Repository navigation
fix(ci): deploy merged pull request images on push to main - #669
Merged
Merged
Conversation
Merge to Main ran after every Pull Request Closed run, so closing a pull request without merging it still deployed TEST and PROD and cut a release. It also promoted whatever the latest tag held at the time. It now runs on push to main, looks up the merged pull request like quickstart-openshift, and promotes that pull request's images, which were built and tested on it. Refs #597
There was a problem hiding this comment.
🟡 Changes recommended
Manual dispatch can promote an open PR branch’s images to production instead of the latest merged PR.
1 open finding
What changed in this PR
Updates deployment promotion to use images from the PR merged into main, avoiding deployments caused by unmerged PR closures.
Changes:
- Triggers deployment on pushes to
main. - Resolves the associated PR number.
- Retags that PR’s images with release versions.
| File | Description |
|---|---|
.github/workflows/merge.yml |
Changes the deployment trigger and image promotion source. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
A manual run from another branch would have promoted that branch's pull request images, and versioning ran in parallel with the lookup. Initialization now requires main and versioning waits for it. Refs #597
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Closing a pull request without merging it deploys TEST and PROD:
merge.ymlruns after everyPull Request Closedrun, merged or not. For example, closing Renovate PR #634 unmerged on Sep 12 started run 34704659263, which deployed PROD and cut a release.Refs #597
Problems in the current workflow
workflow_runonPull Request Closedfires for every closed PR. Its conclusion and branch are never checked.merge.ymlpromotes whatever thelatesttag holds. That tag is set byPull Request Closedin a separate run, so two merges close together can deploy the wrong PR's images.continue-on-error, so a failed release still shows green.Changes (quickstart-openshift deploy pattern)
pushtomain(plusworkflow_dispatch) instead ofworkflow_run. There are nopathsfilters. Closing a PR without merging no longer deploys anything.initjob usesbcgov/action-get-prv0.3.1 to find the PR that was squash-merged.ghcr.io/bcgov/pubcode/<package>:<PR number>, which PR builds already publish. The Helm chart tag and image tags use the PR number.retag-imagesis removed. Images are no longer re-tagged with versions.promotetags the PR's imagesprod, the chart's default tag, as quickstart-openshift does.semantic-versionstill works out the next version with conventional-changelog, but no longer pushes anything (git-push: "false", read-only permissions). It reads history at the merge commit instead of pulling main.Create Releasemakes the git tag and GitHub release on the merge commit (github.sha). If a deploy or the tests fail, no tag or release is created.continue-on-erroris removed from the release step, so a failed release fails the run.workflow_dispatchonly works frommain, where it redeploys the latest merged PR's images through TEST then PROD and cuts a release. It never builds.Job order
init→TEST Deployments→Tests→PROD Deployments→Promote ImagesandCreate Release.Semantic Versionruns alongside the deploys and feedsCreate Release.Not covered here
actionlintpasses on it. Watch the firstMerge to Mainrun after this lands.Thanks for the PR!
Deployments, as required, will be available below:
Please create PRs in draft mode. Mark as ready to enable:
After merge, new images are deployed in: