Skip to content

ci(release): promote stream-connectors to stable on release tag push - #409

Open
tuntoja wants to merge 4 commits into
developfrom
MON-205723-stream-connectors-tag-promotion
Open

tuntoja wants to merge 4 commits into
developfrom
MON-205723-stream-connectors-tag-promotion

Conversation

@tuntoja

@tuntoja tuntoja commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Refs MON-205723

Description

Second step after #407. Pushing a centreon-stream-connectors-YYYYMMNN tag (done by release-new) now promotes testing to stable on Pulp and JFrog, so releases no longer go through master. Same model as centreon-plugins#6461 and centreon-plugin-packs#2336.

  • get-environment: on a release tag push, stability is stable, the release type comes from the tag message, and skip_workflow is set when the workflow on.push.paths did not change since the previous release tag (.github/scripts/release/get-release-tag-context.sh, same as plugin-packs).
  • The 8 packaging workflows (connectors, lib, lua-*) get tags: ['centreon-stream-connectors-[0-9]+']. On a tag:
    • package, test and deliver are skipped, so nothing is rebuilt;
    • a new promote job runs the existing promote-to-stable-pulp first, then JFrog (also when Pulp failed).
  • JFrog: the new promote-jfrog.sh (promote-to-stable-jfrog action) copies the latest testing build per package to stable. JFrog testing keeps every build, so the latest is picked from the rpm.metadata.* / deb.* properties.
    • A file already in stable is skipped and never overwritten. If its checksum differs, a warning asks for a version bump.
    • A testing package missing one of those properties fails the job.
  • JFrog testing is split per release type, as in centreon-plugins. Hotfix rpms go to testing-hotfix, and testing debs carry a release_type property. A hotfix tag therefore never promotes release builds, the same way Pulp's testing-release / testing-hotfix work.
  • Testing builds: a dispatch of stream-connectors.yml on release-N / hotfix-N packages every connector changed since the previous release tag. It used to take only the last commit.
  • The master flow is unchanged (rebuild, JFrog upload, PR lookup) until the cutover.

Release order

  • Merge this PR before cutting release-20261000. A tag runs the workflow files of the tagged commit.
  • A fixed-version package whose content changed needs a version bump before its build. Pulp would otherwise replace the stable file under the same version while JFrog keeps the old one.
  • First release (20261000): merge ci(release): read package versions from root version files #410 right after this PR. It moves the fixed versions to root .version.* files, bumps the lib to 3.8.2, versions connectors with the release number, ignores CI-only changes, and adds a bump guard to release-new. With it, only stream-connectors, stream-connectors-lib and lua-cffi are dispatched on the branch, and no promote job fails.
  • Add triggers for stream connectors #389 makes stream-connectors.yml and stream-connectors-lib.yml workflow_call only. Whichever merges first, the tag trigger has to move to its orchestrator. See Add triggers for stream connectors #389 (comment).
  • Recovery: a failed promote job can be re-run from the tag run. If testing was empty, recreate the branch from the tag, dispatch the build, then re-run promptly, because a re-run takes whatever is latest in testing at that moment.
  • Never merge the release branch into master. Fixes made on it need their own PR to develop.

Type of change

  • Enhancement (non-breaking change)

How this pull request can be tested ?

  • Local harnesses:
    • tag context, 38 checks (including a lightweight previous tag);
    • promotion, 111 checks: get-environment per event type, the changes base against the real tag history with decoys, and promote-jfrog.sh with a stubbed jf, including the release/hotfix split, missing properties and checksum warnings. Five deliberate mutations were caught.
  • JFrog dry run on the real repositories: nothing to promote today.
    • RPMs are already stable, and checksums differ because the old master flow rebuilt them.
    • Testing debs carry no release_type yet; the release-branch builds add it.
  • Pulp, read-only replay from the public indexes:
    • testing-release is empty for every pair today;
    • with unstable as a stand-in source, it selects exactly the latest build per package.
  • Lint: actionlint 1.7.7 with the CI flags, shellcheck, and yamllint 1.35.1.
  • Canary: a dispatch on this branch. The tag path is first exercised by the real release, after a Pulp/JFrog preview on the real release branch.

A centreon-stream-connectors-YYYYMMNN tag push gives stability stable,
the release type from the tag message, and skip_workflow when the
workflow paths did not change since the previous release tag.
Each packaging workflow promotes the latest testing packages of its
module on Pulp and JFrog when a release tag is pushed; nothing is
rebuilt. The master flow is unchanged.
…us tag

A dispatch on release-YYYYMMNN / hotfix-YYYYMMNN used to package only
the connectors of the last commit.
Hotfix rpms are delivered to testing-hotfix and testing debs carry a
release_type property, as in centreon-plugins, so a hotfix tag never
promotes release builds on JFrog. The promotion also fails on missing
package properties and warns when stable has another build of the same
version.
@tuntoja
tuntoja marked this pull request as ready for review October 6, 2026 14:10
@tuntoja
tuntoja requested a review from a team as a code owner October 6, 2026 14:10
@tuntoja
tuntoja requested review from Nivoky and kduret and removed request for a team October 6, 2026 14:10
@tuntoja tuntoja mentioned this pull request Oct 8, 2026
1 of 11 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants