Skip to content

ci: fail clearly when the release deploy key is missing - #100

Merged
plumppig merged 1 commit into
masterfrom
fix/release-deploy-key-check
Oct 10, 2026
Merged

plumppig merged 1 commit into
masterfrom
fix/release-deploy-key-check

Conversation

@plumppig

Copy link
Copy Markdown
Contributor

With no RELEASE_DEPLOY_KEY secret, actions/checkout quietly falls back to the read-only workflow token. A dry run then passed, and a real run only failed at the very end of the push job with a bare 403 (seen on the first run after #97 merged).

The push job now starts by failing if the secret is empty, and asserts that checkout used an SSH remote. push-release.sh turns a rejected push into a message that names the likely causes: a missing or read-only deploy key, or rulesets that deploy keys cannot bypass. RELEASING.md describes what a green dry run does and does not prove, and lists the three failure messages.

With no RELEASE_DEPLOY_KEY secret, actions/checkout quietly falls back to the
read-only workflow token. A dry run then passed, and a real run only failed at
the very end of the push job with a bare 403 (seen on the first run after
#97 merged).

The push job now starts by failing if the secret is empty, and asserts that
checkout used an SSH remote. push-release.sh turns a rejected push into a
message that names the likely causes: a missing or read-only deploy key, or
rulesets that deploy keys cannot bypass. RELEASING.md describes what a green
dry run does and does not prove, and lists the three failure messages.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@plumppig
plumppig merged commit b36a37f into master Oct 10, 2026
2 of 5 checks passed
@plumppig
plumppig deleted the fix/release-deploy-key-check branch October 10, 2026 05:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant