Skip to content

feat(template): release through continuo's public release API - #73

Merged
carolsimone merged 2 commits into
mainfrom
feat/public-release-api
Oct 2, 2026
Merged

carolsimone merged 2 commits into
mainfrom
feat/public-release-api

Conversation

@carolsimone

@carolsimone carolsimone commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • The template/ release workflow now submits to <RELEASE_ENDPOINT>/api/v1/releases with the job's GitHub Actions OIDC token (audience = origin of RELEASE_ENDPOINT, a fresh token per call, never printed) and polls GET /api/v1/releases/{id} until terminal. promoted passes; rejected, superseded, an API error or a ~15 minute timeout (90 polls x 10 s) fail the job. Transient 429/5xx on submit (idempotent) and on polls are retried.
  • RELEASE_ENDPOINT keeps its name and is continuo's base URL (scheme://host[:port], no path). A new first step fails before any build when it is empty or has a path.
  • The body is built with jq -n --arg and carries release_id, service, image_tag, kind; repo/commit_sha come from the token. The workflow never sends bootstrap: a service's first release is an operator bootstrap.
  • Job gets timeout-minutes: 45; permissions, build and upload steps are unchanged.
  • Docs: template/README.md, root README.md quickstart and docs/boundary-contract.md (13.3, 13.5) describe the base URL, the ciAuth.bindings requirement (linked to continuo's deploy/README.md) and the bootstrap. CHANGELOG entry added.

Breaking for existing template users: a RELEASE_ENDPOINT that carries a path is rejected, and the repository must be bound in ciAuth.bindings.

Test plan

  • actionlint template/.github/workflows/release.yml clean
  • New tests in tests/test_template.py: workflow shape (API path, audience, bounded poll, timeout, ordering) and the endpoint check step executed against empty / no scheme / path / query / valid inputs
  • Ran the submit step's script against a local mock server for promoted, rejected and superseded: exit codes 0/1/1, token never appears in output
  • uv run pytest tests/test_template.py tests/test_release_pipeline_structure.py tests/test_ci_test_coverage.py and ruff check . pass
  • Repo CI green on this PR (test, integration-postgres/trino/duckdb, dco, security)
  • Not exercised against a live install (requires a bound repository)

🤖 Generated with Claude Code

https://claude.ai/code/session_01QtrP3QHzy3ubJfRXaHB57m

carolsimone and others added 2 commits October 2, 2026 13:31
The template release workflow submits to <RELEASE_ENDPOINT>/api/v1/releases with
the job's GitHub Actions OIDC token (a fresh one per call) and polls
GET /api/v1/releases/{id} to a terminal status, bounded to about 15 minutes.
RELEASE_ENDPOINT keeps its name and is now continuo's base URL; the workflow
fails before building when it is empty or malformed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QtrP3QHzy3ubJfRXaHB57m
Signed-off-by: Simone Carolini <simonecarolini.sc@gmail.com>
… preflight

- Match RELEASE_ENDPOINT as a whole string so a multi-line value cannot inject
  lines into $GITHUB_ENV; reject userinfo and whitespace; never echo the value.
- Add a preflight read of /api/v1/current-prod before the build, naming
  ciAuth.bindings and the audience on a 401/403.
- Poll for about 50 minutes with timeout-minutes 60; do not cancel a run that is
  waiting for its release; do not sleep after the last retry.
- Document the exact-origin requirement and mark the template change Breaking
  for newly copied templates in the changelog.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QtrP3QHzy3ubJfRXaHB57m
Signed-off-by: Simone Carolini <simonecarolini.sc@gmail.com>
@carolsimone
carolsimone merged commit 722f4f3 into main Oct 2, 2026
9 checks passed
@carolsimone
carolsimone deleted the feat/public-release-api branch October 2, 2026 11:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant