Repository navigation
fix(ci): build otdfctl release binaries with GOWORK=off - #4115
Conversation
The otdfctl release workflow ran `make build` with the root go.work, so the binaries compiled against the in-repo sdk/ and service/ instead of the versions pinned in otdfctl/go.mod. That doesn't match what release-please validates (work-init.sh) or what `go install github.com/opentdf/platform/otdfctl@vX` produces, and it can break a release on a release branch whose in-repo sdk/ lags the pinned version. Set GOWORK=off for the build step so the published binaries are built strictly from otdfctl/go.mod. Signed-off-by: Elizabeth Healy <35498075+elizabethhealy@users.noreply.github.com> Co-authored-by: CoopAgent <coopagent@users.noreply.github.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe release workflow sets Changesotdfctl Release Build
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The release build is configured to use otdfctl’s declared dependency versions, and no actionable merge blocker is evident in the supplied change context. Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the build at night, Comment |
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
|
|
/backport |
|
Successfully created backport PR for |
## Summary `release-otdfctl.yaml` runs `make build` with the root `go.work`, so the published otdfctl binaries are compiled against the **in-repo** `sdk/`, `protocol/go`, `lib/*` instead of the versions pinned in `otdfctl/go.mod`. That's inconsistent with: - the release-please PR check, which runs `.github/scripts/work-init.sh` to drop `./sdk` from the workspace and validate against the pinned versions - what users get from `go install github.com/opentdf/platform/otdfctl@vX` On release branches this can break a release after it's published: e.g. on `release/otdfctl/v0.38`, otdfctl pins `sdk v0.33.0` (which includes #3945), but the in-tree `sdk/` did not until #4114. The release-please check would pass while the post-publish binary build would fail to compile, leaving a release with no artifacts. This sets `GOWORK=off` on the build step so binaries are built strictly from `otdfctl/go.mod`. `setup-go` still reads the Go version from `go.work`. ## Test plan - [ ] actionlint passes - [ ] Locally: `cd otdfctl && GOWORK=off make build` succeeds on `main` - [ ] Next `otdfctl/v*` release uploads binaries successfully - [ ] Consider backporting to active `release/otdfctl/*` branches <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated the release build to use dependencies specified for `otdfctl`. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: CoopAgent <coopagent@users.noreply.github.com> (cherry picked from commit e8a2f7f)
Summary
release-otdfctl.yamlrunsmake buildwith the rootgo.work, so the published otdfctl binaries are compiled against the in-reposdk/,protocol/go,lib/*instead of the versions pinned inotdfctl/go.mod.That's inconsistent with:
.github/scripts/work-init.shto drop./sdkfrom the workspace and validate against the pinned versionsgo install github.com/opentdf/platform/otdfctl@vXOn release branches this can break a release after it's published: e.g. on
release/otdfctl/v0.38, otdfctl pinssdk v0.33.0(which includes #3945), but the in-treesdk/did not until #4114. The release-please check would pass while the post-publish binary build would fail to compile, leaving a release with no artifacts.This sets
GOWORK=offon the build step so binaries are built strictly fromotdfctl/go.mod.setup-gostill reads the Go version fromgo.work.Test plan
cd otdfctl && GOWORK=off make buildsucceeds onmainotdfctl/v*release uploads binaries successfullyrelease/otdfctl/*branchesSummary by CodeRabbit
otdfctl.