Skip to content

Commit d9b9e4e

Browse files
committed
temprary gating on every release step
1 parent 8ffcefc commit d9b9e4e

2 files changed

Lines changed: 16 additions & 3 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 15 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ name: Release
44
# every stage first checks whether its work is already done, "Re-run failed jobs"
55
# picks up where the release stopped instead of redoing the 20-minute Maven
66
# Central publish.
7+
#
8+
# TEMPORARY: stages 2 and 4-8 also sit behind the `release-approval` environment,
9+
# so the release advances one stage per human approval while the first few real
10+
# releases are watched by hand. Drop those `environment:` lines once it is trusted.
11+
# Two must not change with them: stage 3's gate is permanent (it triggers an
12+
# irreversible publish), and stage 9 must never be gated (it reports failures, so
13+
# needing approval to find out what broke defeats the point).
714

815
on:
916
workflow_dispatch:
@@ -52,6 +59,7 @@ jobs:
5259
name: 2 · release notes
5360
needs: [plan]
5461
runs-on: ubuntu-latest
62+
environment: release-approval
5563
steps:
5664
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
5765
- uses: ./.github/actions/setup
@@ -70,8 +78,8 @@ jobs:
7078
name: 3 · cut frontend release
7179
needs: [notes]
7280
runs-on: ubuntu-latest
73-
# The Maven Central publish this sets off cannot be undone, so it is the one
74-
# place a human signs off. Add required reviewers to the environment.
81+
# The Maven Central publish this sets off cannot be undone. This gate is
82+
# permanent: it stays after the temporary per-stage gates above come off.
7583
environment: release-approval
7684
steps:
7785
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
@@ -92,6 +100,7 @@ jobs:
92100
needs: [frontend_release]
93101
runs-on: ubuntu-latest
94102
timeout-minutes: 45
103+
environment: release-approval
95104
steps:
96105
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
97106
- uses: ./.github/actions/setup
@@ -110,6 +119,7 @@ jobs:
110119
name: 5 · point backend at the new frontend
111120
needs: [frontend_central]
112121
runs-on: ubuntu-latest
122+
environment: release-approval
113123
steps:
114124
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
115125
- uses: ./.github/actions/setup
@@ -138,6 +148,7 @@ jobs:
138148
name: 6 · cut backend release
139149
needs: [backend_pom]
140150
runs-on: ubuntu-latest
151+
environment: release-approval
141152
steps:
142153
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
143154
- uses: ./.github/actions/setup
@@ -162,6 +173,7 @@ jobs:
162173
needs: [backend_release]
163174
runs-on: ubuntu-latest
164175
timeout-minutes: 90
176+
environment: release-approval
165177
steps:
166178
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
167179
- uses: ./.github/actions/setup
@@ -180,6 +192,7 @@ jobs:
180192
name: 8 · reopen master for development
181193
needs: [backend_release]
182194
runs-on: ubuntu-latest
195+
environment: release-approval
183196
steps:
184197
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
185198
- uses: ./.github/actions/setup

‎README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# cbioportal-release-manager
1+
# cBioPortal Release Manager
22

33
Cuts the weekly release across `cbioportal` and `cbioportal-frontend`, up to a
44
published and verified Docker image, then files an issue saying what to deploy.

0 commit comments

Comments
 (0)