Skip to content

ci(release): archive both binaries to Artifact Registry from on-release; drop the legacy release workflows - #214

Merged
Troublor merged 3 commits into
mainfrom
troublor/ci/ar-archive
Sep 9, 2026
Merged

Troublor merged 3 commits into
mainfrom
troublor/ci/ar-archive

Conversation

@Troublor

@Troublor Troublor commented Sep 9, 2026

Copy link
Copy Markdown
Collaborator

Retires the legacy release pipeline. The Artifact Registry archive of both binaries moves into on-release.yml, next to the Release-page assets, and release.yaml / release-tracing.yaml are deleted.

Shape

  • build builds both binaries, verifies each reports the tag's version (release-verify-version), and hands them over as a workflow artifact.
  • assets attaches them plus SHA256SUMS to the GitHub Release (unchanged behaviour).
  • registry uploads them to the generic repository megaeth-generic-registry (devops-production-464602, asia-northeast1) with the shared release-upload-artifact action, under environment: publish. The action is idempotent: an identical file already there is a no-op, a different one fails rather than overwrites.

One build feeds both targets, so the Release page and the registry carry the same bytes and the same checksum. dry_run (rehearsal dispatch on a tag ref) runs everything and publishes nothing.

Registry layout changes

The new path is the org convention already used for mega-evme: <binary>/<X.Y.Z>/<binary>, e.g. stateless-validator/2.0.19/stateless-validator. The legacy chain-ops action wrote <binary>/<commit-sha>/release/vX.Y.Z/<binary> (v2.0.18 is at stateless-validator/4d5c0b8…/release/v2.0.18/stateless-validator). I found no consumer of that layout in chain-ops, mega-infra, dist-docs or the CI inventories; if something outside those reads it, the shared action's path input can reproduce the old shape.

What goes away

  • release.yaml and release-tracing.yaml: tag-push archive through chain-ops' pkg_upload_gcp, needing PAT_GAO_CI to check out chain-ops (this repo's dependencies are public; nothing else here uses that PAT) and gated by the prod environment. Only release.yaml had the gate; release-tracing.yaml uploaded unapproved.
  • With direct settlement (ci(release): settle directly, gated by the release environment #212) the release approval is the release environment at settle, so the archive no longer needs its own approval gate. The prod environment and its secrets are deleted once this has shipped a release.

Prerequisites

🤖 Generated with Claude Code

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-09T07:46:18.844698Z 8ea0317 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@mega-maxwell

mega-maxwell Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Claude review status

Living comment — rewritten in place. The review workflow keeps this single comment up to date instead of posting a new one each round, so it always describes the latest reviewed commit and the earlier text is intentionally gone. No reply is needed here; reply to a finding in its own review thread, and answer an open question in a reply on this PR. The next review round reconciles your answer.

⚠️ 1 open finding(s)

Last reviewed: 8dc29bd4..8ea03171 · updated 2026-09-09T07:47:46+00:00

New this round: 1 finding(s), 0 question(s) · Resolved this round: 0 · Open questions: 0

…se; drop the legacy release workflows

The Artifact Registry archive moves into on-release.yml, where the other
publish targets already live. One build job builds and verifies both
binaries and hands them to two target jobs: `assets` attaches them to
the GitHub Release as before, `registry` uploads them to the generic
repository megaeth-generic-registry under <binary>/<X.Y.Z>/<binary>
(the org convention, as mega-evme; the legacy layout was
<binary>/<commit-sha>/release/vX.Y.Z/<binary>). Both targets publish
the same bytes, so the Release page and the registry agree on the
checksum. GCP_AUTH_KEY comes from the `publish` environment, whose
deployment policy allows only v* tag refs.

release.yaml and release-tracing.yaml — the chain-ops based archive on
tag push, gated by the `prod` environment and needing PAT_GAO_CI to
check out chain-ops — are deleted; the `prod` environment and its
secrets go once this has shipped a release.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f74ec244d9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/on-release.yml
Troublor and others added 2 commits September 9, 2026 15:37
…obes

Same one-line change as #213, carried here so this PR is correct on
its own whichever merges first.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

@mega-maxwell mega-maxwell Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Review needs attention — 1 finding(s)

0 blocking · 0 should-fix · 1 suggestion(s) · 0 open question(s)

Reviewed 8dc29bd4..8ea03171.

Findings without inline anchors:

  • .github/workflows/release-settle.yml:8 — [Minor] release-settle.yml comment still describes release.yaml/release-tracing.yaml as active archivers, but this PR deletes them Reader-level confusion for the person operating a release: the doc comment cites two workflows that are gone and pins the archive step to a tag push that no longer exists, hiding that on-release.yml now performs both the Release-page attach and the Artifact Registry archive. It also weakens the reasoning in the surrounding paragraph, which relies on release.yaml / release-tracing.yaml still being a distinct target. Suggested fix: Update the comment in release-settle.yml so it matches the new shape, e.g. replace 'on-release.yml then attaches the binaries; release.yaml / release-tracing.yaml archive to Artifact Registry on the tag push' with something like 'on-release.yml then attaches the binaries to the Release page and archives them to Artifact Registry'.

@Troublor
Troublor merged commit 74b6270 into main Sep 9, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant