Skip to content

ci: make the release a reconciler, not a trigger - #17

Merged
github-actions[bot] merged 1 commit into
mainfrom
ci/release-reconciler
Aug 16, 2026
Merged

ci: make the release a reconciler, not a trigger#17
github-actions[bot] merged 1 commit into
mainfrom
ci/release-reconciler

Conversation

@catomean

Copy link
Copy Markdown
Collaborator

The self-releasing workflow I merged an hour ago would not have released anything, and the proof is in this repo: #16 merged to main and no publish run started. threadkit's identical change did fire — because I merged that one by hand with a user token.

auto-merge merges with GITHUB_TOKEN, and a push made with that token starts no workflow. So on: push: branches: [main] silently doesn't fire for exactly the merges that matter. This is the no-cascade rule already documented in CLAUDE.md, and I walked into it while writing the thing meant to remove manual steps.

Two fixes — one is a promise, one is a mechanism

The promise: auto-merge.yml carries REARM_WORKFLOWS, whose own comment says "keep this in sync when a push-triggered workflow is added". I added one and didn't. Now listed.

The mechanism: publish.yml gains an hourly schedule. The question it asks — is package.json's version on the registry? — is idempotent, so asking it on a timer costs one npm view when there's nothing to do, and repairs a missed release when there is.

A hand-maintained list of workflows to re-arm is something to keep correct forever. A reconciler is correct by construction.

This matches how deploys already work in the fleet: compare desired against actual and act on the difference, rather than trusting an event to arrive.

🤖 Generated with Claude Code

The self-releasing workflow I merged an hour ago would not have released
anything, and the proof is in this repo: #16 merged to main and no publish run
started. threadkit's identical change did fire — because I merged that one by
hand with a user token.

auto-merge merges with GITHUB_TOKEN, and a push made with that token starts no
workflow. So `on: push: branches: [main]` silently does not fire for exactly the
merges that matter here. This is the no-cascade rule already documented in
CLAUDE.md, and I walked into it while writing the thing meant to remove manual
steps.

Two fixes, because one of them is a promise and the other is a mechanism:

- auto-merge.yml carries REARM_WORKFLOWS, whose comment says "keep this in sync
  when a push-triggered workflow is added". I added one and did not. Now listed.
- More importantly: publish.yml gains an hourly schedule. The question it asks —
  "is package.json's version on the registry?" — is idempotent, so asking it on a
  timer costs one `npm view` when there is nothing to do and repairs a missed
  release when there is. A hand-maintained list of workflows to re-arm is
  something to keep correct forever; a reconciler is correct by construction.

This matches how deploys already work in the fleet: compare desired against
actual and act on the difference, rather than trusting an event to arrive.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-actions
github-actions Bot merged commit a80a5a0 into main Aug 16, 2026
1 check passed
@github-actions
github-actions Bot deleted the ci/release-reconciler branch August 16, 2026 16:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant