Skip to content

fix(ci): restore packages:write for release image push - #2155

Merged
msardara merged 3 commits into
mainfrom
fix/ci-release-images-packages-write
Oct 1, 2026
Merged

msardara merged 3 commits into
mainfrom
fix/ci-release-images-packages-write

Conversation

@msardara

@msardara msardara commented Oct 1, 2026

Copy link
Copy Markdown
Member

Summary

  • reusable-docker-build-push.yaml added a top-level permissions: contents: read block in fix(security): address code scanning alerts #2032 (Scorecard fix for missing explicit permissions).
  • Reusable workflows that declare their own permissions: block no longer inherit the caller's job-level grants for unlisted scopes — they get none. Since the caller (release-images.yaml) grants packages: write, but the reusable workflow only listed contents: read, that write permission was silently dropped.
  • This broke GHCR pushes for release image builds (slim-v3.0.1 run: https://github.com/agntcy/slim/actions/runs/36715071461) with denied: installation not allowed to Write organization package, even though release-images.yaml itself was never changed.
  • Fix: add packages: write to the reusable workflow's top-level permissions block so the grant actually reaches the push step.

Test plan

  • Re-run (or push a new slim-* tag) to confirm ci-release-images pushes successfully to ghcr.io/agntcy/slim

reusable-docker-build-push.yaml gained a top-level permissions block
in 8d8851c (Scorecard fix) that only grants contents: read. Reusable
workflows do not inherit the caller's job-level permissions once they
declare their own block, so packages: write from release-images.yaml
is silently dropped, and GHCR push fails with "denied: installation
not allowed to Write organization package".

Signed-off-by: Mauro Sardara <msardara@cisco.com>
@msardara
msardara requested a review from a team as a code owner October 1, 2026 08:00
muscariello
muscariello previously approved these changes Oct 1, 2026

@muscariello muscariello left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@msardara
msardara enabled auto-merge October 1, 2026 08:12
reusable-docker-build-push.yaml now requests packages: write
unconditionally. ci.yaml's docker-build job called it without any
packages grant, so GitHub's static reusable-workflow permission check
rejected the workflow even though this call path never pushes
(push only runs on tag refs).

Signed-off-by: Mauro Sardara <msardara@cisco.com>

@muscariello muscariello left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@msardara
msardara added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit 66ae71f Oct 1, 2026
17 checks passed
@msardara
msardara deleted the fix/ci-release-images-packages-write branch October 1, 2026 19:45
muscariello added a commit to muscariello/slim that referenced this pull request Oct 5, 2026
The slim-v3.0.0 and slim-v3.0.1 image pushes failed because agntcy#2032 gave
the reusable build workflow a top-level permissions block that dropped
packages: write. agntcy#2155 restored the grant, but nothing stops the same
mistake from coming back, and the failure went unnoticed for days.

- reusable-docker-build-push: push and ref are explicit inputs instead
  of being inferred from the triggering event; grants move to the job;
  pushed tags are read back from the registry after the push.
- release-images: add workflow_dispatch to rebuild an existing tag with
  the current workflow (re-running a tag run reuses the broken one);
  latest is opt-in for manual rebuilds; open an issue when a release
  image build fails; drop the unused attestations: write grant.
- lint-workflows: add a check that fails when a reusable workflow drops
  a write scope its caller grants. It flags the pre-agntcy#2155 tree.

Signed-off-by: Luca Muscariello <muscariello@ieee.org>
muscariello added a commit to muscariello/slim that referenced this pull request Oct 5, 2026
The slim-v3.0.0 and slim-v3.0.1 image pushes failed with "installation
not allowed to Write organization package". agntcy#2032 added a top-level
`permissions: contents: read` to the reusable build workflow, and for a
reusable workflow that block is the whole list: `packages: write` from
the caller became none. agntcy#2155 put the grant back, but the shape that
invited the mistake was still there, and nothing exercised the push path
between releases, so the breakage surfaced weeks later at release time.

- reusable-docker-build-push: keep the top-level block empty and put the
  grants on the job, next to the steps that need them. Take the token
  from `github.token` -- a reusable workflow already gets GITHUB_TOKEN
  with the caller job's grants -- instead of passing it as a secret, and
  drop that input. `push` and `ref` become explicit inputs rather than
  being inferred from the triggering event. Read every pushed tag back
  from the registry, so a green run means pullable images.
- ci: push the `main` tag on merges to main. The same
  login-build-push-verify path a release takes now runs on every merge,
  on a moving tag that does not accumulate, so a broken grant fails on
  the commit that caused it. This also covers the gap that ci never
  passed `github-token`, so its login would have failed on first push.
- release-images: add workflow_dispatch to rebuild an existing tag with
  the current workflow, since re-running a tag run replays the workflow
  as it was at the tag. `latest` is opt-in for those manual rebuilds.
  Open an issue when a release image build fails. Drop the unused
  `attestations: write` grant.

Signed-off-by: Luca Muscariello <muscariello@ieee.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants