Repository navigation
Add workflow to trigger wheel releases - #22656
Merged
Merged
Conversation
This workflow triggers automated wheel builds in the private agent-integration-wheels-release repo via repository_dispatch. For testing: can be triggered manually with workflow_dispatch Future: will trigger on tag pushes (e.g., postgres-23.2.0)
Contributor
|
This PR does not modify any files shipped with the agent. To help streamline the release process, please consider adding the |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 073d7a8916
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
The integrations input was directly interpolated into JavaScript, allowing code injection via crafted workflow_dispatch inputs. Fix: Pass values via environment variables and JSON.parse() to prevent script injection attacks. Security: Prevents arbitrary code execution with INTEGRATION_RELEASE_TOKEN in scope.
Replace INTEGRATION_RELEASE_TOKEN PAT with OIDC-based authentication. Benefits: - No long-lived secrets stored in GitHub - Short-lived tokens (1 hour) - Audit trail built-in - Access controlled by trust policies in target repo The token is obtained from dd-octo-sts-action and used to trigger repository_dispatch events in agent-integration-wheels-release.
Pin actions/github-script@v7 to commit 60a0d83 (v7.0.1) for supply chain security and reproducibility.
Allow workflow to run on pull requests targeting master or the test branch. When triggered by a PR, uses test integrations (postgres, mysql) and builds from the PR's head SHA.
Required for dd-octo-sts-action to generate OIDC tokens.
Use integrations-core.dispatch-wheel-builds for more explicit naming
- PR events: integrations-core.dispatch-wheel-builds-test - workflow_dispatch: integrations-core.dispatch-wheel-builds This allows testing in PRs while keeping production restricted.
Only allow PRs targeting dk/test-release-trigger to trigger the workflow. This prevents PRs targeting master from using the test trust policy, maintaining proper security boundaries. Master branch releases will use workflow_dispatch with the production trust policy instead.
For pull_request events, use createWorkflowDispatch to target the release-integrations.yml workflow on the 01-28-add_release_workflow branch. This allows testing before the workflow is merged to main. For workflow_dispatch events (manual triggers), continue using repository_dispatch which will work once the workflow is on main. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
The pull_request.branches config specifies the target branch of PRs, not the source branch. Changed to trigger on PRs targeting master (from the test branch) and added a paths filter to only trigger when the workflow file itself is modified. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
dkirov-dd
force-pushed
the
dk/test-release-trigger
branch
from
February 20, 2026 14:11
882efe1 to
e30e2e0
Compare
Created a reusable dispatch-release workflow that handles chunking and dispatching release workflow runs to agent-integration-wheels-release. This workflow: - Lives in integrations-core (not agent-integration-wheels-release) - Chunks integrations into batches (default: 200 per batch) - Dispatches multiple workflow runs for >200 integrations - Uses dd-octo-sts for secure cross-repo dispatch - Supports both test and production trust policies - Can be copied to integrations-extras and marketplace Example: 450 integrations → 3 runs of 200, 200, and 50 The trigger workflow now: - Extracts inputs (integrations, source ref, policy name) - Selects correct trust policy based on event type: - pull_request: integrations-core.dispatch-wheel-builds-test - workflow_dispatch: integrations-core.dispatch-wheel-builds - Calls local dispatch workflow with all parameters Benefits: - Scales to unlimited integrations (no 256 limit) - Simpler trigger workflow (removed 64 lines) - Each integration repo controls its own dispatch logic - No cross-repo workflow dependency - Secure: uses appropriate trust policy per event type 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Updated PR testing to use 4 integrations with a chunk size of 2 to test the chunking functionality: - Test integrations: postgres, mysql, redis, nginx - Chunk size: 2 (for PRs only, production uses 200) - Expected behavior: 2 workflow runs with 2 integrations each This will verify that the dispatch workflow correctly: - Splits integrations into multiple chunks - Dispatches separate workflow runs for each chunk - Processes integrations in parallel across runs 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
dkirov-dd
force-pushed
the
dk/test-release-trigger
branch
from
February 20, 2026 14:25
e30e2e0 to
e667643
Compare
Replace mysql and nginx with windows_performance_counters and ibm_mq for more representative E2E testing. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…tests - Rewrite TestParseBoolEnv.test_true_values and test_false_values with pytest.mark.parametrize so each value gets its own test case - Rename TestResolvePackages.ALL attribute to all_packages (PEP 8 — not a module-level constant) - Pass all_packages as a keyword argument to resolve_packages for readability - Assert exact mode string in test_all_keyword instead of loose substring checks - Rename test_hyphenated_package_name to test_strips_only_version_suffix and remove inline comment (name is now self-describing) Rationale: PR review feedback flagged these tests as harder to debug than necessary. Parametrized tests produce per-value failure messages instead of stopping at the first failing iteration. The rename and exact assertion changes make failures immediately interpretable without reading the implementation. This commit made by [/dd:git:commit:atomic](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/atomic.md)
- Pin pytest to 8.3.5 in test-release-scripts.yml to prevent surprise breakage from unpinned installs - Change dispatch-release.yml target default from dev to prod and remove the TODO comment - Remove TODO comment from trigger-release.yml target line (pipeline is validated) Rationale: The pipeline has been validated in prod so the TODO comments are no longer accurate. Pinning pytest ensures the CI test job runs against a known-good version rather than whatever the latest release happens to be at run time. This commit made by [/dd:git:commit:atomic](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/atomic.md)
…flows - Note in trigger-release.yml that equivalent workflows exist in integrations-extras and marketplace - Note in dispatch-release.yml that it is a reusable workflow called by trigger-release from integration repos Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Assert full mode string in test_json_array and test_auto_detect - Pin ddev default to 14.3.2 in dispatch-release.yml install step Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
… minor cleanup - write_summary() now called before sys.exit(1) when stable packages are found on an alpha/beta/rc branch, matching the behaviour of the HAS_FRAGMENTS failure path - add target default comment in dispatch-release.yml to surface that callers typically override it - replace manual batch_num increment with enumerate(..., 1) in dispatch.py - remove stray double blank line in validation.py - update test to assert summary is written on stable-on-pre-release failure Rationale: stable-on-pre-release validation failure left the GitHub Step Summary empty, making it hard to diagnose the failure from the Actions UI This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
…d param - Drop _TYPE_LABELS dict; extract _row_label() that enumerates every case - Rename build_summary param dispatched -> was_dispatched to eliminate naming collision with per-row dispatch field - Rename local will_dispatch -> eligible for clarity - Add explicit labels for STABLE-on-pre-release and PRE_RELEASE-on-stable symmetric cases (previously fell through to a false-positive "✅ Ready") - Add "✅ Validated" label for eligible packages when dispatch was blocked - Update callers (dispatch_release.py, validate_release.py) and tests - Add 3 new label tests covering the previously unhandled cases Rationale: the old catch-all "✅ Ready" in _TYPE_LABELS produced misleading green labels in error summaries; symmetric branch-mismatch cases had no distinct labels, making release summaries hard to interpret at a glance. This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
…_label - Replace .get(typ, fallback) dict literal with explicit if statements - Raise ValueError on unknown type instead of silently returning "⏭️ Skipped" Rationale: dict is allocated on every call for a single lookup; explicit if-chain is clearer, and an unknown type is a programmer error that should surface loudly rather than produce a misleading label. This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
- Assert actual env var values in test_successful_validation_writes_json instead of just checking key presence - Add test_unknown_type_raises to cover the ValueError raised by _row_label for unrecognized validation types Rationale: key-presence checks don't catch wrong values; the ValueError branch had no test coverage after the dict-to-if-chain refactor. This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
…ke tests - New workflow fires on PRs to master that touch release scripts/workflows - Always runs with dry-run=true — no tags pushed, no builds triggered - Uses GITHUB_BASE_REF for stable-release detection (correct for PR events) - Remove environment: release gate from dispatch-release.yml for PR testing - Bump apache 7.3.0→7.3.1, nginx 9.3.0→9.3.1, snmp 12.3.0→12.3.1, kafka 4.3.0→4.3.1 Rationale: verify the end-to-end pipeline works on PRs without risking real dispatches to agent-integration-wheels-release. This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
…line smoke tests" This reverts commit 50e0fb6.
…call_args_list - Replace index-based call_args_list access with full mock.call comparisons - Extract _GIT_NAME/_GIT_EMAIL class constants to avoid repeating expected calls - Remove test_git_config_called_before_ddev (now redundant: test_push_flag asserts the full call list) Rationale: asserting complete call objects catches regressions in argument values, not just argument position; full call assertions are also easier to read. This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
- Replace call_args.args[0] and call_args[0][1] with mock_calls comparisons - All dispatch call assertions now use complete call() objects Rationale: consistent with the full-call assertion style used elsewhere. This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
- Fix MANUAL_PACKAGES → SELECTED_PACKAGES bug in dispatch-release.yml that silently broke manual package selection - Catch urllib.error.URLError in send_dispatch retry loop; network-level failures were bypassing all retry attempts - Replace sys.exit(1) in send_dispatch with DispatchError; in resolve_packages with ValueError — makes library functions testable and reusable outside CLI context - Fix typo selected_PACKAGES → SELECTED_PACKAGES in error message - Wrap CalledProcessError from get_tags_at_head with clean RuntimeError - Use Path(path).open() instead of bare open() in github.py for consistency with rest of _release/ module - Inline eligible label in build_summary, rename _row_label → _ineligible_label to clarify its contract - Catch json.JSONDecodeError in _load_validation for partial-write resilience - Update misleading is-stable-release comments in workflow files - Add sleep backoff assertions, URLError tests, retry-failure test Rationale: review identified a silent bug (MANUAL_PACKAGES), retry bypass for network errors, and sys.exit anti-patterns in library code This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Rename dispatch-release.yml → release-dispatch.yml - Rename trigger-release.yml → release-trigger.yml - Update all internal cross-references in test-release-scripts.yml, release-trigger.yml, and release-dispatch.yml comments Rationale: align with the existing release-* naming convention used by other workflows in this repo (release-base.yml, release-dev.yml, release-hash-check.yml) This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
These were accidentally staged by a prior git add -A during the rename commit. .gitignore already covers .agint-review/ but the index had them from a failed commit attempt.
- Replace three sequential workflow steps (tag_releases, detect_packages, validate_release) with a single release_prepare.py script - Rename dispatch_release.py → release_dispatch.py for naming consistency - Update release-dispatch.yml: single 'prepare' step, all downstream steps.detect refs updated to steps.prepare - Merge corresponding test files into test_script_release_prepare.py and test_script_release_dispatch.py Rationale: eliminates GITHUB_OUTPUT round-trips between steps and centralises all release-prep logic in one place; the "skip validate if no packages" branch is now a plain Python if-statement instead of a YAML conditional reading back from disk This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
- Fix SSL errors treated as retriable in dispatch.py (raise immediately) - Normalize SELECTED_PACKAGES="[]" to auto-detect in release_prepare.py - Add diagnostic print before silent sys.exit after ddev tag retry - Make missing release_validation.json a hard error in release_dispatch.py - Add comment explaining dry_run data-provenance asymmetry - Fix parse_bool_env to use strict allowlist (unrecognised → default) - Add PackageValidationResult TypedDict to validation.py - Move TARGET_REPO constant to _release/__init__.py, remove duplicates - Add return type annotation to _urlopen - Rename nbr_packages → num_packages in dispatch_in_batches - Extract _stable_result to module level in test_script_release_prepare.py - Add TestMain.test_dry_run_propagates_to_validation_json - Add TestMain.test_validate_failure_exits_from_main Rationale: Addresses all review findings on PR #22656. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Remove dry_run from release_validation.json (prepare no longer writes it) - Read DRY_RUN directly from env in dispatch, same as SOURCE_REPO/REF/TARGET - Update tests to set DRY_RUN env var instead of embedding in JSON Rationale: Having dry_run sourced from the JSON was confusing — all other workflow inputs come from env vars injected by the YAML step. Keeping one value in the file while the rest come from env made the contract inconsistent. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Disable environment: release gate in release-dispatch.yml so the job can run in PR context without requiring environment approval - Add release-test-trigger.yml: fires on pull_request to this branch, invokes release-dispatch with dry-run=true for active_directory, activemq, and airflow (stable packages with no changelog fragments) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…atch" This reverts commit b91002a.
iliakur
approved these changes
Mar 20, 2026
1 of 3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR adds a workflow to trigger automated wheel builds in the private
agent-integration-wheels-releaserepository.Check the Actions runs.
Comments
Manual releases are possible through a
workflow_dispatchusing theghCLI.These are placed behind the new
releaseenvironment for security.Note
Related PRs:
v1 Example run
v2 Example run with additional logging
v3 Example run with job summaries
v4 Example run with unified summary
v5 Example run with all packages