Skip to content

fix(ci): deploy merged pull request images on push to main - #669

Merged
DerekRoberts merged 4 commits into
mainfrom
fix/merge-deploy-merged-prs
Oct 11, 2026
Merged

DerekRoberts merged 4 commits into
mainfrom
fix/merge-deploy-merged-prs

Conversation

@DerekRoberts

@DerekRoberts DerekRoberts commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Closing a pull request without merging it deploys TEST and PROD: merge.yml runs after every Pull Request Closed run, merged or not. For example, closing Renovate PR #634 unmerged on Sep 12 started run 34704659263, which deployed PROD and cut a release.

Refs #597

Problems in the current workflow

  • workflow_run on Pull Request Closed fires for every closed PR. Its conclusion and branch are never checked.
  • merge.yml promotes whatever the latest tag holds. That tag is set by Pull Request Closed in a separate run, so two merges close together can deploy the wrong PR's images.
  • The version tag is pushed before TEST and PROD deploy, so a failed deploy leaves a tag with no release behind.
  • The release step has continue-on-error, so a failed release still shows green.

Changes (quickstart-openshift deploy pattern)

  • Triggers on push to main (plus workflow_dispatch) instead of workflow_run. There are no paths filters. Closing a PR without merging no longer deploys anything.
  • A new init job uses bcgov/action-get-pr v0.3.1 to find the PR that was squash-merged.
  • TEST, Cypress on TEST, then PROD deploy that PR's own images, ghcr.io/bcgov/pubcode/<package>:<PR number>, which PR builds already publish. The Helm chart tag and image tags use the PR number.
  • retag-images is removed. Images are no longer re-tagged with versions.
  • After PROD succeeds, promote tags the PR's images prod, the chart's default tag, as quickstart-openshift does.
  • semantic-version still works out the next version with conventional-changelog, but no longer pushes anything (git-push: "false", read-only permissions). It reads history at the merge commit instead of pulling main.
  • Releases are now created only after PROD succeeds. Create Release makes the git tag and GitHub release on the merge commit (github.sha). If a deploy or the tests fail, no tag or release is created.
  • continue-on-error is removed from the release step, so a failed release fails the run.
  • Unchanged: a version and GitHub release for every merge, with the same changelog notes.
  • workflow_dispatch only works from main, where it redeploys the latest merged PR's images through TEST then PROD and cuts a release. It never builds.

Job order

init → TEST Deployments → Tests → PROD Deployments → Promote Images and Create Release. Semantic Version runs alongside the deploys and feeds Create Release.

Not covered here

  • Digest verification: promotion is by tag, as in quickstart-openshift. A PR's tag is final once the PR merges, since nothing pushes to a merged PR.
  • Verification: this workflow only runs after merge. actionlint passes on it. Watch the first Merge to Main run after this lands.

Thanks for the PR!

Deployments, as required, will be available below:

Please create PRs in draft mode. Mark as ready to enable:

After merge, new images are deployed in:

Merge to Main ran after every Pull Request Closed run, so closing a pull request without merging it still deployed TEST and PROD and cut a release. It also promoted whatever the latest tag held at the time. It now runs on push to main, looks up the merged pull request like quickstart-openshift, and promotes that pull request's images, which were built and tested on it.

Refs #597
Copilot AI balanced review requested due to automatic review settings October 9, 2026 23:11
@DerekRoberts DerekRoberts self-assigned this Oct 9, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Manual dispatch can promote an open PR branch’s images to production instead of the latest merged PR.

1 open finding
What changed in this PR

Updates deployment promotion to use images from the PR merged into main, avoiding deployments caused by unmerged PR closures.

Changes:

  • Triggers deployment on pushes to main.
  • Resolves the associated PR number.
  • Retags that PR’s images with release versions.
File Description
.github/​workflows/​merge.yml Changes the deployment trigger and image promotion source.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/merge.yml
A manual run from another branch would have promoted that branch's pull request images, and versioning ran in parallel with the lookup. Initialization now requires main and versioning waits for it.

Refs #597
@DerekRoberts DerekRoberts mentioned this pull request Oct 9, 2026
3 of 8 tasks
@DerekRoberts
DerekRoberts merged commit ef42308 into main Oct 11, 2026
21 checks passed
@DerekRoberts
DerekRoberts deleted the fix/merge-deploy-merged-prs branch October 11, 2026 03:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants