Skip to content

fix: wire release_token to the trigger-capable state token - #254

Merged
joshua-temple merged 1 commit into
mainfrom
fix/release-token-trigger-capable
Jun 22, 2026
Merged

joshua-temple merged 1 commit into
mainfrom
fix/release-token-trigger-capable

Conversation

@joshua-temple

Copy link
Copy Markdown
Collaborator

Problem

rc tags were created by the orchestrate finalize Manage Release step using release_token, which was unset and defaulted to secrets.GITHUB_TOKEN. GitHub suppresses workflow-triggering events for refs created by GITHUB_TOKEN, so the rc tag push raised no event: the Release workflow never fired, and with it the fleet (gated on Release completion) and auto-promote never fired. The rc to Release to fleet to promote chain has been dead since the v0.3.0 rc line.

Fix

Set release_token to the existing trigger-capable secrets.CASCADE_STATE_TOKEN in this repo's manifest (alongside state_token, which already uses it) and regenerate. The Manage Release step now creates the rc tag with the PAT, so the tag push fires Release, then the fleet, then auto-promote, end to end.

This re-arms the full release pipeline, including auto-promote publishing a release on a green fleet run.

Verification

Regenerated orchestrate.yaml and promote.yaml; the Manage Release token is now secrets.CASCADE_STATE_TOKEN. cascade verify reports no drift; go build and generate tests pass. Repo-config only; schema_version unchanged.

Follow-up

The generator should not let this be a silent footgun for adopters: when state_token is set but release_token is not, the rc to Release chain dies quietly. A separate change should default release_token to the state-token value, or have the tag-creating step use the state token, or document that release_token must be trigger-capable.

Signed-off-by: Joshua Temple <joshua.temple@stablekernel.com>
@joshua-temple
joshua-temple merged commit 8082008 into main Jun 22, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant