Skip to content

ci: tag-driven, gated release workflow (modeled on hardbyte/awa) - #351

Merged
hardbyte merged 2 commits into
mainfrom
claude/pr-346-merge-review-4e573g
Sep 4, 2026
Merged

hardbyte merged 2 commits into
mainfrom
claude/pr-346-merge-review-4e573g

Conversation

@hardbyte

@hardbyte hardbyte commented Sep 2, 2026 •

Copy link
Copy Markdown
Owner

Ports the release process from hardbyte/awa to netchecks: the tag is the trigger, and nothing publishes until the tag matches every version manifest and CI has passed on that exact commit.

What changes

New .github/workflows/release.yaml — runs on v* tag push:

Job Purpose
version-check check_versions.py --expect $TAG: tag must equal pyproject.toml, operator/Cargo.toml and the chart appVersion (real TOML/YAML parse, not grep)
candidate-ci requires ≥1 successful push-triggered ci.yaml run on this exact SHA — i.e. unit + kind integration tests passed on main for the commit being released
probe-image / operator-image + -merge multi-arch images pushed with X.Y.Z, X.Y, latest, sha-… tags; keyless cosign signatures and build-provenance attestations (actions/attest, pushed to the registry) — same as awa
python-dist → publish-pypi uv build → PyPI (still via PYPI_API_TOKEN; switching to trusted publishing is a one-line change once the publisher is registered on PyPI — the job already has id-token: write)
helm-chart chart-releaser, moved here from the standalone workflow so it also sits behind the gates
github-release last job: if a draft release exists for the tag, its notes are kept, the sdist + wheel are attached and it is published; otherwise a release is generated from the matching ## X.Y.Z section of CHANGELOG.md (falling back to generated notes; --prerelease for alpha/beta/rc). Either way the GitHub release only becomes public after every other job has succeeded.

ci.yaml drops its release: and tag triggers, the PyPI job and the semver image tags — it now only builds/tests PRs and main. helm-chart-release.yaml is deleted (folded into release.yaml). AGENTS.md documents the new process; CHANGELOG.md gains an ## [Unreleased] section, as in awa.

The one rule: push the tag, never publish a draft to create it

Publishing a draft release makes it public before the tag-triggered workflow can run, so a failed gate would leave an announced release with no package/images/chart behind it (thanks Codex). The supported path is:

git tag v0.11.0 <merge commit on main> && git push origin v0.11.0

A hand-written release may exist beforehand as a draft; the workflow publishes it as its final step.

Effect on the pending v0.11.0 draft

Leave the draft as it is. After this PR merges and the push-CI run on the new main tip is green, push the v0.11.0 tag at that tip; the workflow will run the gates, publish PyPI/images/chart, attach the Python distribution to your draft (keeping your notes) and publish it.

Not carried over from awa (by design)

  • No cross-compiled CLI binaries / maturin wheels — netchecks ships a pure-Python package; uv build covers it.
  • No N-1 upgrade-rehearsal gate — the closest equivalent here is the kind integration suite, which candidate-ci already requires to have passed on the exact commit. A rehearsal gate for chart upgrades (≤0.3.x → 0.5.0 CRD adoption) would be a good follow-up.

Verification

actionlint clean on both workflows; check_versions.py with/without --expect behaves (matching tag passes, mismatching tag fails with a clear message); the CHANGELOG-section extraction was tested against the 0.11.0 entry; ruff and typos clean. The workflow itself can only be exercised by a real tag.

https://claude.ai/code/session_01U71MHip9jr1QHckFbBL4Sp

Publishing moves out of ci.yaml (which now only builds and tests PRs and
main) and the standalone chart-release workflow into release.yaml, triggered
by pushing a v* tag - including the tag GitHub creates when a draft release
is published. Nothing publishes until two gates pass:

  version-check  the tag equals the version in pyproject.toml, Cargo.toml and
                 the chart appVersion (check_versions.py gained --expect)
  candidate-ci   a successful push-triggered CI run exists for this exact SHA

then: multi-arch probe and operator images pushed with X.Y.Z / X.Y / latest
tags, keyless cosign signatures and build-provenance attestations; sdist and
wheel published to PyPI; Helm chart released via chart-releaser; and the
GitHub release created from the matching CHANGELOG.md section (kept as-is if
a draft already exists) with the Python distribution attached, then published.

CHANGELOG.md gains an [Unreleased] section and AGENTS.md documents the new
process.

Claude-Session: https://claude.ai/code/session_01U71MHip9jr1QHckFbBL4Sp
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-02T11:57:20.163405Z 3b54eda PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Deploying netchecks-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: e7ffb33
Status: ✅  Deploy successful!
Preview URL: https://0fbaa6cd.netchecks-docs.pages.dev
Branch Preview URL: https://claude-pr-346-merge-review-4.netchecks-docs.pages.dev

View logs

@coveralls

coveralls commented Sep 2, 2026 •

Copy link
Copy Markdown

Coverage Report for CI Build 33627357435

Coverage remained the same at 87.167%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 639
Covered Lines: 557
Line Coverage: 87.17%
Coverage Strength: 5.23 hits per line

💛 - Coveralls

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3b54edaf15

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/release.yaml Outdated
Review finding: publishing a draft release to create the tag makes the
release public before the gates run, so a failed gate would leave an
announced release with no artifacts. The workflow already publishes an
existing draft only after every job succeeds; document that as the only
supported path and drop the 'publish the draft' alternative.

Claude-Session: https://claude.ai/code/session_01U71MHip9jr1QHckFbBL4Sp
@hardbyte
hardbyte merged commit 1de41b9 into main Sep 4, 2026
22 checks passed
@hardbyte
hardbyte deleted the claude/pr-346-merge-review-4e573g branch September 4, 2026 08:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants