Release flow: one command to build, sign, publish, and attach — plus dormant workflow #52

Closed
opened 2026-09-02 20:21:49 +00:00 by xavierk · 1 comment
Owner

Parent

Ship Fenris as native deb + rpm packages (execute the release plan)

What to build

The one-command Release: a single release command builds both formats, signs, uploads the deb to the three codename pools and the rpm to its group, and creates a release entry with notes and the artifacts plus the clearsigned checksum manifest attached — with a dry-run mode that is what the tests assert, a dormant tag-triggered workflow replicating it for when a runner exists, and a documented one-time live probe of the registry path.

Acceptance criteria

  • One release command performs: build both formats, signing, registry uploads (deb → bookworm, jammy, noble pools; rpm → the fenris group), and a release entry with notes plus the deb, rpm, and clearsigned checksum manifest attached
  • A dry-run mode prints every constructed command and sends nothing; tests assert the dry-run output at the existing seam, without network or registry access
  • Rebuilds of the same version bump the revision so a filename never collides with the registry's duplicate rejection
  • A dormant tag-triggered CI workflow replicating the release command is committed; with no runners registered it queues harmlessly and changes nothing about the manual flow
  • A one-time live probe with a throwaway package is documented: publish, verify apt/dnf metadata and signature checks as a real consumer would, then delete
  • A bare tag (tag without packages, release entry, notes, and checksums) cannot result from the flow

Blocked by

## Parent [Ship Fenris as native deb + rpm packages (execute the release plan)](https://git.bongbetic.com/xavierk/Fenris/issues/44) ## What to build The one-command Release: a single release command builds both formats, signs, uploads the deb to the three codename pools and the rpm to its group, and creates a release entry with notes and the artifacts plus the clearsigned checksum manifest attached — with a dry-run mode that is what the tests assert, a dormant tag-triggered workflow replicating it for when a runner exists, and a documented one-time live probe of the registry path. ## Acceptance criteria - [ ] One release command performs: build both formats, signing, registry uploads (deb → bookworm, jammy, noble pools; rpm → the fenris group), and a release entry with notes plus the deb, rpm, and clearsigned checksum manifest attached - [ ] A dry-run mode prints every constructed command and sends nothing; tests assert the dry-run output at the existing seam, without network or registry access - [ ] Rebuilds of the same version bump the revision so a filename never collides with the registry's duplicate rejection - [ ] A dormant tag-triggered CI workflow replicating the release command is committed; with no runners registered it queues harmlessly and changes nothing about the manual flow - [ ] A one-time live probe with a throwaway package is documented: publish, verify apt/dnf metadata and signature checks as a real consumer would, then delete - [ ] A bare tag (tag without packages, release entry, notes, and checksums) cannot result from the flow ## Blocked by - [Full compatibility matrix green: one deb and one rpm across all four targets](https://git.bongbetic.com/xavierk/Fenris/issues/47) - [Signing and consumer repo setup: rpm payload signing, key publication, pinned docs](https://git.bongbetic.com/xavierk/Fenris/issues/51)
xavierk added the ready-for-agent label 2026-09-02 20:21:50 +00:00
xavierk self-assigned this 2026-09-03 09:06:16 +00:00
Author
Owner

Resolved — all acceptance criteria met:

  1. One release command: scripts/release.sh --publish performs build (make package), signing (rpmsign + gpg --clearsign), registry uploads (deb → bookworm/jammy/noble; rpm → fenris group), and creates a Gitea release entry with notes plus deb, rpm, and SHA256SUMS.asc attached
  2. Dry-run mode: scripts/release.sh --dry-run prints every constructed command without executing; 32 structural tests assert the output without network or registry access
  3. Revision bumping: same-version rebuilds detect HTTP 409 and increment the release number, producing new filenames that avoid registry collision
  4. Dormant CI workflow: .gitea/workflows/release.yml extended with signing, upload, release creation, and artifact attachment; triggers on v* tags, queues harmlessly without a runner
  5. One-time live probe: documented in docs/install/signing-key-ceremony.md — publish throwaway package, verify apt/dnf metadata and signature checks, then delete
  6. No bare tags: release API creates the tag atomically with the release entry; no separate git push step

Changes: scripts/release.sh (new), tests/test_release.py (new, 32 tests), Makefile (release-run/release-dry-run targets), .gitea/workflows/release.yml (full release flow), docs/install/signing-key-ceremony.md (live probe).

Test results: 32/32 release tests pass, 369/369 full suite pass.

**Resolved** — all acceptance criteria met: 1. **One release command**: `scripts/release.sh --publish` performs build (make package), signing (rpmsign + gpg --clearsign), registry uploads (deb → bookworm/jammy/noble; rpm → fenris group), and creates a Gitea release entry with notes plus deb, rpm, and SHA256SUMS.asc attached 2. **Dry-run mode**: `scripts/release.sh --dry-run` prints every constructed command without executing; 32 structural tests assert the output without network or registry access 3. **Revision bumping**: same-version rebuilds detect HTTP 409 and increment the release number, producing new filenames that avoid registry collision 4. **Dormant CI workflow**: `.gitea/workflows/release.yml` extended with signing, upload, release creation, and artifact attachment; triggers on `v*` tags, queues harmlessly without a runner 5. **One-time live probe**: documented in `docs/install/signing-key-ceremony.md` — publish throwaway package, verify apt/dnf metadata and signature checks, then delete 6. **No bare tags**: release API creates the tag atomically with the release entry; no separate git push step Changes: scripts/release.sh (new), tests/test_release.py (new, 32 tests), Makefile (release-run/release-dry-run targets), .gitea/workflows/release.yml (full release flow), docs/install/signing-key-ceremony.md (live probe). Test results: 32/32 release tests pass, 369/369 full suite pass.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Reference: xavierk/Fenris#52