feat(github): publish the Helm chart to GHCR; skip immutable re-pushes #52

Merged
ryangr0 merged 2 commits from feat/ghcr-chart-and-immutable-skip into main 2026-08-25 10:11:51 +00:00
Owner

Closes the last two gaps in ploeg's release chain.

fix(helm): skip the push when the chart version is already published

Harbor tags are immutable, so re-publishing an existing version fails outright instead of no-opping. ploeg run 183:

PUT .../charts/ploeg/manifests/0.2.0-rc.23: 412 precondition:
  'charts/ploeg:0.2.0-rc.23' configured as immutable

This is the chart-side twin of the image probe already in ploeg's caller, and the last thing keeping a backfill from going fully green. helm show chart runs after the registry login (it needs the same credentials). Fail-open: anything but a clean hit falls through and pushes, exactly as a first publish does.

feat(github): publish the OCI Helm chart to GHCR

The GitHub track carried the repo, the release and the image, but not the chart — ghcr.io had no counterpart to Harbor's webgrip/charts/ploeg.

Built from source, not copied from Harbor, matching forgejo-distribute's publish-chart: helm package is deterministic from the tagged tree, and copying an OCI artifact by digest needs tooling the runner does not carry — imagetools understands image manifest lists, not Helm's config media type.

Lands at ghcr.io/<owner>/charts/<chart> by default, mirroring the Harbor layout and keeping charts out of the image namespace. Gated on chart-path being non-empty, so existing callers are unaffected, and independent of the ref and image jobs. Carries the same already-published probe.

Note on the reusable-collision constraint

The obvious alternative — a second helm-chart-push.yml call in ploeg with registry: ghcr.io — does not work. Forgejo v15 flattening collides two instances of the same reusable in one caller, which ploeg's own comments document. Putting the chart inside github-distribute.yml keeps it to one instance each.

helm-chart-push.yml is byte-identical between v1.0.0 and main, so ploeg bumping that pin picks up only this probe.

Closes the last two gaps in ploeg's release chain. ## `fix(helm)`: skip the push when the chart version is already published Harbor tags are immutable, so re-publishing an existing version fails outright instead of no-opping. ploeg run 183: ``` PUT .../charts/ploeg/manifests/0.2.0-rc.23: 412 precondition: 'charts/ploeg:0.2.0-rc.23' configured as immutable ``` This is the chart-side twin of the image probe already in ploeg's caller, and the last thing keeping a backfill from going fully green. `helm show chart` runs after the registry login (it needs the same credentials). Fail-open: anything but a clean hit falls through and pushes, exactly as a first publish does. ## `feat(github)`: publish the OCI Helm chart to GHCR The GitHub track carried the repo, the release and the image, but not the chart — ghcr.io had no counterpart to Harbor's `webgrip/charts/ploeg`. **Built from source, not copied from Harbor**, matching `forgejo-distribute`'s `publish-chart`: `helm package` is deterministic from the tagged tree, and copying an OCI artifact by digest needs tooling the runner does not carry — `imagetools` understands image manifest lists, not Helm's config media type. Lands at `ghcr.io/<owner>/charts/<chart>` by default, mirroring the Harbor layout and keeping charts out of the image namespace. Gated on `chart-path` being non-empty, so **existing callers are unaffected**, and independent of the ref and image jobs. Carries the same already-published probe. ### Note on the reusable-collision constraint The obvious alternative — a second `helm-chart-push.yml` call in ploeg with `registry: ghcr.io` — does not work. Forgejo v15 flattening collides two instances of the *same* reusable in one caller, which ploeg's own comments document. Putting the chart inside `github-distribute.yml` keeps it to one instance each. `helm-chart-push.yml` is byte-identical between `v1.0.0` and `main`, so ploeg bumping that pin picks up only this probe.
Harbor tags are immutable, so re-publishing a version that is already there
fails the job outright instead of no-opping. ploeg run 183 died with

    PUT .../charts/ploeg/manifests/0.2.0-rc.23: 412 precondition:
      'charts/ploeg:0.2.0-rc.23' configured as immutable

on a backfill of a release whose chart was published on the original run. This
is the chart-side twin of the image probe already landed in ploeg's caller, and
the last thing that kept a re-publish from going green.

`helm show chart` against the target runs after the registry login, since it
needs the same credentials. Fail-open: anything but a clean hit falls through
and pushes, which is exactly what every first publish already does.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
feat(github): publish the OCI Helm chart to GHCR
Some checks failed
docker-build-and-push-registry.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
docker-build-and-push.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
forgejo-distribute.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
github-distribute.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
github-issue-create-by-prompt.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
github-issues-create-by-prompt.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
helm-chart-deploy.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
helm-chart-push.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
helm-charts-deploy.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
helm-charts-push.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
laravel-quality.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
php-application-static-analysis.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
rust-semantic-release.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
semantic-release-monorepo.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
semantic-release.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
setup-repository-bootstrap.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
setup-repository-copilot-files.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
setup-repository-create-from-template.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
spa-preview.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
static-analysis.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
sync-template-files.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
techdocs-deploy-backstage-s3.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
techdocs-deploy-codeberg.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
techdocs-deploy-docs-site.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
techdocs-deploy-gh-pages.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
tests.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
update_mkdocs.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
update_techdocs.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
wordpress-plugin-release-distribute.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
wordpress-plugin-release.yml / Merge pull request 'feat(github): publish the Helm chart to GHCR; skip immutable re-pushes' (#52) from feat/ghcr-chart-and-immutable-skip into main (pull_request) Failing after 0s
ac958e9d43
The GitHub track carried the repo, the release and the image, but not the
chart — so ghcr.io had no counterpart to Harbor's webgrip/charts/ploeg.

Built from source rather than copied from Harbor, matching forgejo-distribute's
publish-chart: `helm package` is deterministic from the tagged tree, and
copying an OCI artifact by digest needs tooling the runner does not carry —
imagetools understands image manifest lists, not Helm's config media type.

Lands at ghcr.io/<owner>/charts/<chart> by default, mirroring the Harbor layout
and keeping charts out of the image namespace. The job is gated on chart-path
being non-empty, so existing callers are unaffected, and it is independent of
the ref and image jobs. The same already-published probe as the Harbor push
keeps it idempotent on a backfill.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
webgrip-ci referenced this pull request from a commit 2026-08-25 10:12:54 +00:00
Sign in to join this conversation.
No reviewers
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/workflows!52
No description provided.