Give the SDK job the pulumi CLI it has always needed
build / build (push) Successful in 14m12s

The v0.2.0 plugin binaries published, then the SDK job died in tfgen:

    panic: fatal: error An assertion has failed: bulk converting examples
    failed. convertViaPulumiCLI: pulumi executable not in PATH

tfgen converts the upstream provider's documentation examples into each
language by shelling out to `pulumi convert`, and asserts rather than degrades
when the binary is missing. The build workflow installs the CLI; this job never
did. It went unnoticed through v0.1.0 because tfgen had no docs to convert
until UpstreamRepoPath pointed it at the upstream checkout.

So half a release is published and the other half is not, and re-pushing the
tag would rerun a 45 minute build against artifacts that are already uploaded.
Let a dispatch republish just the SDKs instead: it takes the tag to publish,
skips the plugin job, and checks the tree out at that tag while the workflow
file itself comes from the branch it was dispatched on.
This commit is contained in:
max-voitcov
2026-08-26 02:52:02 +03:00
parent 5e9b1ea663
commit 381c928342
+29 -6
View File
@@ -3,12 +3,17 @@ name: release
on:
push:
tags: ["v*.*.*"]
# A release that dies halfway -- the runner OOMs, the host reboots -- leaves
# the tag pushed and nothing published, and re-pushing a tag to retry it is
# both awkward and destructive. Dispatch re-runs the same release instead.
# goreleaser refuses to run unless the checked-out commit is itself tagged,
# so this can only ever republish a real tag, never main-in-progress.
workflow_dispatch: {}
# A release that dies halfway -- the runner OOMs, the host reboots, a job is
# missing a tool -- leaves the tag pushed and only part of the release
# published, and re-pushing a tag to retry it is both awkward and
# destructive. Dispatch republishes the SDKs for a tag that already has its
# plugin binaries, which is the half that fails: the plugin job is a 45
# minute build that either produced its artifacts or did not.
workflow_dispatch:
inputs:
tag:
description: Tag to publish the SDKs for, e.g. v0.2.0
required: true
env:
GO_VERSION: "1.25.x"
@@ -27,6 +32,11 @@ jobs:
# PluginDownloadURL baked into the schema, so this has to land before anyone
# installs an SDK.
plugin:
# Only on a tag push. A dispatch is for republishing SDKs against a tag
# whose binaries are already uploaded, and goreleaser would collide with
# them. To rebuild the binaries themselves, delete the release and
# re-push the tag.
if: github.event_name == 'push'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
@@ -67,11 +77,17 @@ jobs:
sdks:
needs: plugin
# `always()` so a dispatch, where plugin is skipped rather than run, still
# gets here -- but not past a plugin job that actually failed.
if: always() && needs.plugin.result != 'failure' && needs.plugin.result != 'cancelled'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
path: pulumi-dokploy
# The workflow file comes from the dispatched branch; the tree to
# publish comes from the tag. On a push the two are the same thing.
ref: ${{ inputs.tag || github.ref }}
# Needed for the tag lookup below.
fetch-depth: 0
@@ -100,6 +116,13 @@ jobs:
with:
dotnet-version: ${{ env.DOTNET_VERSION }}
# tfgen converts the upstream provider's documentation examples into
# each language by shelling out to `pulumi convert`, and asserts rather
# than degrades when the binary is absent: "pulumi executable not in
# PATH". It only started mattering once UpstreamRepoPath gave tfgen
# docs to find, which is why v0.1.0 published without this.
- uses: pulumi/actions@v6
# On a tag push the ref name is the tag; on a dispatch it is the branch,
# so ask git what tag this commit carries. --exact-match keeps a dispatch
# from quietly publishing an untagged commit under the previous version.