Problem
The generated orchestrate finalize Manage Release step creates the rc tag using release_token. When an adopter sets state_token to a trigger-capable PAT or App token (for protected-trunk state writes) but leaves release_token unset, release_token defaults to secrets.GITHUB_TOKEN. GitHub suppresses workflow-triggering events for refs created by GITHUB_TOKEN, so the rc tag push raises no event and the Release workflow (and anything gated on it, such as a fleet or promotion stage) never fires. The failure is silent: tags appear, but the downstream chain is dead.
This bit cascade's own pipeline (fixed for this repo in #254 by setting release_token to the same trigger-capable secret).
Proposed
Make the generator not allow this silent dead-chain. Options:
- Default
release_token to the resolved state_token value when release_token is unset but state_token is set.
- Or have the tag-creating step specifically use the state token (the trigger-capable trunk-write token), since creating a tag that must fire downstream workflows is a trunk-write concern.
- At minimum, validate or document that
release_token must be trigger-capable (not the default GITHUB_TOKEN) for the automatic rc-to-release chain to fire.
Additive; no schema change.
Acceptance
- An adopter who sets only a trigger-capable
state_token gets a working rc-to-release chain without separately discovering they must also set release_token, or is clearly warned.
- Covered by a generator test and a docs note.
Problem
The generated orchestrate finalize Manage Release step creates the rc tag using
release_token. When an adopter setsstate_tokento a trigger-capable PAT or App token (for protected-trunk state writes) but leavesrelease_tokenunset,release_tokendefaults tosecrets.GITHUB_TOKEN. GitHub suppresses workflow-triggering events for refs created byGITHUB_TOKEN, so the rc tag push raises no event and the Release workflow (and anything gated on it, such as a fleet or promotion stage) never fires. The failure is silent: tags appear, but the downstream chain is dead.This bit cascade's own pipeline (fixed for this repo in #254 by setting
release_tokento the same trigger-capable secret).Proposed
Make the generator not allow this silent dead-chain. Options:
release_tokento the resolvedstate_tokenvalue whenrelease_tokenis unset butstate_tokenis set.release_tokenmust be trigger-capable (not the defaultGITHUB_TOKEN) for the automatic rc-to-release chain to fire.Additive; no schema change.
Acceptance
state_tokengets a working rc-to-release chain without separately discovering they must also setrelease_token, or is clearly warned.