-
Notifications
You must be signed in to change notification settings - Fork 8
V10.8.0/options enhancement #172
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
29 commits
Select commit
Hold shift + click to select a range
b35e495
🔄 update ci/cd workflow references and codecov branch
gimlichael 480adce
🔄 update contributing guide with new ci/cd workflow structure
gimlichael bc6c348
🗑️ remove obsolete ci-pipeline workflow file
gimlichael 9d3be7d
📝 add .bot workspace readme with ai working guidelines
gimlichael af5491b
🤖 add .bot workspace to gitignore with readme exception
gimlichael d5859e8
🧪 expand servicecollectionextensions test coverage with comprehensive…
gimlichael 271b734
✨ add configured options integration
aicia-bot 130b6b4
📝 document configured options api behavior
aicia-bot 0caea60
📦 add configured options package notes
aicia-bot 3fb3bd1
💬 add 10.8.0 changelog entry
gimlichael 38db817
📝 update CI runner guidance
aicia-bot de455a7
👷 update GitHub workflow runners
aicia-bot f02e921
🐛 propagate cancellation during options validation
aicia-bot 9f8e43c
🐛 ensure unmanaged cleanup after managed cleanup fails
aicia-bot cf06640
⬆️ update coverlet and sqlclient versions
aicia-bot 10a1a65
👷 reuse the shared codecov workflow
aicia-bot 9b8e9fd
📦 update package release notes
aicia-bot 0bcd6c2
💬 update 10.8.0 release summary
aicia-bot d56d25a
✅ use UTC validity windows in signed URI test
aicia-bot 98908e9
✅ isolate latency limits from retry behavior tests
aicia-bot 29f2945
original
gimlichael 8a4d295
👷 switch release automation to validated version tags
aicia-bot 83de72a
👷 add published release deployment workflow
aicia-bot 1950469
💬 update 10.8.0 changelog with release details
aicia-bot 79f1588
🐛 preserve exceptions from both disposal hooks
aicia-bot 26d1890
🔒️ verify the live release tag before publishing
aicia-bot e7ef743
🔧 pass Codecov tokens explicitly to reusable workflows
aicia-bot eb5cd84
💬 document release and deployment steps
aicia-bot fca2b1d
update cl
gimlichael File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,10 @@ | ||
| # .bot Workspace | ||
|
|
||
| This folder is reserved for local-only AI working material such as: | ||
|
|
||
| - brainstorm notes | ||
| - draft implementation plans | ||
| - design alternatives | ||
| - temporary agent state | ||
|
|
||
| Keep this folder out of source control. Move only finalized, non-confidential guidance into `AGENTS.md` or `.github/copilot-instructions.md`. | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,172 @@ | ||
| name: Deploy Flow | ||
| on: | ||
| release: | ||
| types: [published] | ||
| workflow_dispatch: | ||
| inputs: | ||
| tag: | ||
| type: string | ||
| description: Existing published GitHub Release tag to deploy, e.g. v10.7.2. | ||
| required: true | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| concurrency: | ||
| group: cuemon-deploy-${{ github.event.release.tag_name || inputs.tag }} | ||
| cancel-in-progress: false | ||
|
|
||
| jobs: | ||
| resolve_release: | ||
| name: Resolve published release and authoritative SHA | ||
| runs-on: ubuntu-26.04 | ||
| permissions: | ||
| contents: read | ||
| outputs: | ||
| version: ${{ steps.resolve.outputs.version }} | ||
| tag: ${{ steps.resolve.outputs.tag }} | ||
| sha: ${{ steps.resolve.outputs.sha }} | ||
| steps: | ||
| - id: resolve | ||
| name: Validate release identity and resolve the released commit | ||
| shell: bash | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| WORKFLOW_REF: ${{ github.ref }} | ||
| RELEASE_TAG: ${{ github.event.release.tag_name || inputs.tag }} | ||
| run: | | ||
| set -euo pipefail | ||
|
|
||
| if [[ "$GITHUB_EVENT_NAME" == "release" ]]; then | ||
| if ! jq -e --arg tag "$RELEASE_TAG" '.action == "published" and .release.draft == false and .release.tag_name == $tag' "$GITHUB_EVENT_PATH" >/dev/null; then | ||
| echo "::error::Deployment requires a published, non-draft GitHub Release matching '$RELEASE_TAG'." | ||
| exit 1 | ||
| fi | ||
| elif [[ "$GITHUB_EVENT_NAME" == "workflow_dispatch" ]]; then | ||
| if [[ "$WORKFLOW_REF" != "refs/heads/main" ]]; then | ||
| echo "::error::Deployment dispatch must target refs/heads/main; received '$WORKFLOW_REF'." | ||
| exit 1 | ||
| fi | ||
| else | ||
| echo "::error::Unsupported deployment event '$GITHUB_EVENT_NAME'." | ||
| exit 1 | ||
| fi | ||
|
|
||
| if [[ "$RELEASE_TAG" != v* ]]; then | ||
| echo "::error::Release tag '$RELEASE_TAG' must have the v prefix (for example, v10.7.2)." | ||
| exit 1 | ||
| fi | ||
|
|
||
| RELEASE_VERSION="${RELEASE_TAG#v}" | ||
| semver_regex='^(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)(-((0|[1-9][0-9]*|[0-9A-Za-z-]*[A-Za-z-][0-9A-Za-z-]*)(\.(0|[1-9][0-9]*|[0-9A-Za-z-]*[A-Za-z-][0-9A-Za-z-]*))*))?$' | ||
| if [[ ! "$RELEASE_VERSION" =~ $semver_regex ]]; then | ||
| echo "::error::'$RELEASE_VERSION' is not a supported SemVer release version." | ||
| exit 1 | ||
| fi | ||
|
|
||
| release_tag="$RELEASE_TAG" | ||
| release_json="$(gh api "repos/$GITHUB_REPOSITORY/releases/tags/$release_tag")" | ||
| if ! jq -e --arg tag "$release_tag" '.tag_name == $tag and .draft == false and (.published_at | type == "string")' <<< "$release_json" >/dev/null; then | ||
| echo "::error::GitHub Release '$release_tag' is missing, has a different tag, or is not published." | ||
| exit 1 | ||
| fi | ||
|
|
||
| archive_name="cuemon-docfx-$RELEASE_VERSION.oci.tar" | ||
| checksum_name="$archive_name.sha256" | ||
| if ! jq -e --arg archive "$archive_name" --arg checksum "$checksum_name" \ | ||
| 'any(.assets[]; .name == $archive and .state == "uploaded") and any(.assets[]; .name == $checksum and .state == "uploaded")' <<< "$release_json" >/dev/null; then | ||
| echo "::error::GitHub Release '$release_tag' must contain the immutable OCI archive '$archive_name' and checksum '$checksum_name'." | ||
| exit 1 | ||
| fi | ||
|
|
||
| ref_json="$(gh api "repos/$GITHUB_REPOSITORY/git/ref/tags/$release_tag")" | ||
| object_type="$(jq -r '.object.type' <<< "$ref_json")" | ||
| object_sha="$(jq -r '.object.sha' <<< "$ref_json")" | ||
| if [[ "$object_type" == "tag" ]]; then | ||
| tag_json="$(gh api "repos/$GITHUB_REPOSITORY/git/tags/$object_sha")" | ||
| object_type="$(jq -r '.object.type' <<< "$tag_json")" | ||
| object_sha="$(jq -r '.object.sha' <<< "$tag_json")" | ||
| fi | ||
|
|
||
| if [[ "$object_type" != "commit" || ! "$object_sha" =~ ^[0-9a-fA-F]{40}$ ]]; then | ||
| echo "::error::Release tag '$release_tag' does not resolve to a Git commit." | ||
| exit 1 | ||
| fi | ||
|
|
||
| { | ||
| echo "version=$RELEASE_VERSION" | ||
| echo "tag=$release_tag" | ||
| echo "sha=$object_sha" | ||
| } >> "$GITHUB_OUTPUT" | ||
|
|
||
| { | ||
| echo "## DocFX promotion request validated" | ||
| echo | ||
| echo "- Version: $RELEASE_VERSION" | ||
| echo "- Release tag: $release_tag" | ||
| echo "- Released SHA: $object_sha" | ||
| } >> "$GITHUB_STEP_SUMMARY" | ||
|
|
||
| promote_docfx_image: | ||
| name: Promote the released DocFX OCI image to JCR | ||
| needs: [resolve_release] | ||
| runs-on: ubuntu-26.04 | ||
| timeout-minutes: 30 | ||
| environment: Production | ||
| permissions: | ||
| contents: read | ||
| steps: | ||
| - name: Download the immutable OCI assets from the GitHub Release | ||
| shell: bash | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| RELEASE_VERSION: ${{ needs.resolve_release.outputs.version }} | ||
| RELEASE_TAG: ${{ needs.resolve_release.outputs.tag }} | ||
| run: | | ||
| set -euo pipefail | ||
| release_json="$(gh api "repos/$GITHUB_REPOSITORY/releases/tags/$RELEASE_TAG")" | ||
| if ! jq -e --arg tag "$RELEASE_TAG" '.tag_name == $tag and .draft == false and (.published_at | type == "string")' <<< "$release_json" >/dev/null; then | ||
| echo "::error::GitHub Release '$RELEASE_TAG' is no longer published." | ||
| exit 1 | ||
| fi | ||
|
|
||
| artifact_directory="$RUNNER_TEMP/docfx-release-asset" | ||
| mkdir -p "$artifact_directory" | ||
| archive_name="cuemon-docfx-$RELEASE_VERSION.oci.tar" | ||
| checksum_name="$archive_name.sha256" | ||
| gh release download "$RELEASE_TAG" --repo "$GITHUB_REPOSITORY" --pattern "$archive_name" --dir "$artifact_directory" | ||
| gh release download "$RELEASE_TAG" --repo "$GITHUB_REPOSITORY" --pattern "$checksum_name" --dir "$artifact_directory" | ||
|
|
||
| - id: publish | ||
| name: Promote the verified OCI artifact to JCR and confirm its digest | ||
| uses: codebeltnet/oci-artifact-publish@v1 | ||
| with: | ||
| archive-path: ${{ runner.temp }}/docfx-release-asset/cuemon-docfx-${{ needs.resolve_release.outputs.version }}.oci.tar | ||
| checksum-path: ${{ runner.temp }}/docfx-release-asset/cuemon-docfx-${{ needs.resolve_release.outputs.version }}.oci.tar.sha256 | ||
| version: ${{ needs.resolve_release.outputs.version }} | ||
| revision: ${{ needs.resolve_release.outputs.sha }} | ||
| repository: jcr.codebelt.net/geekle/cuemon-docfx | ||
| username: ${{ secrets.JCR_USERNAME }} | ||
| password: ${{ secrets.JCR_PASSWORD }} | ||
|
|
||
| - name: Record the immutable JCR identity and Kubernetes handoff | ||
| shell: bash | ||
| env: | ||
| RELEASE_VERSION: ${{ needs.resolve_release.outputs.version }} | ||
| RELEASE_SHA: ${{ needs.resolve_release.outputs.sha }} | ||
| IMAGE: ${{ steps.publish.outputs.image }} | ||
| DIGEST: ${{ steps.publish.outputs.digest }} | ||
| IMAGE_BY_DIGEST: ${{ steps.publish.outputs.image-by-digest }} | ||
| run: | | ||
| set -euo pipefail | ||
| { | ||
| echo "## DocFX image promoted" | ||
| echo | ||
| echo "- Release: $RELEASE_VERSION" | ||
| echo "- Released SHA: $RELEASE_SHA" | ||
| echo "- Registry tag: $IMAGE" | ||
| echo "- Immutable registry digest: $DIGEST" | ||
| echo "- Kubernetes-ready image reference: $IMAGE_BY_DIGEST" | ||
| echo | ||
| echo "JCR publication succeeded. This POC stops at the immutable registry reference; Kubernetes rollout configuration is not present in this repository." | ||
| } >> "$GITHUB_STEP_SUMMARY" |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This adds a tracked guide for a local-only bot workspace. The repository’s public-API documentation directive limits new working-tree files to the managed AGENTS block, active DocFX configuration, an approved waiver, or DocFX namespace and type pages. This file is outside those categories, so the repository requirement must be satisfied before merging.
Context Used: AGENTS.md (source)
Prompt To Fix With AI
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!