Skip to content

Fix gem releases by separating build and publish jobs - #408

Open
ogajduse wants to merge 1 commit into
theforeman:masterfrom
ogajduse:feat/build-gem-before-publish
Open

ogajduse wants to merge 1 commit into
theforeman:masterfrom
ogajduse:feat/build-gem-before-publish

Conversation

@ogajduse

@ogajduse ogajduse commented Oct 2, 2026

Copy link
Copy Markdown
Member

Tag releases fail because gem build requires man/hammer.1.gz, which is generated and not tracked. Build the man page and gem in a read-only job, then transfer the gem to a separate job with RubyGems OIDC publishing permission. Check that the built gem's versioned filename matches the tag before uploading it.

Related upstream issue: voxpupuli/ruby-release#13

This follows the split-workflow approach discussed in voxpupuli/ruby-release#13 (comment) and needs no upstream action change. The workflow filename and release environment are unchanged. Documentation tooling is installed without recommendations to avoid unnecessary TeX dependencies; no application bundle is installed.

Validation:

  • actionlint 1.7.12 (including shellcheck) and git diff --check pass.
  • Clean Ubuntu 24.04 container builds succeeded for master, 5.0.1, and 3.19.1 using the direct build recipe. All gems contain the man page and 15 compiled locale files.
  • Correct version checks pass; mismatched tag/version checks fail.
  • Live GitHub artifact transfer and RubyGems OIDC/publication were not exercised. Container checks used Ubuntu Ruby 3.2.3; the workflow uses ruby/setup-ruby's latest Ruby.

Backport the workflow to 5.0-stable and 3.19-stable before future release tags. The latter also needs the unprefixed tag pattern. Existing tags are not moved or republished by this change.

id-token: write

steps:
- uses: voxpupuli/ruby-release@v0

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why can't we keep using the voxpupuli one as we use in all other repos? We need to fix the gemspec to make it work.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The gemspec lists man/hammer.1.gz because it needs to ship in the gem, but that file must be generated before gem build. Removing it would make the build pass while dropping the man page.

I raised this in voxpupuli/ruby-release#13, where ekohl suggested starting with a longer Hammer-specific workflow that separates building from publishing. This PR follows that approach, keeping build steps outside the job with publishing permissions. I prefer shared tooling too, but we’d need support for generated files or a prebuilt gem, not just a gemspec change.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants