Skip to content

ci: take the fleet's release workflow - #27

Merged
zmaril merged 1 commit into
mainfrom
release-workflow
Aug 30, 2026
Merged

zmaril merged 1 commit into
mainfrom
release-workflow

Conversation

@zmaril

@zmaril zmaril commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

The release half of setting jawohl up for crates.io Trusted Publishing. Both
files are fleet-managed and arrive through ordnung; the source change is
PowderworksCode/conf#18, which teaches the managed release workflow to handle a
library crate.

.github/workflows/release.yml — a tag is the whole trigger. It checks the tag
against Cargo.toml, drafts a GitHub release, publishes the crate, and
un-drafts. The archive, checksum and install-smoke jobs skip themselves: jawohl
has no binary target, and the workflow asks cargo rather than assuming.

scripts/publish.sh — dry run by default, --execute to upload. It reads the
sparse index to see whether the version is already published, so re-running a
release for an existing tag is a no-op rather than a failure. Verified here:
./scripts/publish.sh packages 42 files, compiles the packaged crate, and stops
at aborting upload due to dry run, having correctly seen 0.2.0 as not yet on
the registry (0.1.0 is, from 2023).

Two steps outside this PR

  1. This repository → Settings → Environments → New environment → crates-io.
    The publish job targets it, and it is the one place to require an approval
    before an irreversible upload.
  2. crates.io → jawohl → Settings → Trusted Publishing → Add, with owner
    PowderworksCode, repository jawohl, workflow release.yml, environment
    crates-io. The form checks that the workflow exists on the default branch,
    so this has to merge first.

No registry token is stored: publishing authenticates over OIDC with a token
that lives under an hour. The workflow does still accept a
CARGO_REGISTRY_TOKEN secret as a bootstrap path, which jawohl does not need —
that exists for a crate's first version, and jawohl is already on the registry.

Releasing 0.2.0 afterwards is git tag v0.2.0 && git push origin v0.2.0.

Unrelated, but noticed

jawohl declares license = "MIT" and has no LICENSE file. cargo is content
with the field alone, so this does not block publishing, but the file is worth
adding.

jawohl publishes to crates.io by hand today, which is why 0.2.0 has been sitting
unreleased. This is the fleet's release workflow and publish script, arriving
through ordnung rather than written here.

A tag is the whole trigger: the workflow checks it against Cargo.toml, drafts a
GitHub release, and publishes the crate. The archive, checksum and install-smoke
jobs skip themselves, because jawohl has no binary target for them to work on.

Publishing authenticates over OIDC through crates.io Trusted Publishing, so no
registry token is stored here. That needs two things outside this PR: a
`crates-io` environment in this repository's settings, and a trusted publisher
on crates.io naming this workflow file and that environment.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0144PU3MssnfbM5tZiqXW7d3
@zmaril
zmaril merged commit d739050 into main Aug 30, 2026
12 checks passed
@zmaril
zmaril deleted the release-workflow branch August 30, 2026 12:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant