feat(template): release through continuo's public release API - #73
Merged
Merged
Conversation
The template release workflow submits to <RELEASE_ENDPOINT>/api/v1/releases with
the job's GitHub Actions OIDC token (a fresh one per call) and polls
GET /api/v1/releases/{id} to a terminal status, bounded to about 15 minutes.
RELEASE_ENDPOINT keeps its name and is now continuo's base URL; the workflow
fails before building when it is empty or malformed.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QtrP3QHzy3ubJfRXaHB57m
Signed-off-by: Simone Carolini <simonecarolini.sc@gmail.com>
… preflight - Match RELEASE_ENDPOINT as a whole string so a multi-line value cannot inject lines into $GITHUB_ENV; reject userinfo and whitespace; never echo the value. - Add a preflight read of /api/v1/current-prod before the build, naming ciAuth.bindings and the audience on a 401/403. - Poll for about 50 minutes with timeout-minutes 60; do not cancel a run that is waiting for its release; do not sleep after the last retry. - Document the exact-origin requirement and mark the template change Breaking for newly copied templates in the changelog. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QtrP3QHzy3ubJfRXaHB57m Signed-off-by: Simone Carolini <simonecarolini.sc@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
template/release workflow now submits to<RELEASE_ENDPOINT>/api/v1/releaseswith the job's GitHub Actions OIDC token (audience = origin ofRELEASE_ENDPOINT, a fresh token per call, never printed) and pollsGET /api/v1/releases/{id}untilterminal.promotedpasses;rejected,superseded, an API error or a ~15 minute timeout (90 polls x 10 s) fail the job. Transient 429/5xx on submit (idempotent) and on polls are retried.RELEASE_ENDPOINTkeeps its name and is continuo's base URL (scheme://host[:port], no path). A new first step fails before any build when it is empty or has a path.jq -n --argand carriesrelease_id, service, image_tag, kind;repo/commit_shacome from the token. The workflow never sendsbootstrap: a service's first release is an operator bootstrap.timeout-minutes: 45; permissions, build and upload steps are unchanged.template/README.md, rootREADME.mdquickstart anddocs/boundary-contract.md(13.3, 13.5) describe the base URL, theciAuth.bindingsrequirement (linked to continuo's deploy/README.md) and the bootstrap. CHANGELOG entry added.Breaking for existing template users: a
RELEASE_ENDPOINTthat carries a path is rejected, and the repository must be bound inciAuth.bindings.Test plan
actionlint template/.github/workflows/release.ymlcleantests/test_template.py: workflow shape (API path, audience, bounded poll, timeout, ordering) and the endpoint check step executed against empty / no scheme / path / query / valid inputsuv run pytest tests/test_template.py tests/test_release_pipeline_structure.py tests/test_ci_test_coverage.pyandruff check .pass🤖 Generated with Claude Code
https://claude.ai/code/session_01QtrP3QHzy3ubJfRXaHB57m