Skip to content

ci: stop pushing :latest from main - #17

Merged
fylorn merged 1 commit into
mainfrom
dev
Sep 13, 2026
Merged

fylorn merged 1 commit into
mainfrom
dev

Conversation

@fylorn

@fylorn fylorn commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

think-watch-server:latest points at a main build rather than v1.0.2 — both workflows push :latest with no concurrency group, and the release lost the race.

:latest is now set only by release.yml. The :<sha> tags stay. Runbook gains a tag-ownership table.

Repointing the live tag is a separate step, after this lands.

🤖 Generated with Claude Code

`think-watch-server:latest` currently points at a `main` build rather
than v1.0.2. Both workflows push `:latest` and neither declares a
concurrency group, so cutting the release raced the `main` push that
carried it — same tag, two runs, last writer wins. CI's server manifest
finished after the release's, so it won. `think-watch-web:latest` is
correct only because CI's web job happened to be cancelled in that run,
which is the same race landing the other way.

None of this is visible from the Release page: every job in the release
run reports success, the version tags are right, and the chart is
attached. Only comparing digests shows it.

`:latest` asserts "the newest stable release". A branch push cannot know
whether its commit is that, so it must not set the tag that claims it.
Both `:latest` pushes are removed from `ci.yml`; the `:<sha>` tags stay,
which is how you deploy an unreleased `main` deliberately and can never
collide with a release.

A shared concurrency group was the other option and is worse: it makes
the two runs queue, so which one writes `:latest` last is still decided
by ordering rather than by meaning.

`docs/operations/release.md` gains a table of which workflow owns which
tag. The runbook already said `:latest` was for stable releases only —
that was true of the intent and false of the implementation, which is
the pairing that keeps a defect alive.

Repointing the live `:latest` is a separate step, done after this lands
so the merge's own CI run can't overwrite it again.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@fylorn
fylorn merged commit 35c4056 into main Sep 13, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant