From 065aa0dfd724c18b721710799241749e619deb26 Mon Sep 17 00:00:00 2001 From: Shiqiang Duan Date: Mon, 21 Sep 2026 16:49:38 +0800 Subject: [PATCH] ci: notify data-plane-infrastructure when a release is published MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sends a repository_dispatch so data-plane-infrastructure can open its BYOC onboarding wrapper bump PR straight away. That PR is what carries an onboarding change into the dev test accounts: the dev terragrunt units source their wrapper from the working tree, so bumping the wrapper's ?ref= changes what they resolve to, Atlantis plans them on the PR, and applying it deploys. The consuming workflow already polls on a weekday-morning schedule, so this is purely a latency improvement — a release is picked up within a minute rather than the next morning. Nothing depends on it succeeding; the release has already been published by auto-release.yaml by the time this runs. Triggered on release published rather than added as a job to auto-release.yaml, so hand-cut releases notify too. The README notes those are still supported for releases needing curated notes, and they should reach dev the same way. NOT YET FUNCTIONAL: WORKFLOW_AUTH_APP_ID and WORKFLOW_AUTH_PRIVATE_KEY are organization secrets that this repository cannot currently read, so the job will fail at the token step until someone with organization admin grants access. The consuming schedule is unaffected either way. The token action is pinned to a SHA rather than a tag, unlike the other actions here, because it mints a credential with write access to another repository. It is scoped to data-plane-infrastructure with permission-contents write, which is what the dispatch API requires and nothing more. --- .../workflows/notify-onboarding-release.yaml | 76 +++++++++++++++++++ 1 file changed, 76 insertions(+) create mode 100644 .github/workflows/notify-onboarding-release.yaml diff --git a/.github/workflows/notify-onboarding-release.yaml b/.github/workflows/notify-onboarding-release.yaml new file mode 100644 index 0000000..39b20ea --- /dev/null +++ b/.github/workflows/notify-onboarding-release.yaml @@ -0,0 +1,76 @@ +name: Notify onboarding release + +# Tells data-plane-infrastructure that a new release is out, so it can open its +# PR bumping the BYOC onboarding wrapper modules straight away. +# +# That PR is what carries an onboarding change into the dev test accounts: the dev +# terragrunt units source their wrapper from the working tree, so bumping the +# wrapper's ?ref= changes what they resolve to, Atlantis plans them on the PR, and +# applying it deploys. See .github/workflows/byoc-bump-onboarding-module.yaml in +# data-plane-infrastructure. +# +# That workflow also polls on a weekday-morning schedule, so this is purely a +# latency improvement — without it a release is picked up the next morning rather +# than within a minute. If this job fails the release is unaffected; it has already +# been published by auto-release.yaml at that point. +# +# Fires for hand-cut releases as well as automated ones, which is deliberate: the +# README notes that tagging by hand is still supported for releases needing curated +# notes, and those should reach dev the same way. +# +# PREREQUISITE: this needs WORKFLOW_AUTH_APP_ID and WORKFLOW_AUTH_PRIVATE_KEY to be +# readable from this repository. They are organization secrets today but are not +# shared with it, so until someone with organization admin grants access the job +# will fail at the token step. The consuming workflow's schedule keeps working +# regardless. + +on: + release: + types: [published] + +permissions: + contents: read + +concurrency: + group: notify-onboarding-release + cancel-in-progress: false + +env: + TARGET_REPO: ClickHouse/data-plane-infrastructure + +jobs: + dispatch: + name: Dispatch to data-plane-infrastructure + runs-on: ubuntu-latest + steps: + # Pinned to a SHA rather than a tag, unlike the other actions in this + # repository: this one mints a credential with write access to another + # repository, so it is worth not tracking a mutable tag. Same pin that + # data-plane-infrastructure already uses. + - name: Generate token + id: generate-token + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3 + with: + app-id: ${{ secrets.WORKFLOW_AUTH_APP_ID }} + private-key: ${{ secrets.WORKFLOW_AUTH_PRIVATE_KEY }} + owner: ${{ github.repository_owner }} + repositories: data-plane-infrastructure + # The repository dispatch API requires write access to Contents on the + # target repository; nothing else is needed. + permission-contents: write + + - name: Send repository dispatch + env: + GH_TOKEN: ${{ steps.generate-token.outputs.token }} + # Passed through the environment rather than interpolated into the script: + # a release name or tag is user-supplied, and `${{ }}` inside a run block + # is substituted before the shell sees it. + TAG: ${{ github.event.release.tag_name }} + RELEASE_URL: ${{ github.event.release.html_url }} + run: | + set -euo pipefail + echo "::notice::notifying ${TARGET_REPO} of release ${TAG}" + gh api --method POST "repos/${TARGET_REPO}/dispatches" \ + -f "event_type=byoc-onboarding-released" \ + -f "client_payload[tag]=${TAG}" \ + -f "client_payload[release_url]=${RELEASE_URL}"