Skip to content

Add workflow to trigger wheel releases - #22656

Merged
dkirov-dd merged 96 commits into
masterfrom
dk/test-release-trigger
Mar 20, 2026
Merged

dkirov-dd merged 96 commits into
masterfrom
dk/test-release-trigger

Conversation

@dkirov-dd

@dkirov-dd dkirov-dd commented Feb 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This PR adds a workflow to trigger automated wheel builds in the private agent-integration-wheels-release repository.

Check the Actions runs.

Comments

Manual releases are possible through a workflow_dispatch using the gh CLI.
These are placed behind the new release environment for security.

v1 Example run
v2 Example run with additional logging
v3 Example run with job summaries
v4 Example run with unified summary
v5 Example run with all packages

This workflow triggers automated wheel builds in the private
agent-integration-wheels-release repo via repository_dispatch.

For testing: can be triggered manually with workflow_dispatch
Future: will trigger on tag pushes (e.g., postgres-23.2.0)
@github-actions

github-actions Bot commented Feb 17, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Recommendation: Add qa/skip-qa label

This PR does not modify any files shipped with the agent.

To help streamline the release process, please consider adding the qa/skip-qa label if these changes do not require QA testing.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 073d7a8916

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread .github/workflows/trigger-release.yml Outdated
dkirov-dd and others added 11 commits February 17, 2026 15:14
The integrations input was directly interpolated into JavaScript,
allowing code injection via crafted workflow_dispatch inputs.

Fix: Pass values via environment variables and JSON.parse() to
prevent script injection attacks.

Security: Prevents arbitrary code execution with INTEGRATION_RELEASE_TOKEN
in scope.
Replace INTEGRATION_RELEASE_TOKEN PAT with OIDC-based authentication.

Benefits:
- No long-lived secrets stored in GitHub
- Short-lived tokens (1 hour)
- Audit trail built-in
- Access controlled by trust policies in target repo

The token is obtained from dd-octo-sts-action and used to trigger
repository_dispatch events in agent-integration-wheels-release.
Pin actions/github-script@v7 to commit 60a0d83 (v7.0.1) for supply
chain security and reproducibility.
Allow workflow to run on pull requests targeting master or the test
branch. When triggered by a PR, uses test integrations (postgres,
mysql) and builds from the PR's head SHA.
Required for dd-octo-sts-action to generate OIDC tokens.
Use integrations-core.dispatch-wheel-builds for more explicit naming
- PR events: integrations-core.dispatch-wheel-builds-test
- workflow_dispatch: integrations-core.dispatch-wheel-builds

This allows testing in PRs while keeping production restricted.
Only allow PRs targeting dk/test-release-trigger to trigger the
workflow. This prevents PRs targeting master from using the test
trust policy, maintaining proper security boundaries.

Master branch releases will use workflow_dispatch with the production
trust policy instead.
For pull_request events, use createWorkflowDispatch to target the
release-integrations.yml workflow on the 01-28-add_release_workflow branch.
This allows testing before the workflow is merged to main.

For workflow_dispatch events (manual triggers), continue using
repository_dispatch which will work once the workflow is on main.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
The pull_request.branches config specifies the target branch of PRs,
not the source branch. Changed to trigger on PRs targeting master
(from the test branch) and added a paths filter to only trigger when
the workflow file itself is modified.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@dkirov-dd
dkirov-dd force-pushed the dk/test-release-trigger branch from 882efe1 to e30e2e0 Compare February 20, 2026 14:11
dkirov-dd and others added 2 commits February 20, 2026 15:24
Created a reusable dispatch-release workflow that handles chunking and
dispatching release workflow runs to agent-integration-wheels-release.

This workflow:
- Lives in integrations-core (not agent-integration-wheels-release)
- Chunks integrations into batches (default: 200 per batch)
- Dispatches multiple workflow runs for >200 integrations
- Uses dd-octo-sts for secure cross-repo dispatch
- Supports both test and production trust policies
- Can be copied to integrations-extras and marketplace

Example: 450 integrations → 3 runs of 200, 200, and 50

The trigger workflow now:
- Extracts inputs (integrations, source ref, policy name)
- Selects correct trust policy based on event type:
  - pull_request: integrations-core.dispatch-wheel-builds-test
  - workflow_dispatch: integrations-core.dispatch-wheel-builds
- Calls local dispatch workflow with all parameters

Benefits:
- Scales to unlimited integrations (no 256 limit)
- Simpler trigger workflow (removed 64 lines)
- Each integration repo controls its own dispatch logic
- No cross-repo workflow dependency
- Secure: uses appropriate trust policy per event type

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Updated PR testing to use 4 integrations with a chunk size of 2 to test
the chunking functionality:
- Test integrations: postgres, mysql, redis, nginx
- Chunk size: 2 (for PRs only, production uses 200)
- Expected behavior: 2 workflow runs with 2 integrations each

This will verify that the dispatch workflow correctly:
- Splits integrations into multiple chunks
- Dispatches separate workflow runs for each chunk
- Processes integrations in parallel across runs

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@dkirov-dd
dkirov-dd force-pushed the dk/test-release-trigger branch from e30e2e0 to e667643 Compare February 20, 2026 14:25
dkirov-dd and others added 28 commits March 16, 2026 15:23
…tests

- Rewrite TestParseBoolEnv.test_true_values and test_false_values with pytest.mark.parametrize so each value gets its own test case
- Rename TestResolvePackages.ALL attribute to all_packages (PEP 8 — not a module-level constant)
- Pass all_packages as a keyword argument to resolve_packages for readability
- Assert exact mode string in test_all_keyword instead of loose substring checks
- Rename test_hyphenated_package_name to test_strips_only_version_suffix and remove inline comment (name is now self-describing)

Rationale: PR review feedback flagged these tests as harder to debug than necessary. Parametrized tests produce per-value failure messages instead of stopping at the first failing iteration. The rename and exact assertion changes make failures immediately interpretable without reading the implementation.

This commit made by [/dd:git:commit:atomic](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/atomic.md)
- Pin pytest to 8.3.5 in test-release-scripts.yml to prevent surprise breakage from unpinned installs
- Change dispatch-release.yml target default from dev to prod and remove the TODO comment
- Remove TODO comment from trigger-release.yml target line (pipeline is validated)

Rationale: The pipeline has been validated in prod so the TODO comments are no longer accurate. Pinning pytest ensures the CI test job runs against a known-good version rather than whatever the latest release happens to be at run time.

This commit made by [/dd:git:commit:atomic](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/atomic.md)
…flows

- Note in trigger-release.yml that equivalent workflows exist in integrations-extras and marketplace
- Note in dispatch-release.yml that it is a reusable workflow called by trigger-release from integration repos

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Assert full mode string in test_json_array and test_auto_detect
- Pin ddev default to 14.3.2 in dispatch-release.yml install step

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
… minor cleanup

- write_summary() now called before sys.exit(1) when stable packages are
  found on an alpha/beta/rc branch, matching the behaviour of the HAS_FRAGMENTS
  failure path
- add target default comment in dispatch-release.yml to surface that callers
  typically override it
- replace manual batch_num increment with enumerate(..., 1) in dispatch.py
- remove stray double blank line in validation.py
- update test to assert summary is written on stable-on-pre-release failure

Rationale: stable-on-pre-release validation failure left the GitHub Step
Summary empty, making it hard to diagnose the failure from the Actions UI

This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
…d param

- Drop _TYPE_LABELS dict; extract _row_label() that enumerates every case
- Rename build_summary param dispatched -> was_dispatched to eliminate
  naming collision with per-row dispatch field
- Rename local will_dispatch -> eligible for clarity
- Add explicit labels for STABLE-on-pre-release and PRE_RELEASE-on-stable
  symmetric cases (previously fell through to a false-positive "✅ Ready")
- Add "✅ Validated" label for eligible packages when dispatch was blocked
- Update callers (dispatch_release.py, validate_release.py) and tests
- Add 3 new label tests covering the previously unhandled cases

Rationale: the old catch-all "✅ Ready" in _TYPE_LABELS produced misleading
green labels in error summaries; symmetric branch-mismatch cases had no
distinct labels, making release summaries hard to interpret at a glance.

This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
…_label

- Replace .get(typ, fallback) dict literal with explicit if statements
- Raise ValueError on unknown type instead of silently returning "⏭️ Skipped"

Rationale: dict is allocated on every call for a single lookup; explicit
if-chain is clearer, and an unknown type is a programmer error that should
surface loudly rather than produce a misleading label.

This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
- Assert actual env var values in test_successful_validation_writes_json
  instead of just checking key presence
- Add test_unknown_type_raises to cover the ValueError raised by _row_label
  for unrecognized validation types

Rationale: key-presence checks don't catch wrong values; the ValueError
branch had no test coverage after the dict-to-if-chain refactor.

This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
…ke tests

- New workflow fires on PRs to master that touch release scripts/workflows
- Always runs with dry-run=true — no tags pushed, no builds triggered
- Uses GITHUB_BASE_REF for stable-release detection (correct for PR events)
- Remove environment: release gate from dispatch-release.yml for PR testing
- Bump apache 7.3.0→7.3.1, nginx 9.3.0→9.3.1, snmp 12.3.0→12.3.1, kafka 4.3.0→4.3.1

Rationale: verify the end-to-end pipeline works on PRs without risking
real dispatches to agent-integration-wheels-release.

This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
…call_args_list

- Replace index-based call_args_list access with full mock.call comparisons
- Extract _GIT_NAME/_GIT_EMAIL class constants to avoid repeating expected calls
- Remove test_git_config_called_before_ddev (now redundant: test_push_flag asserts the full call list)

Rationale: asserting complete call objects catches regressions in argument values,
not just argument position; full call assertions are also easier to read.

This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
- Replace call_args.args[0] and call_args[0][1] with mock_calls comparisons
- All dispatch call assertions now use complete call() objects

Rationale: consistent with the full-call assertion style used elsewhere.

This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
- Fix MANUAL_PACKAGES → SELECTED_PACKAGES bug in dispatch-release.yml
  that silently broke manual package selection
- Catch urllib.error.URLError in send_dispatch retry loop; network-level
  failures were bypassing all retry attempts
- Replace sys.exit(1) in send_dispatch with DispatchError; in
  resolve_packages with ValueError — makes library functions testable
  and reusable outside CLI context
- Fix typo selected_PACKAGES → SELECTED_PACKAGES in error message
- Wrap CalledProcessError from get_tags_at_head with clean RuntimeError
- Use Path(path).open() instead of bare open() in github.py for
  consistency with rest of _release/ module
- Inline eligible label in build_summary, rename _row_label →
  _ineligible_label to clarify its contract
- Catch json.JSONDecodeError in _load_validation for partial-write
  resilience
- Update misleading is-stable-release comments in workflow files
- Add sleep backoff assertions, URLError tests, retry-failure test

Rationale: review identified a silent bug (MANUAL_PACKAGES), retry
bypass for network errors, and sys.exit anti-patterns in library code

This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Rename dispatch-release.yml → release-dispatch.yml
- Rename trigger-release.yml → release-trigger.yml
- Update all internal cross-references in test-release-scripts.yml,
  release-trigger.yml, and release-dispatch.yml comments

Rationale: align with the existing release-* naming convention used
by other workflows in this repo (release-base.yml, release-dev.yml,
release-hash-check.yml)

This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
These were accidentally staged by a prior git add -A during the rename
commit. .gitignore already covers .agint-review/ but the index had them
from a failed commit attempt.
- Replace three sequential workflow steps (tag_releases, detect_packages,
  validate_release) with a single release_prepare.py script
- Rename dispatch_release.py → release_dispatch.py for naming consistency
- Update release-dispatch.yml: single 'prepare' step, all downstream
  steps.detect refs updated to steps.prepare
- Merge corresponding test files into test_script_release_prepare.py and
  test_script_release_dispatch.py

Rationale: eliminates GITHUB_OUTPUT round-trips between steps and
centralises all release-prep logic in one place; the "skip validate if
no packages" branch is now a plain Python if-statement instead of a
YAML conditional reading back from disk

This commit made by [/dd:git:commit:quick](https://github.com/DataDog/claude-marketplace/tree/main/dd/commands/git/commit/quick.md)
- Fix SSL errors treated as retriable in dispatch.py (raise immediately)
- Normalize SELECTED_PACKAGES="[]" to auto-detect in release_prepare.py
- Add diagnostic print before silent sys.exit after ddev tag retry
- Make missing release_validation.json a hard error in release_dispatch.py
- Add comment explaining dry_run data-provenance asymmetry
- Fix parse_bool_env to use strict allowlist (unrecognised → default)
- Add PackageValidationResult TypedDict to validation.py
- Move TARGET_REPO constant to _release/__init__.py, remove duplicates
- Add return type annotation to _urlopen
- Rename nbr_packages → num_packages in dispatch_in_batches
- Extract _stable_result to module level in test_script_release_prepare.py
- Add TestMain.test_dry_run_propagates_to_validation_json
- Add TestMain.test_validate_failure_exits_from_main

Rationale: Addresses all review findings on PR #22656.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Remove dry_run from release_validation.json (prepare no longer writes it)
- Read DRY_RUN directly from env in dispatch, same as SOURCE_REPO/REF/TARGET
- Update tests to set DRY_RUN env var instead of embedding in JSON

Rationale: Having dry_run sourced from the JSON was confusing — all other
workflow inputs come from env vars injected by the YAML step. Keeping one
value in the file while the rest come from env made the contract inconsistent.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Disable environment: release gate in release-dispatch.yml so the job
  can run in PR context without requiring environment approval
- Add release-test-trigger.yml: fires on pull_request to this branch,
  invokes release-dispatch with dry-run=true for active_directory,
  activemq, and airflow (stable packages with no changelog fragments)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants