Skip to content

Release workflow: publish to RubyGems.org from GitHub Actions - #23

Merged
PetrHeinz merged 6 commits into
mainfrom
claude/release-workflow
Sep 30, 2026
Merged

PetrHeinz merged 6 commits into
mainfrom
claude/release-workflow

Conversation

@PetrHeinz

@PetrHeinz PetrHeinz commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Mirrors the Release workflow of logtail-js and logtail-python: Actions → Release → Run workflow from main, pick patch or minor, and the workflow runs the tests, bumps the version in lib/*/version.rb, builds the gem, commits vX.Y.Z, tags it, pushes both, pushes the gem to RubyGems.org and creates a GitHub release with generated notes. retry finishes a release that failed after the version commit was pushed: it bumps nothing, rebuilds the tagged commit and only does what is still missing.

Authentication is trusted publishing (OIDC), like the npm packages: no API key is stored anywhere, the gem on rubygems.org trusts this workflow file run from this repository in the rubygems environment, and the shared account's multi-factor authentication stays as it is (its "UI and API" level rejects pushes with an API key, which is what stopped the first logtail release). One-time setup on rubygems.org, signed in as the gem's owner: logtail-rack → Trusted publishers → GitHub Actions with owner logtail, repository logtail-ruby-rack, workflow release.yml, environment rubygems. The RUBYGEMS_CREDENTIALS secret is unused and can be deleted.

The version commit is pushed with the workflow's own token. main requires pull requests, so the GitHub Actions app is among the actors allowed to bypass that requirement (Settings → Branches → the main rule), and the workflow header says so. The rubygems environment exists with deployment branches limited to main and no required reviewers, so anyone who can dispatch the workflow can release. Add reviewers there if releases should need an approval.

Dry run: every push that touches .github/workflows/release.yml bumps in place, runs the tests and builds the gem, without committing or publishing anything. The rubygems environment only admits main, so the token exchange with RubyGems.org runs in dry runs on main: the push that merges this pull request triggers one, and it is red until the trusted publisher exists. A dry run can also be dispatched from main at any time. Pushing the version commit itself is only exercised by the first real release.

🤖 Generated with Claude Code

PetrHeinz and others added 4 commits September 25, 2026 16:59
Mirrors the logtail-js and logtail-python release workflows. main requires
pull requests, so the version bump stays a pull request and the workflow
tests, builds, pushes the gem, tags and creates the GitHub release. Every
push touching the workflow file is a dry run.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The environment restricts deployments to main and has no required
reviewers, so anyone who can dispatch the workflow can release.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The GitHub Actions app may bypass the pull request requirement of main
now, so the workflow takes patch, minor and retry inputs like the
logtail-js and logtail-python ones and pushes the version commit and
the tag itself. Dry runs bump in place without committing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The shared rubygems.org account requires a one-time code for API pushes,
which no workflow can supply: the first logtail release stopped at gem
push. The publish job now exchanges its OIDC token with RubyGems.org for
a short-lived key, like the npm packages do. Dry runs perform the
exchange too, so a workflow change proves the trusted publisher setup
before it is merged.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
PetrHeinz and others added 2 commits September 30, 2026 18:18
The rubygems environment admits main only, so a publish job started from
another branch is rejected before its first step. Dry runs from other
branches stop after the build; the push that merges a workflow change
into main performs the token exchange.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
retry insisted that the version commit is HEAD, but main moves on as
soon as anything else is merged, as happened between the failed logtail
0.1.18 release and its retry. The retry now checks out the tag of the
version in lib/*/version.rb and rebuilds that commit.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@PetrHeinz
PetrHeinz marked this pull request as ready for review September 30, 2026 16:38
@PetrHeinz
PetrHeinz merged commit 6adb816 into main Sep 30, 2026
27 checks passed
@PetrHeinz
PetrHeinz deleted the claude/release-workflow branch September 30, 2026 16:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant