feat(github): publish the Helm chart to GHCR; skip immutable re-pushes #52
No reviewers
Labels
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/workflows!52
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/ghcr-chart-and-immutable-skip"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes the last two gaps in ploeg's release chain.
fix(helm): skip the push when the chart version is already publishedHarbor tags are immutable, so re-publishing an existing version fails outright instead of no-opping. ploeg run 183:
This is the chart-side twin of the image probe already in ploeg's caller, and the last thing keeping a backfill from going fully green.
helm show chartruns after the registry login (it needs the same credentials). Fail-open: anything but a clean hit falls through and pushes, exactly as a first publish does.feat(github): publish the OCI Helm chart to GHCRThe GitHub track carried the repo, the release and the image, but not the chart — ghcr.io had no counterpart to Harbor's
webgrip/charts/ploeg.Built from source, not copied from Harbor, matching
forgejo-distribute'spublish-chart:helm packageis deterministic from the tagged tree, and copying an OCI artifact by digest needs tooling the runner does not carry —imagetoolsunderstands image manifest lists, not Helm's config media type.Lands at
ghcr.io/<owner>/charts/<chart>by default, mirroring the Harbor layout and keeping charts out of the image namespace. Gated onchart-pathbeing non-empty, so existing callers are unaffected, and independent of the ref and image jobs. Carries the same already-published probe.Note on the reusable-collision constraint
The obvious alternative — a second
helm-chart-push.ymlcall in ploeg withregistry: ghcr.io— does not work. Forgejo v15 flattening collides two instances of the same reusable in one caller, which ploeg's own comments document. Putting the chart insidegithub-distribute.ymlkeeps it to one instance each.helm-chart-push.ymlis byte-identical betweenv1.0.0andmain, so ploeg bumping that pin picks up only this probe.Harbor tags are immutable, so re-publishing a version that is already there fails the job outright instead of no-opping. ploeg run 183 died with PUT .../charts/ploeg/manifests/0.2.0-rc.23: 412 precondition: 'charts/ploeg:0.2.0-rc.23' configured as immutable on a backfill of a release whose chart was published on the original run. This is the chart-side twin of the image probe already landed in ploeg's caller, and the last thing that kept a re-publish from going green. `helm show chart` against the target runs after the registry login, since it needs the same credentials. Fail-open: anything but a clean hit falls through and pushes, which is exactly what every first publish already does. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>