Skip to content

Merge master back into testing after 20260917-001 GA - #172

Merged
jsokol merged 8 commits into
testingfrom
MERGE-master-into-testing
Sep 29, 2026
Merged

jsokol merged 8 commits into
testingfrom
MERGE-master-into-testing

Conversation

@jsokol

@jsokol jsokol commented Sep 29, 2026

Copy link
Copy Markdown
Member

Description

Merge master back into testing after the 20260917-001 GA promotion (#171).

master is 8 commits ahead of testing and 0 behind. The only file difference is .github/workflows/promote-latest.yml, changed directly on master by #166 (fire promote-latest on the GA merge). The other commits are merge commits from earlier release promotions (#164, #167, #168, #171) with no file differences.

Why

testing never received promote-latest.yml, so every release-<version> branch cut from it is BEHIND master. The Protect master ruleset requires an up-to-date branch, so auto-merge of the release PR cannot land it. #171 needed an admin-bypass merge for exactly this reason. Merging master back stops it recurring.

Testing Results

No code change beyond promote-latest.yml, which is unchanged from what already runs on master. No new tests apply.

🤖 Generated with Claude Code

https://claude.ai/code/session_01RWsGdgn3khwahjF4C96HM9

jsokol and others added 8 commits August 21, 2026 15:50
Publishing the release images was the one manual step in the release, and
nothing failed if it was skipped -- :latest simply stayed on the previous
release while every monitored stage reported green.

Fire on a master push instead, path-filtered to simplerisk-minimal/Dockerfile
(the file carrying the `ENV version=` this job promotes). workflow_dispatch
stays for heals.

Auto-firing is safe precisely BECAUSE nothing is rebuilt. The 20260820-001
failure came from rebuilding on a master push and racing the GA bundle upload;
a retag touches no bundle. The deliberate release gate moves to where the
release decision is actually made -- the code-development testing -> master
merge, restricted to release owners -- rather than a second dispatch nobody is
prompted to run. This reverses the "manual workflow_dispatch" line in the
2026-07-10 design on purpose.

Adds an idempotence guard so the automatic path is safe to re-enter: if
:latest already resolves to the digest we would promote for every image, all
five mutating steps skip. A dispatch always runs in full.

The guard fails loudly when the minimal RC tag is ABSENT rather than treating
it as "nothing to do" -- that condition means the release has no images to
promote, which must not surface as a green no-op run.

Guard logic exercised offline across 8 scenarios (already-promoted, new
release, each image differing alone, minimal RC missing, full RC missing,
both skip_full paths): correct verdict and exit status in every case, no
set -e traps in the && chains.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Merge testing into master to reset the merge base
Fire the GA promote on the master merge instead of a manual dispatch
@jsokol
jsokol merged commit 376de6f into testing Sep 29, 2026
9 checks passed
@jsokol
jsokol deleted the MERGE-master-into-testing branch September 29, 2026 16:03

This branch was successfully deployed

1 active deployment
release — 39d5e9be Deployed Sep 29, 2026 by jsokol via promote #7
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant