Skip to content

Release through the reusable workflows of tamada/.github - #48

Merged
tamada merged 1 commit into
mainfrom
refactor/reusable-workflows
Aug 7, 2026
Merged

tamada merged 1 commit into
mainfrom
refactor/reusable-workflows

Conversation

@tamada

@tamada tamada commented Aug 7, 2026

Copy link
Copy Markdown
Owner

The publish workflow tagged, released, and deployed the site by itself. This
hands those to the reusable workflows of tamada/.github@v1, and keeps here
what only this repository knows.

job what runs it
start release-start.yaml@v1 — tags main, opens the release as a draft
documents build-hugo-and-publish.yaml@v1 — builds docs, deploys to Pages
publish this repository — builds the command for four platforms, attaches the assets
publish_to_crates_io this repository — trusted publishing
finish release-finish.yaml@v1 — publishes the draft with the App token

Two things this fixes

The site deployment was broken, quietly. Pages of this repository serves what a
workflow uploads (build_type: workflow), while the workflow pushed the built site to
the gh-pages branch. The job succeeded, the branch moved, and Pages kept serving the
older site; it still tells v2.0.5 today, after v3.0.0 was released. The last Pages
deployment is of 2026-07-25.

notify-publish.yaml has never run. A release published by GITHUB_TOKEN does not
fire release: published. release-finish publishes the draft with the token of the
GitHub App, which does fire it.

Before merging: one secret is needed

release-finish reads APP_CLIENT_ID and APP_PRIVATE_KEY through secrets: inherit.
This repository has APP_PRIVATE_KEY and CLIENT_ID, which does not match by name
and therefore never arrives.

Add APP_CLIENT_ID with the same value as CLIENT_ID (or rename it, and update
notify-publish.yaml which reads CLIENT_ID).

Without it the release is still published, using GITHUB_TOKEN, and the job says so in
its log — but notify-publish would stay silent as before.

Notes

  • The manual dispatch is kept, with version as its input, so a release which failed
    halfway is completed without merging a pull request again.
  • Hugo stays pinned at 0.154.5; the blowfish theme of docs/go.mod asks for 0.141.0
    or later and tells it works up to 0.154.5.
  • actionlint reports two findings on notify-publish.yaml, both false: its bundled
    metadata for actions/create-github-app-token@v3 is stale, and the upstream action
    does accept client-id. The reusable release-finish uses the same input.
  • The gh-pages branch is left as it is; nothing serves from it any more.

🤖 Generated with Claude Code

The publish workflow did the tagging, the release, and the site deployment by
itself. Hand them to the reusable workflows, and keep here what only this
repository knows; building the command for each platform, and publishing the
crate.

- release-start tags main and opens the release as a draft,
- build-hugo-and-publish builds docs and deploys it to Pages, and
- release-finish takes the draft off with the token of the GitHub App.

The draft matters. The assets are attached while nobody knows about the
release, and the last job publishes it, which fires `release: published`;
the release published by GITHUB_TOKEN, as the old workflow did, fires nothing.
That is why notify-publish.yaml has never run once, and it will from now on.

The site deployment was broken in a quiet way. The Pages of this repository
serves what a workflow uploads (build_type: workflow), while the workflow
pushed the built site to the gh-pages branch; the job succeeded, the branch
moved, and Pages served the older site. It still tells v2.0.5 today, after the
release of v3.0.0. build-hugo-and-publish uploads the artifact to Pages, hence,
the deployment reaches the site.

Also quiet the shellcheck of versionup.yaml; the redirections were unquoted,
and it read a header into a variable which nothing used.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@tamada
tamada merged commit 6541626 into main Aug 7, 2026
8 checks passed
@tamada
tamada deleted the refactor/reusable-workflows branch August 7, 2026 07:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant