Release workflow: publish with trusted publishing instead of an API key - #47
Merged
Merged
Conversation
The shared rubygems.org account requires a one-time code for API pushes, which no workflow can supply: the first release stopped at gem push. The publish job now exchanges its OIDC token with RubyGems.org for a short-lived key, like the npm packages do. Dry runs perform the exchange too, so a workflow change proves the trusted publisher setup before it is merged. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
PetrHeinz
had a problem deploying
to
rubygems
September 30, 2026 16:15 — with
GitHub Actions
Failure
The rubygems environment admits main only, so a publish job started from another branch is rejected before its first step. Dry runs from other branches stop after the build; the push that merges a workflow change into main performs the token exchange. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The first release with the workflow stopped at
gem push: the shared rubygems.org account requires a one-time code for API pushes, which no workflow can supply. RubyGems.org offers trusted publishing for exactly this case, the same OIDC mechanism the npm packages use, so the publish job now exchanges its identity token for a short-lived key and no API key is stored anywhere. TheRUBYGEMS_CREDENTIALSsecret can be deleted once this is merged.One-time setup on rubygems.org, signed in as the gem's owner:
logtail→ Trusted publishers → GitHub Actions with ownerlogtail, repositorylogtail-ruby, workflowrelease.yml, environmentrubygems.The
rubygemsenvironment only admitsmain, so the token exchange with RubyGems.org runs in dry runs onmain: the push that merges this pull request triggers one, and it is red until the publisher exists. Set the publisher up, merge, and watch that run turn green; a dry run can also be dispatched frommainat any time. Then Actions → Release →retryfrommainfinishes the pending 0.1.18: the version commit and the tag are onmainalready, only the gem push and the GitHub release are missing.🤖 Generated with Claude Code