Skip to content

ci(release): create release tags with a deploy key - #52

Merged
jo16oh merged 1 commit into
mainfrom
ci/release-tag-deploy-key
Sep 24, 2026
Merged

jo16oh merged 1 commit into
mainfrom
ci/release-tag-deploy-key

Conversation

@jo16oh

@jo16oh jo16oh commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

The next release fails at the tag job. The release-tags ruleset blocks tag creation for GITHUB_TOKEN, and adding GitHub Actions as a bypass actor fails on a personal repository with:

422 Actor GitHub Actions integration must be part of the ruleset source or owner organization
  • Push v* and zed-v* tags over SSH with a deploy key, the ruleset's only bypass actor
  • Keep the key as RELEASE_TAG_KEY in the release environment, limited to main
  • Load the key into an ssh-agent that ends with the step, so it is never written to disk
  • Drop contents: write from both tag jobs

The deploy key, the environment and the ruleset bypass are already set up, and admins no longer bypass the ruleset. The SSH push has not run yet; the first release tests it.

- Only deploy keys bypass the `release-tags` ruleset, because a personal repository cannot list GitHub Actions as a bypass actor
- Key in the `release` environment (main only), loaded into an ssh-agent for the tag step alone
@jo16oh
jo16oh force-pushed the ci/release-tag-deploy-key branch from 539af1e to 31d8722 Compare September 24, 2026 11:56
@jo16oh
jo16oh merged commit 0c64abd into main Sep 24, 2026
9 checks passed
@jo16oh
jo16oh deleted the ci/release-tag-deploy-key branch September 25, 2026 00:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant