Skip to content

fix: publish release charts to native Cloudsmith Helm - #30

Merged
captjt merged 2 commits into
mainfrom
fix/cloudsmith-destination-checks
Sep 25, 2026
Merged

captjt merged 2 commits into
mainfrom
fix/cloudsmith-destination-checks

Conversation

@captjt

@captjt captjt commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Release mirroring stops before uploading because the authenticated Helm OCI endpoint returns HTTP 500 during destination preflight. Publish the verified release chart archives as native Helm packages in eqtylab/prod and install them through https://dl.cloudsmith.io/basic/eqtylab/prod/helm/charts/.

  • Authenticate Helm's repository using the existing short-lived OIDC credential; keep images on the Docker registry.
  • Reuse identical native packages, reject conflicts and policy failures, wait for package processing and Helm index propagation, and pull each chart to verify its original SHA-256.
  • Record native repository/package IDs and original source hashes in delivery schema v2. Preserve source release archives, signatures, digest pins, and completion-marker-last behavior.
  • Update customer docs and govctl commands. Matching source changes: https://github.com/eqtylab/guardian-infrastructure/pull/121, so the next sync preserves them.
  • Retain safe HTTP status diagnostics without exposing provider responses or credentials.

Validation: 31 release unit tests, six govctl tests, actionlint on both release workflows, and git diff --check pass. With explicit approval, uploaded auth-service 1.2.1 as a native Helm package (ID 14u0mZRx5Cmo), pulled it via the Helm repository, and verified SHA-256 b8990a667c424942c509ca8bbbaea2feca53472bac486b02e439128badff7467. Repeating the publisher reused the existing package. Read-only validation of saved 1.2.0 and 1.2.1 artifacts against live releases and native Helm/raw destinations passed.

After merge, start a fresh run using the fixed workflow on main:

gh workflow run mirror-cloudsmith-release.yaml --repo eqtylab/deployment --ref main -f version=1.2.1 -f publish=true

For historical releases, substitute the version while retaining --ref main. Re-running an old workflow run uses its old code. Full OIDC publication remains to be verified by the main-branch run; the native test package will be reused. The earlier approved OCI diagnostic package is left untouched.

@captjt
captjt requested a review from tmccoy14 September 25, 2026 14:14
@captjt captjt self-assigned this Sep 25, 2026
@captjt
captjt merged commit 54eb432 into main Sep 25, 2026
2 checks passed
@captjt
captjt deleted the fix/cloudsmith-destination-checks branch September 25, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants