fix: wire release_token to the trigger-capable state token - #254
Merged
Merged
Conversation
Signed-off-by: Joshua Temple <joshua.temple@stablekernel.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
rc tags were created by the orchestrate finalize Manage Release step using release_token, which was unset and defaulted to secrets.GITHUB_TOKEN. GitHub suppresses workflow-triggering events for refs created by GITHUB_TOKEN, so the rc tag push raised no event: the Release workflow never fired, and with it the fleet (gated on Release completion) and auto-promote never fired. The rc to Release to fleet to promote chain has been dead since the v0.3.0 rc line.
Fix
Set release_token to the existing trigger-capable secrets.CASCADE_STATE_TOKEN in this repo's manifest (alongside state_token, which already uses it) and regenerate. The Manage Release step now creates the rc tag with the PAT, so the tag push fires Release, then the fleet, then auto-promote, end to end.
This re-arms the full release pipeline, including auto-promote publishing a release on a green fleet run.
Verification
Regenerated orchestrate.yaml and promote.yaml; the Manage Release token is now secrets.CASCADE_STATE_TOKEN. cascade verify reports no drift; go build and generate tests pass. Repo-config only; schema_version unchanged.
Follow-up
The generator should not let this be a silent footgun for adopters: when state_token is set but release_token is not, the rc to Release chain dies quietly. A separate change should default release_token to the state-token value, or have the tag-creating step use the state token, or document that release_token must be trigger-capable.