Skip to content

Ci publish codeartifact - #1

Merged
mikhail-musin-idt merged 7 commits into
masterfrom
ci-publish-codeartifact
Sep 8, 2026
Merged

mikhail-musin-idt merged 7 commits into
masterfrom
ci-publish-codeartifact

Conversation

@mikhail-musin-idt

Copy link
Copy Markdown

No description provided.

mikhail-musin-idt and others added 6 commits September 4, 2026 17:53
Adds a workflow that packs SqsPoller and SqsPoller.Extensions.Publisher and
pushes them to the team_caf-nuget CodeArtifact repository, which is the feed
consuming services restore from.

Authentication uses the organisation's GitHub OIDC role rather than a
long-lived API key. Triggering is on a v* tag instead of a push to master,
because the package version comes from the csproj and a push-triggered
publish would fail on any commit that does not bump it.

Only the two library projects are packed: packing the solution also produces
packages for sample/SqsPoller.Sample.Publisher and
sample/SqsPoller.Sample.Subscriber, which are not products.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Removes both workflows that pushed to public nuget.org and replaces the
prerelease one with a CodeArtifact equivalent, so releases and prereleases
now go to the same internal feed consuming services restore from.

Deletes the committed nuget-apikey file, which only existed to authenticate
against nuget.org and is dead once that path is gone. Note that deleting the
file does not remove it from history: the key still needs to be revoked.

Package metadata pointed RepositoryUrl at a personal fork and ProjectUrl at
the public nuget.org listing; both now point at this repository.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The publish workflows targeted the self-hosted `gha-runner-scale-set` label,
which is not available to this repository, so the prerelease job stayed queued
with no runner assigned. OIDC role assumption works the same on GitHub-hosted
runners, so both workflows now use ubuntu-latest.

Integration tests failed with `docker-compose: command not found`: Compose v1
is no longer installed on hosted runners. Uses `docker compose` instead, with
--wait so the step blocks on the localstack healthcheck rather than racing it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Both library projects set GeneratePackageOnBuild=true, which wires packing
into the build. Hosted runners resolve the newest installed SDK (10.0.400,
not the 8.0.x that setup-dotnet requests, since there is no global.json), and
there dotnet pack no longer rebuilds under that property, failing with NU5026
because the dll is absent. SDK 8 tolerated the same command locally.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The push reaches CodeArtifact and is rejected with 400, but dotnet nuget push
reports only the status code. Adds a temporary diagnostic step so the run
shows the repository upstreams and the package origin configuration.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The publish path is confirmed working end to end, so the step that dumped the
repository and package origin configuration is no longer needed. Keeps the
finding as a comment: both package names need publish=ALLOW set once, because
the feed has a public nuget.org external connection and CodeArtifact defaults
such packages to publish=BLOCK.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The release workflow now passes -p:Version derived from the tag, so v2.1.0
always publishes 2.1.0. Previously the csproj decided the version and the tag
only triggered the run: tagging without bumping the csproj republished the old
version, which --skip-duplicate turned into a silently green no-op.

A tag that does not parse as MAJOR.MINOR.PATCH[-suffix] fails the run instead
of publishing something unintended. workflow_dispatch runs from a branch, where
the ref is not a version, and there the csproj value is used unchanged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@mikhail-musin-idt
mikhail-musin-idt merged commit 5b8b1cd into master Sep 8, 2026
5 checks passed
@mikhail-musin-idt
mikhail-musin-idt deleted the ci-publish-codeartifact branch September 8, 2026 11:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant