mirror of
https://github.com/screentinker/screentinker.git
synced 2026-08-13 13:53:12 -06:00
Retry the ghcr push once — a transient 403 should not cost a release
ghcr refused the 1.9.29 push with "denied: permission_denied: Error from intermediary with HTTP status code 403", then accepted the identical build on a manual re-run minutes later. Nothing about the token, the permissions or the workflow changed in between; the registry simply said no once. The timing is what makes it worth handling. The GitHub Release job has already published by the time this runs, so a failure here leaves a tag that exists with no image behind it — alpha and every self-hoster pulling :latest see a version that is announced and unpullable, which reads as a broken release rather than a hiccup at a registry. It also needs a human to notice and re-run, which is the part that does not scale. One retry, after a pause, and a second refusal still fails the release. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Uaeo9MvzKoyXuN6ZsbhtkL
This commit is contained in:
parent
c2240288a7
commit
afe3f7f57f
26
.github/workflows/release.yml
vendored
26
.github/workflows/release.yml
vendored
|
|
@ -171,7 +171,33 @@ jobs:
|
||||||
registry: ghcr.io
|
registry: ghcr.io
|
||||||
username: ${{ github.actor }}
|
username: ${{ github.actor }}
|
||||||
password: ${{ secrets.GITHUB_TOKEN }}
|
password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
# ghcr refused this push on the 1.9.29 release with "denied: permission_denied: Error from
|
||||||
|
# intermediary with HTTP status code 403", then accepted the identical build on a manual
|
||||||
|
# re-run minutes later. Nothing about the token, the permissions or the workflow changed in
|
||||||
|
# between — the registry simply said no once.
|
||||||
|
#
|
||||||
|
# That is worth one retry rather than a failed release, and it is worst exactly here: the
|
||||||
|
# GitHub Release job has already published by this point, so a failure leaves a tag that
|
||||||
|
# exists with no image behind it. Anyone deploying from ghcr — alpha, and every self-hoster
|
||||||
|
# pulling :latest — sees a version that is announced and unpullable, which reads as a broken
|
||||||
|
# release rather than a hiccup at a registry.
|
||||||
- uses: docker/build-push-action@v6
|
- uses: docker/build-push-action@v6
|
||||||
|
id: push
|
||||||
|
continue-on-error: true
|
||||||
|
with:
|
||||||
|
context: .
|
||||||
|
platforms: linux/amd64,linux/arm64
|
||||||
|
push: true
|
||||||
|
tags: ${{ steps.ver.outputs.tags }}
|
||||||
|
|
||||||
|
- name: Pause before retrying the push
|
||||||
|
if: steps.push.outcome == 'failure'
|
||||||
|
run: sleep 45
|
||||||
|
|
||||||
|
# No continue-on-error: a second refusal is a real failure and must fail the release.
|
||||||
|
- name: Retry the push
|
||||||
|
if: steps.push.outcome == 'failure'
|
||||||
|
uses: docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
platforms: linux/amd64,linux/arm64
|
platforms: linux/amd64,linux/arm64
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue