Skip to content

fix(ci): build otdfctl release binaries with GOWORK=off - #4115

Merged
elizabethhealy merged 1 commit into
mainfrom
fix/otdfctl-release-gowork-off
Sep 28, 2026
Merged

elizabethhealy merged 1 commit into
mainfrom
fix/otdfctl-release-gowork-off

Conversation

@elizabethhealy

@elizabethhealy elizabethhealy commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Summary

release-otdfctl.yaml runs make build with the root go.work, so the published otdfctl binaries are compiled against the in-repo sdk/, protocol/go, lib/* instead of the versions pinned in otdfctl/go.mod.

That's inconsistent with:

  • the release-please PR check, which runs .github/scripts/work-init.sh to drop ./sdk from the workspace and validate against the pinned versions
  • what users get from go install github.com/opentdf/platform/otdfctl@vX

On release branches this can break a release after it's published: e.g. on release/otdfctl/v0.38, otdfctl pins sdk v0.33.0 (which includes #3945), but the in-tree sdk/ did not until #4114. The release-please check would pass while the post-publish binary build would fail to compile, leaving a release with no artifacts.

This sets GOWORK=off on the build step so binaries are built strictly from otdfctl/go.mod. setup-go still reads the Go version from go.work.

Test plan

  • actionlint passes
  • Locally: cd otdfctl && GOWORK=off make build succeeds on main
  • Next otdfctl/v* release uploads binaries successfully
  • Consider backporting to active release/otdfctl/* branches

Summary by CodeRabbit

  • Chores
    • Updated the release build to use dependencies specified for otdfctl.

The otdfctl release workflow ran `make build` with the root go.work, so
the binaries compiled against the in-repo sdk/ and service/ instead of
the versions pinned in otdfctl/go.mod. That doesn't match what
release-please validates (work-init.sh) or what `go install
github.com/opentdf/platform/otdfctl@vX` produces, and it can break a
release on a release branch whose in-repo sdk/ lags the pinned version.

Set GOWORK=off for the build step so the published binaries are built
strictly from otdfctl/go.mod.

Signed-off-by: Elizabeth Healy <35498075+elizabethhealy@users.noreply.github.com>

Co-authored-by: CoopAgent <coopagent@users.noreply.github.com>
@elizabethhealy
elizabethhealy requested review from a team as code owners September 28, 2026 17:55
@github-actions github-actions Bot added comp:ci Github Actions Work size/xs labels Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: a3e4e538-7667-4c34-9066-8fa4615fa85a

📥 Commits

Reviewing files that changed from the base of the PR and between 53af08e and 84fb10e.

📒 Files selected for processing (1)
  • .github/workflows/release-otdfctl.yaml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The release workflow sets GOWORK to off for the otdfctl build and adds comments about the intended module and dependency versions.

Changes

otdfctl Release Build

Layer / File(s) Summary
Go build configuration
.github/workflows/release-otdfctl.yaml
The build step sets GOWORK to off and adds comments about the intended module and dependency versions.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Bug fix

Suggested reviewers: dmihalcik-virtru

Merge Risk: ⚪ Minimal · up to 84fb1

The release build is configured to use otdfctl’s declared dependency versions, and no actionable merge blocker is evident in the supplied change context.

Architecture Summary

Architecture risk: 🔵 Low · up to 84fb1

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/release-otdfctl.yaml: The build step adds comments stating the intended module and dependency versions, and sets GOWORK to "off" so the build does not use the monorepo workspace.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: setting GOWORK=off for otdfctl release builds in CI.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the build at night,
With GOWORK off, the path is right.
The module notes are tucked in place,
The release hops along its trace.
Then carrots crunch beneath the moon.

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 279.567202ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 134.890136ms

Benchmark Statistics

Name № Requests Avg Duration Min Duration Max Duration

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 418.734119ms
Throughput 238.82 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 59.78474908s
Average Latency 596.270953ms
Throughput 83.63 requests/second

@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Govulncheck found vulnerabilities ⚠️

The following modules have known vulnerabilities:

  • otdfctl
  • service
  • tests-bdd

See the workflow run for details.

@elizabethhealy
elizabethhealy added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit e8a2f7f Sep 28, 2026
54 checks passed
@elizabethhealy
elizabethhealy deleted the fix/otdfctl-release-gowork-off branch September 28, 2026 18:34
@elizabethhealy elizabethhealy added the backport release/otdfctl/v0.38 Backport PR to release otdfctl/v0.38.0 label Sep 28, 2026
@elizabethhealy

Copy link
Copy Markdown
Member Author

/backport

@opentdf-automation

Copy link
Copy Markdown
Contributor

Successfully created backport PR for release/otdfctl/v0.38:

opentdf-automation Bot added a commit that referenced this pull request Sep 28, 2026
## Summary

`release-otdfctl.yaml` runs `make build` with the root `go.work`, so the
published otdfctl binaries are compiled against the **in-repo** `sdk/`,
`protocol/go`, `lib/*` instead of the versions pinned in
`otdfctl/go.mod`.

That's inconsistent with:
- the release-please PR check, which runs `.github/scripts/work-init.sh`
to drop `./sdk` from the workspace and validate against the pinned
versions
- what users get from `go install
github.com/opentdf/platform/otdfctl@vX`

On release branches this can break a release after it's published: e.g.
on `release/otdfctl/v0.38`, otdfctl pins `sdk v0.33.0` (which includes
#3945), but the in-tree `sdk/` did not until #4114. The release-please
check would pass while the post-publish binary build would fail to
compile, leaving a release with no artifacts.

This sets `GOWORK=off` on the build step so binaries are built strictly
from `otdfctl/go.mod`. `setup-go` still reads the Go version from
`go.work`.

## Test plan
- [ ] actionlint passes
- [ ] Locally: `cd otdfctl && GOWORK=off make build` succeeds on `main`
- [ ] Next `otdfctl/v*` release uploads binaries successfully
- [ ] Consider backporting to active `release/otdfctl/*` branches

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated the release build to use dependencies specified for `otdfctl`.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: CoopAgent <coopagent@users.noreply.github.com>
(cherry picked from commit e8a2f7f)
elizabethhealy pushed a commit that referenced this pull request Sep 28, 2026
…release/otdfctl/v0.38] (#4117)

# Description
Backport of #4115 to `release/otdfctl/v0.38`.

Co-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>
Co-authored-by: CoopAgent <coopagent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport release/otdfctl/v0.38 Backport PR to release otdfctl/v0.38.0 comp:ci Github Actions Work size/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants