ci: the image job never ran — fix condition, tag :latest, deploy for real #16

Merged
sharang merged 1 commits from fix/ci-image-deploy into main 2026-08-30 21:10:34 +00:00
Owner

Found while preparing the tenant-registry enforcement flip: the deployment is frozen on an Aug-06 image even though five RBAC merges are on main.

  1. The job never ran: job-level hashFiles('Dockerfile') evaluates before checkout against an empty workspace — always empty string, condition always false, silently skipped on every main push.
  2. It wouldn't have deployed anyway: it tagged only sha-* and env-stage; orca deploys :latest, which nothing updated.
  3. The deploy step targeted a stage env this cluster does not have (orca apply --env=stage, leftover from the abandoned #11 retarget).

Fix: condition without hashFiles, :latest tagged alongside sha-*, and the HMAC-signed orca webhook the other repos use. Webhook is registered on the master and ORCA_WEBHOOK_SECRET is set as a repo Actions secret.

This unblocks deploying the Phase-1 code (memberships endpoint + the service's own auth gate) — prerequisite for the enforcement flip.

🤖 Generated with Claude Code

Found while preparing the tenant-registry enforcement flip: the deployment is frozen on an Aug-06 image even though five RBAC merges are on main. 1. **The job never ran**: job-level `hashFiles('Dockerfile')` evaluates before checkout against an empty workspace — always empty string, condition always false, silently skipped on every main push. 2. **It wouldn't have deployed anyway**: it tagged only `sha-*` and `env-stage`; orca deploys `:latest`, which nothing updated. 3. **The deploy step targeted a stage env this cluster does not have** (`orca apply --env=stage`, leftover from the abandoned #11 retarget). Fix: condition without hashFiles, `:latest` tagged alongside `sha-*`, and the HMAC-signed orca webhook the other repos use. Webhook is registered on the master and ORCA_WEBHOOK_SECRET is set as a repo Actions secret. This unblocks deploying the Phase-1 code (memberships endpoint + the service's own auth gate) — prerequisite for the enforcement flip. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
sharang added 1 commit 2026-08-30 21:10:19 +00:00
ci: the image job never ran — fix its condition, tag :latest, deploy for real
ci / shared (pull_request) Failing after 4s
ci / test (pull_request) Successful in 21m22s
ci / image (pull_request) Skipped
fa07b3bae0
Three defects left the deployment frozen on an Aug-06 image while five
RBAC merges landed on main:

1. The job-level `hashFiles('Dockerfile')` condition evaluates BEFORE
   checkout, against an empty workspace — always '', so the job was
   silently skipped on every push to main.
2. Had it run, it pushed only sha-* and env-stage tags; orca deploys
   :latest, which nothing ever updated.
3. The final step ran `orca apply --env=stage` against a stage
   environment this cluster does not have.

Now: condition without hashFiles (the Dockerfile is not optional),
:latest tagged alongside sha-*, and the deploy step replaced with the
HMAC-signed orca webhook the other repos use (registered on the master;
ORCA_WEBHOOK_SECRET set as a repo Actions secret).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
sharang merged commit 583d8f8f25 into main 2026-08-30 21:10:34 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: platform/tenant-registry#16