Skip to content

Release workflow: publish with trusted publishing instead of an API key - #47

Merged
PetrHeinz merged 2 commits into
mainfrom
claude/release-trusted-publishing
Sep 30, 2026
Merged

PetrHeinz merged 2 commits into
mainfrom
claude/release-trusted-publishing

Conversation

@PetrHeinz

@PetrHeinz PetrHeinz commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

The first release with the workflow stopped at gem push: the shared rubygems.org account requires a one-time code for API pushes, which no workflow can supply. RubyGems.org offers trusted publishing for exactly this case, the same OIDC mechanism the npm packages use, so the publish job now exchanges its identity token for a short-lived key and no API key is stored anywhere. The RUBYGEMS_CREDENTIALS secret can be deleted once this is merged.

One-time setup on rubygems.org, signed in as the gem's owner: logtail → Trusted publishers → GitHub Actions with owner logtail, repository logtail-ruby, workflow release.yml, environment rubygems.

The rubygems environment only admits main, so the token exchange with RubyGems.org runs in dry runs on main: the push that merges this pull request triggers one, and it is red until the publisher exists. Set the publisher up, merge, and watch that run turn green; a dry run can also be dispatched from main at any time. Then Actions → Release → retry from main finishes the pending 0.1.18: the version commit and the tag are on main already, only the gem push and the GitHub release are missing.

🤖 Generated with Claude Code

The shared rubygems.org account requires a one-time code for API pushes,
which no workflow can supply: the first release stopped at gem push.
The publish job now exchanges its OIDC token with RubyGems.org for a
short-lived key, like the npm packages do. Dry runs perform the exchange
too, so a workflow change proves the trusted publisher setup before it
is merged.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The rubygems environment admits main only, so a publish job started from
another branch is rejected before its first step. Dry runs from other
branches stop after the build; the push that merges a workflow change
into main performs the token exchange.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@PetrHeinz
PetrHeinz marked this pull request as ready for review September 30, 2026 16:23
@PetrHeinz
PetrHeinz merged commit 7bf3414 into main Sep 30, 2026
16 checks passed
@PetrHeinz
PetrHeinz deleted the claude/release-trusted-publishing branch September 30, 2026 16:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant