Skip to content

Reusable publish-fragment workflow, and the render diff on the app PR #135

Description

@ExtraToast

Parent

JorisJonkers-dev/deploy-kit#195

What to build

  • A reusable publish-fragment workflow application repositories call on a release tag. It validates the project file with the pinned deploy-kit, resolves every image (and the migration image) to a digest, writes the images-lock share and the migration proof, pushes the keyless-signed OCI Intent Fragment carrying the release version, and dispatches composition in JorisJonkers-dev/estate with a GitHub App token.
  • A reusable step that posts the render diff of a PR's project-file change as a PR comment.

Acceptance criteria

  • home-portal publishes through it on a tag, and composition runs from the dispatch.
  • actionlint passes; every logic step is a deploy-kit CLI call.

Blocked by

Activity

  1. added
    type: featureNew user-facing or operator-facing capability.
    area: deployhomelab-deploy, deploy-v2, manifests, and rollout flow.
    component: ciContinuous integration workflow or check behavior.
    priority: P1High; important and should be handled in the current iteration.
    status: ready-for-agentFully specified; an agent may take it with nobody watching.
    on Oct 1, 2026
  2. self-assigned this
    on Oct 1, 2026
  3. ExtraToast commented on Oct 2, 2026

    @ExtraToast
    ContributorAuthor

    The dispatch App exists (JorisJonkers-dev/estate#1):

    • App: estate-dispatch, id 5165539. Permissions: actions: write, contents: read, statuses: write, metadata: read. Installed on all repositories in the org.
    • Org variable ESTATE_DISPATCH_APP_ID and org secret ESTATE_DISPATCH_APP_PRIVATE_KEY, both with visibility all. A caller's reusable workflow reads them as vars.ESTATE_DISPATCH_APP_ID and secrets.ESTATE_DISPATCH_APP_PRIVATE_KEY (pass secrets: inherit, or the secret by name).
    • Composition is dispatched with a token minted for JorisJonkers-dev/estate, e.g. actions/create-github-app-token with owner: JorisJonkers-dev and repositories: estate. compose.yml on estate is still the canary stage, workflow_dispatch only. JorisJonkers-dev/estate#2 defines the real trigger and its inputs.
    • The signer the artifacts must verify against is https://github.com/JorisJonkers-dev/estate/.github/workflows/compose.yml@refs/heads/main. Fragments are signed by the publishing repository's own identity, not this one.
  4. ExtraToast commented on Oct 3, 2026

    @ExtraToast
    ContributorAuthor

    Two things this ticket was waiting on have landed:

  5. added and removed
    status: ready-for-agentFully specified; an agent may take it with nobody watching.
    on Oct 3, 2026
  6. ExtraToast commented on Oct 3, 2026

    @ExtraToast
    ContributorAuthor

    #136 merged the two pieces this ticket asks for: the reusable publish-fragment.yml workflow and the actions/render-diff step. The ticket stays open for its acceptance line, home-portal publishing through it on a tag. What that still needs:

    For JorisJonkers-dev/estate#2: fragments are signed by https://github.com/JorisJonkers-dev/github-workflows/.github/workflows/publish-fragment.yml@<ref>, and the publishing repository is in the certificate (--certificate-github-workflow-repository). latest on ghcr.io/jorisjonkers-dev/intent-<project> only moves forward, and every release also has its own version tag.

  7. added
    status: ready-for-agentFully specified; an agent may take it with nobody watching.
    and removed
    status: ready-for-agentFully specified; an agent may take it with nobody watching.
    on Oct 3, 2026
  8. ExtraToast commented on Oct 4, 2026

    @ExtraToast
    ContributorAuthor

    #138 added the images-lock share: publish-fragment.yml takes an images-lock-artifact input and hands the lock to deploy-kit publish --images-lock, which packs only the aliases the project file names. That closes the "images-lock share" item in the list above on this side; the option itself lands in deploy-kit with JorisJonkers-dev/deploy-kit#238.

    For the caller (JorisJonkers-dev/home-portal#70): the build job writes images.lock.yml (an ImagesLock document: each image the release pushed, by digest, with the numeric uid and gid it runs as), uploads it as an artifact, and passes the artifact's name. deploy-kit's worked project-publish-fragment.yml shows one way to write it. Composition resolves a Project only from its own share and the Platform document's lock, so every alias the project file names has to be in one of the two.

  9. added
    status: ready-for-agentFully specified; an agent may take it with nobody watching.
    and removed on Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area: deployhomelab-deploy, deploy-v2, manifests, and rollout flow.component: ciContinuous integration workflow or check behavior.priority: P1High; important and should be handled in the current iteration.status: ready-for-agentFully specified; an agent may take it with nobody watching.type: featureNew user-facing or operator-facing capability.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions