fix(release): publish to the renamed unfold repositories without hanging #165

Merged
ryangr0 merged 1 commit from ryangr0/release-publish-unfold-repo into development 2026-10-03 12:14:04 +00:00 AGit
Owner

Why

Run 750 (rc.34) failed: Vloer - Verify and publish all destinations sat silent for 29 minutes and was killed at its 30-minute timeout. It was the first Vloer publish since the repository rename, and the publisher still addressed webgrip/glide:

  1. attach_forgejo POSTed the evidence file to /api/v1/repos/webgrip/glide/.... Forgejo answers 301, and urllib replays a redirected POST as a bodiless GET. The upload "succeeded" and nothing was attached; release-artifacts-vloer.json is missing from the rc.34 release.
  2. mirror_release ran git ls-remote https://github.com/webgrip/glide.git. That repository no longer exists (the mirror is webgrip/unfold), so GitHub asked for credentials and git waited on a prompt until the timeout.

The Harbor, Forgejo and GHCR copies and the Open VSX check had all finished before the hang.

What

  • Point the publisher, the preview preflight (mirror URL, OIDC repository claim), the image source/url labels and annotations, their verifier and both charts' home/sources at webgrip/unfold. OpenBao's cosign-signer role already binds webgrip/unfold.
  • SafeRedirect refuses to follow a redirect on a write: it now fails with the status code.
  • command() runs every subprocess with GIT_TERMINAL_PROMPT=0, a closed stdin and a 600-second limit, so a credential prompt or a stuck tool fails the job with a message.
  • docs/operations/artifacts.md links the current repositories.

Verification

  • mise run verify: all gates passed. mise run docs-check: passed.
  • New tests: a redirected POST raises; a command sees GIT_TERMINAL_PROMPT=0, gets EOF on stdin and times out.

After merge

The publisher checks out the release tag, so re-running run 750 would hang again. This PR changes apps/, so merging it cuts rc.35, which publishes with the fixed script. rc.34 stays partially published: Harbor, Forgejo, GHCR (Vloer) and Open VSX are done; the GitHub release, Ploeg's GHCR copy and the Go module tag are not.

🤖 Generated with Claude Code

## Why [Run 750](https://forgejo.webgrip.dev/webgrip/unfold/actions/runs/750/jobs/8/attempt/1) (rc.34) failed: **Vloer - Verify and publish all destinations** sat silent for 29 minutes and was killed at its 30-minute timeout. It was the first Vloer publish since the repository rename, and the publisher still addressed `webgrip/glide`: 1. `attach_forgejo` POSTed the evidence file to `/api/v1/repos/webgrip/glide/...`. Forgejo answers **301**, and urllib replays a redirected POST as a bodiless GET. The upload "succeeded" and nothing was attached; `release-artifacts-vloer.json` is missing from the rc.34 release. 2. `mirror_release` ran `git ls-remote https://github.com/webgrip/glide.git`. That repository no longer exists (the mirror is `webgrip/unfold`), so GitHub asked for credentials and git waited on a prompt until the timeout. The Harbor, Forgejo and GHCR copies and the Open VSX check had all finished before the hang. ## What - Point the publisher, the preview preflight (mirror URL, OIDC `repository` claim), the image `source`/`url` labels and annotations, their verifier and both charts' `home`/`sources` at `webgrip/unfold`. OpenBao's `cosign-signer` role already binds `webgrip/unfold`. - `SafeRedirect` refuses to follow a redirect on a write: it now fails with the status code. - `command()` runs every subprocess with `GIT_TERMINAL_PROMPT=0`, a closed stdin and a 600-second limit, so a credential prompt or a stuck tool fails the job with a message. - `docs/operations/artifacts.md` links the current repositories. ## Verification - `mise run verify`: all gates passed. `mise run docs-check`: passed. - New tests: a redirected POST raises; a command sees `GIT_TERMINAL_PROMPT=0`, gets EOF on stdin and times out. ## After merge The publisher checks out the release tag, so re-running run 750 would hang again. This PR changes `apps/`, so merging it cuts rc.35, which publishes with the fixed script. rc.34 stays partially published: Harbor, Forgejo, GHCR (Vloer) and Open VSX are done; the GitHub release, Ploeg's GHCR copy and the Go module tag are not. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
fix(release): publish to the renamed unfold repositories without hanging
Some checks failed
[Workflow] On Pull Request / checks (pull_request) Successful in 5m7s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 20s
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
915a354cf4
Run 750 (rc.34) timed out after 30 minutes in "Vloer - Verify and publish
all destinations". The publisher still addressed webgrip/glide:

- The evidence upload POSTed to the old Forgejo API path. Forgejo answered
  301 and urllib replayed it as a bodiless GET, so the upload "succeeded"
  without attaching anything.
- The GitHub mirror check ran git ls-remote against github.com/webgrip/glide,
  which no longer exists. GitHub asked for credentials and git waited on a
  prompt until the job timed out.

Point the publisher, the preview preflight, the image source labels and
annotations, their verifier and the chart metadata at webgrip/unfold. A
redirected write now fails with its status instead of becoming a read, and
every subprocess runs with GIT_TERMINAL_PROMPT=0, a closed stdin and a
600-second limit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ryangr0 force-pushed ryangr0/release-publish-unfold-repo from 915a354cf4
Some checks failed
[Workflow] On Pull Request / checks (pull_request) Successful in 5m7s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 20s
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
to 25374d8b92
All checks were successful
[Workflow] On Pull Request / release-policy (pull_request) Successful in 1m45s
[Workflow] On Pull Request / checks (pull_request) Successful in 8m37s
[Workflow] On Pull Request / warnings (pull_request) Successful in 1s
2026-10-03 12:13:25 +00:00
Compare
ryangr0 merged commit e845695832 into development 2026-10-03 12:14:04 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!165
No description provided.