Skip to content

ci(docker): allow a manual rebuild via workflow_dispatch - #129

Merged
MrChengLen merged 1 commit into
mainfrom
ci/docker-manual-trigger
Sep 14, 2026
Merged

MrChengLen merged 1 commit into
mainfrom
ci/docker-manual-trigger

Conversation

@MrChengLen

@MrChengLen MrChengLen commented Sep 14, 2026

Copy link
Copy Markdown
Owner

Warum

Docker lief bisher nur bei einem Push auf main oder einem Versions-Tag. main ist durch Pflicht-Checks geschützt — ein Image zu bauen (und damit notify-ops und den Deploy dahinter zu erreichen) setzte also immer einen Pull Request voraus, selbst wenn am Code nichts zu ändern war.

Genau diese Lücke war letzte Woche das Problem: Die Zugangsdaten, die notify-ops verwendet, waren am 20.08. abgelaufen; der Workflow scheiterte danach bei jedem Lauf mit HTTP 401, und drei Wochen lang erreichte kein Deploy die Produktion. Nach dem Ersetzen des Tokens gab es keine Möglichkeit, die neue Berechtigung zu prüfen oder den aktuellen main-Stand neu auszurollen, ohne eine Code-Änderung zu erfinden. Ein leerer Commit wird von den Branch-Regeln zurückgewiesen — korrekt so, und nichts, was man umgehen sollte.

workflow_dispatch baut aus dem, was gerade auf main liegt, und durchläuft die ganze Kette: bauen, pushen, signieren, benachrichtigen, deployen. Das ist auch das, was man im Störungsfall braucht, wo die Frage meist „den Stand von main neu ausrollen" lautet und nicht „eine Änderung ausliefern".

Was sich sonst ändert

Nichts. Build, Matrix, Signierung und Permissions bleiben unangetastet; die Supply-Chain-Guards des Repos greifen weiterhin (SHA-gepinnte Actions, expliziter permissions-Block) — tests/test_supply_chain_hygiene.py läuft grün durch.

Nach dem Merge

Der Merge selbst ist zugleich der erste Test des neuen Tokens: Er pusht auf main, also baut docker.yml und notify-ops.yml feuert. Ist der Lauf grün, ist die Kette nachweislich wieder intakt. Danach steht der Knopf unter Actions → Docker → Run workflow dauerhaft zur Verfügung.

🤖 Generated with Claude Code


Nachtrag: Die erste Fassung nannte das Secret beim Namen und wurde vom scope-check blockiert — korrekt, der Name gehört ausschließlich in notify-ops.yml, die dafür auf der Allowlist steht. Der Kommentar beschreibt den Vorfall jetzt ohne ihn.

Docker only ran on a push to main or a version tag. main is protected by
required status checks, so producing an image -- and reaching notify-ops and
the deploy behind it -- always meant opening a pull request, even when nothing
about the code needed to change.

That gap cost three weeks in September 2026: the credential notify-ops uses had
expired, it failed with HTTP 401 on every run, and no deploy reached production.
Once the credential was replaced there was no way to prove it worked, or to
redeploy the current main, without inventing a code change to push. An empty
commit is rejected by the branch rules, which is correct and not something to
work around.

workflow_dispatch rebuilds from whatever main currently holds and runs the whole
chain: build, push, sign, notify, deploy. That is also what is wanted during an
incident, where the question is usually "redeploy what is on main" rather than
"ship a change".

Nothing else moves. The build, the matrix, the signing and the permissions are
untouched, and the repo's supply-chain guards still pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@MrChengLen
MrChengLen force-pushed the ci/docker-manual-trigger branch from e6f0d46 to f72dedc Compare September 14, 2026 17:20
@MrChengLen
MrChengLen merged commit 8184715 into main Sep 14, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant