Enhance release process: require new commits for publishing, improve local tag cleanup after successful pushes

This commit is contained in:
2026-09-28 10:58:13 +02:00
parent cb16c77bad
commit 651c6de392
3 changed files with 16 additions and 3 deletions
+2 -2
View File
@@ -10,10 +10,10 @@ Use this skill when asked to tag or publish a Faerro KB image. The release proce
## Procedure
1. Require a clean worktree and identify the exact committed `HEAD` being released. Staged, unstaged, or untracked changes must be committed or removed before running the script. Do not tag unrelated or unreviewed changes.
2. The script selects the next patch version by default. Use `--minor` or `--major` only when the user requests that increment; lower components are reset. Tags must be exact `MAJOR.MINOR.PATCH`.
2. The script requires at least one commit after the latest exact `MAJOR.MINOR.PATCH` tag, then selects the next patch version by default. Use `--minor` or `--major` only when the user requests that increment; lower components are reset.
3. The script creates an unused annotated local tag on the checked-out commit; do not push Git tags to a remote unless requested.
4. Confirm Docker is available. For non-interactive authentication, put `GITEA_USERNAME` and a package-write `GITEA_TOKEN` in the ignored `.env` file. The script parses only these keys and sends the token through Docker's `--password-stdin`; never put credentials in tracked files, command-line arguments, or chat. Without these settings it relies on Docker's existing login credentials.
5. Run `./scripts/publish-image.sh` from the repository. It builds, logs in when `.env` credentials are set, and pushes both the versioned tag and `latest`.
5. Run `./scripts/publish-image.sh` from the repository. It builds, logs in when `.env` credentials are set, and pushes both the versioned tag and `latest`. After both pushes succeed, it removes older local image tags for this repository, keeping the new version and `latest`; it does not delete packages from the registry.
6. Report the tagged commit, image tags, and actual build/push result. A successful local build is not a successful release if either registry push fails.
Do not force-move an existing tag, create or push Git tags to a remote unless requested, or claim publication succeeded without successful registry pushes.
+3 -1
View File
@@ -10,7 +10,7 @@ docker compose up --build
## Releases
Git tags are the source of truth for release versions. From the repository root, run the publish script to create the next patch tag and publish it:
Git tags are the source of truth for release versions. From the repository root, run the publish script to create the next patch tag and publish it. A release requires at least one commit after the latest version tag; repeated runs without new commits are rejected:
```sh
cp .env.example .env
@@ -20,6 +20,8 @@ cp .env.example .env
Pass `--minor` to increment the minor version and reset patch to zero, or `--major` to increment the major version and reset minor and patch to zero. The options cannot be combined. Run the script from a clean worktree: staged, unstaged, and untracked changes must be committed or removed first. It creates an annotated local Git tag on the checked-out commit, then publishes both the versioned image and `latest`. The commit does not need to be pushed before creating the local tag, but push the commit to the Git server first when it should be shared as part of the release; the script does not push Git tags. `.env` is excluded from Git; the script reads the Gitea credentials from it and passes the token to Docker through standard input. If those credentials are unset, the script uses Docker's existing login credentials.
After both pushes succeed, the script removes older local Docker tags for this image while keeping the newly published version and `latest`. This cleanup affects the local Docker image cache, not previously published packages in the Gitea registry.
Open `http://localhost` for a desktop smoke test. Set `HTTP_PORT` to publish the app on a different host port (for example, `HTTP_PORT=8000 docker compose up`). For iPhone use, serve the app over HTTPS through your VPN/reverse proxy. iOS only grants microphone access in a secure context. Keep the service reachable only through your VPN and firewall; this first version has no login layer.
In Safari on iPhone, open the HTTPS address and use **Share > Add to Home Screen**. Sign in to the VPN before opening the app if the server is only reachable there.
+11
View File
@@ -50,6 +50,12 @@ if [[ -z "$latest_version" ]]; then
exit 1
fi
commits_since_release="$(git -C "$repo_root" rev-list --count "$latest_version..HEAD")"
if [[ "$commits_since_release" -eq 0 ]]; then
echo "No new commits since Git tag $latest_version; nothing to publish." >&2
exit 1
fi
IFS=. read -r major minor patch <<< "$latest_version"
case "$bump" in
major)
@@ -105,4 +111,9 @@ fi
docker push "$image:$version"
docker push "$image:latest"
while IFS= read -r local_image; do
[[ -z "$local_image" || "$local_image" == "$image:$version" || "$local_image" == "$image:latest" ]] && continue
docker image rm "$local_image"
done < <(docker image ls --format '{{.Repository}}:{{.Tag}}' "$image")
echo "Published $image:$version and $image:latest"