Found while preparing the tenant-registry enforcement flip: the deployment is frozen on an Aug-06 image even though five RBAC merges are on main.
The job never ran: job-level hashFiles('Dockerfile') evaluates before checkout against an empty workspace — always empty string, condition always false, silently skipped on every main push.
It wouldn't have deployed anyway: it tagged only sha-* and env-stage; orca deploys :latest, which nothing updated.
The deploy step targeted a stage env this cluster does not have (orca apply --env=stage, leftover from the abandoned #11 retarget).
Fix: condition without hashFiles, :latest tagged alongside sha-*, and the HMAC-signed orca webhook the other repos use. Webhook is registered on the master and ORCA_WEBHOOK_SECRET is set as a repo Actions secret.
This unblocks deploying the Phase-1 code (memberships endpoint + the service's own auth gate) — prerequisite for the enforcement flip.
Found while preparing the tenant-registry enforcement flip: the deployment is frozen on an Aug-06 image even though five RBAC merges are on main.
1. **The job never ran**: job-level `hashFiles('Dockerfile')` evaluates before checkout against an empty workspace — always empty string, condition always false, silently skipped on every main push.
2. **It wouldn't have deployed anyway**: it tagged only `sha-*` and `env-stage`; orca deploys `:latest`, which nothing updated.
3. **The deploy step targeted a stage env this cluster does not have** (`orca apply --env=stage`, leftover from the abandoned #11 retarget).
Fix: condition without hashFiles, `:latest` tagged alongside `sha-*`, and the HMAC-signed orca webhook the other repos use. Webhook is registered on the master and ORCA_WEBHOOK_SECRET is set as a repo Actions secret.
This unblocks deploying the Phase-1 code (memberships endpoint + the service's own auth gate) — prerequisite for the enforcement flip.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Three defects left the deployment frozen on an Aug-06 image while five
RBAC merges landed on main:
1. The job-level `hashFiles('Dockerfile')` condition evaluates BEFORE
checkout, against an empty workspace — always '', so the job was
silently skipped on every push to main.
2. Had it run, it pushed only sha-* and env-stage tags; orca deploys
:latest, which nothing ever updated.
3. The final step ran `orca apply --env=stage` against a stage
environment this cluster does not have.
Now: condition without hashFiles (the Dockerfile is not optional),
:latest tagged alongside sha-*, and the deploy step replaced with the
HMAC-signed orca webhook the other repos use (registered on the master;
ORCA_WEBHOOK_SECRET set as a repo Actions secret).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
sharang
merged commit 583d8f8f25 into main2026-08-30 21:10:34 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found while preparing the tenant-registry enforcement flip: the deployment is frozen on an Aug-06 image even though five RBAC merges are on main.
hashFiles('Dockerfile')evaluates before checkout against an empty workspace — always empty string, condition always false, silently skipped on every main push.sha-*andenv-stage; orca deploys:latest, which nothing updated.orca apply --env=stage, leftover from the abandoned #11 retarget).Fix: condition without hashFiles,
:latesttagged alongsidesha-*, and the HMAC-signed orca webhook the other repos use. Webhook is registered on the master and ORCA_WEBHOOK_SECRET is set as a repo Actions secret.This unblocks deploying the Phase-1 code (memberships endpoint + the service's own auth gate) — prerequisite for the enforcement flip.
🤖 Generated with Claude Code
Three defects left the deployment frozen on an Aug-06 image while five RBAC merges landed on main: 1. The job-level `hashFiles('Dockerfile')` condition evaluates BEFORE checkout, against an empty workspace — always '', so the job was silently skipped on every push to main. 2. Had it run, it pushed only sha-* and env-stage tags; orca deploys :latest, which nothing ever updated. 3. The final step ran `orca apply --env=stage` against a stage environment this cluster does not have. Now: condition without hashFiles (the Dockerfile is not optional), :latest tagged alongside sha-*, and the deploy step replaced with the HMAC-signed orca webhook the other repos use (registered on the master; ORCA_WEBHOOK_SECRET set as a repo Actions secret). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>