.34 at the Forgejo commits.

After merge

rc.35 should publish end to end. rc.33 and rc.34 Vloer evidence and GitHub release drafts were never written; re-running on_release_published for them (workflow_dispatch with the tag) uses the tag's old scripts and would hang the same way, so let them be superseded.

🤖 Generated with Claude Code

## Why rc.34 (run 750) built and signed every image, including `de-vloer-agent` (the #163 VEX statement worked), but **Vloer - Verify and publish all destinations** hung until its 30-minute timeout. Forgejo's log shows what happened: - `POST /api/v1/repos/webgrip/glide/releases/14726/assets` → **301** (repo renamed). Python's redirect handler replayed it as a `GET` of the asset list, so `release-artifacts-vloer.json` was never attached and nothing failed. - `git ls-remote https://github.com/webgrip/glide.git`: that GitHub repo is gone (404) since the history purge recreated it as `webgrip/unfold`. Git waited on a credential prompt until the job was killed. - `POST .../packages/.../unlink` → **500** for `de-vloer-agent` and `charts/de-vloer`: `link_package` compares against `webgrip/glide`, so it re-links packages that are already linked to `webgrip/unfold`. Ploeg's distribution would hit the same wall, and `release_preflight.py` checks the signing identity against `webgrip/glide`. ## Change - Release scripts, preflight, `verify_image`, workflow `EXPECTED_SOURCE`, OCI `source`/`url` labels (both apps' Dockerfiles and the index annotations) and chart `home`/`sources` name `webgrip/unfold`. - `SafeRedirect` raises on a redirected non-GET/HEAD request instead of silently turning a write into a read (new test). - `publish_release.git()` always sets `GIT_TERMINAL_PROMPT=0`, so an unreachable remote fails in seconds. - ADR-0013: the repository and its mirror are no longer pending external names. ## Verification - `mise run verify`: all gates pass, including the 22 release distribution tests and `release-check` (39/0). - Not provable before a release: the next tag's distribute jobs. GitHub `webgrip/unfold` already carries `unfold-v0.4.0-rc.33` and `rc.34` at the Forgejo commits. ## After merge rc.35 should publish end to end. rc.33 and rc.34 Vloer evidence and GitHub release drafts were never written; re-running `on_release_published` for them (workflow_dispatch with the tag) uses the tag's old scripts and would hang the same way, so let them be superseded. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
fix(release): publish to webgrip/unfold and fail fast on dead addresses
Some checks failed
[Workflow] On Pull Request / release-policy (pull_request) Successful in 25s
[Workflow] On Pull Request / checks (pull_request) Successful in 6m37s
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
4637099afb
rc.34's Vloer distribution hung for its 30-minute timeout. The publisher
still named webgrip/glide: its evidence POST was answered 301 by the
renamed Forgejo repository and urllib replayed it as a GET, so nothing
was attached, and git ls-remote against the deleted GitHub webgrip/glide
waited on a credential prompt. Package linking also unlinked packages
already linked to webgrip/unfold and got HTTP 500.

The release scripts, preflight, image source labels and chart metadata
now name webgrip/unfold. A redirected write raises instead of turning
into a read, and the publisher's git never prompts.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ryangr0 merged commit 60df87a74b into development 2026-10-03 11:53:39 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!164
No description provided.