Both CLAUDE.md and README.md claimed there were deliberately no build or
push targets because the workflow owned publishing. That stopped being true
in 69fcc24, which moved publishing onto the Makefile so release.yaml could
call it — the docs described the arrangement that change replaced.
The claim was wrong in its reasoning too, not just out of date. It was
written on the assumption that riksdata and rd-web duplicated their
pipelines by having those targets. They never did: their workflows call
make and always have, which is what makes a green gate locally and a green
pipeline the same code instead of two descriptions of it. This repo was the
exception, for the single day it had a Makefile that nothing called.
Claude-Session: https://claude.ai/code/session_01S7R4gWTz5wh5xCY4nCSJjN
1.7 KiB
Release
Say "Release" (or "Release X.Y.Z") and the release skill runs it: commit, push, tag,
wait for the pipeline, then open the wrapper-chart PR against Ryuvia/charts. It stops
there — merging and the Flux reconcile stay manual, deliberately.
Preconditions and the plan, without side effects:
~/.claude/skills/release/scripts/release-preflight # state + suggested version
~/.claude/skills/release/scripts/release-preflight vX.Y.Z # validate that release
Config is .release.conf here plus make release-vars. The process itself lives in
~/.claude/skills/release/; why it is shaped this way is in README.md §Releasing.
Two things about this repo specifically:
- The pipeline has no image scan.
.gitea/workflows/release.yamlrunstest,binaries,imageandchart. A green release run is not evidence the image is CVE-clean, and a release note must not imply it is. - The wrapper chart has two
tag:lines — the app image and the python backup sidecar — sochart-bumpneeds--image "$IMAGE"to know which one moves.
Checks
make fmt lint test helm-lint is what the pipeline runs — ci.yaml and release.yaml
call these targets rather than restating them, the way riksdata and rd-web do. A green gate
here and a green pipeline are the same code, not two descriptions of it. test adds -race,
which the workflows do not have to ask for since they call the target; see the comment on it
for why.
make release (build + push the multi-arch image, package + push the chart) is what
release.yaml invokes. Do not run it by hand — it refuses VERSION=dev for that reason, and
publishing happens by pushing a tag.