ci: prune expired preview releases after promotion - #461
Conversation
Signed-off-by: Kalvin Chau <kalvin@block.xyz>
Drop tests and table rows that no script mutation distinguishes from the remaining ones, and the workflow assertions cleanup does not depend on. Add the repository's real suffixed candidate tag to the exclusion table and an extra-platform feed row, which the previous cases did not exercise. Co-authored-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz> Signed-off-by: peon <9ac6794b000690b7e814eb1805ad32405d0bec7d52838de3a86cf967565dacc0@buzz.block.builderlab.xyz>
e1e127f to
e3b8e14
Compare
wesbillman
left a comment
There was a problem hiding this comment.
No changes requested: the retention union, canonical-tag filtering, fail-closed planning, and serialized post-promotion cleanup match the stated contract; Mantis’s independent source review agrees.
Star Lord automated source review via Wes’s account; head e3b8e14510eab22d2cd9ca42fb78894080ccf2f6, base bfe4c7f1832935ef5a4c93e11ba4725baac4b728, COMMENT only—not approval.
No PR code/tests or cleanup executed here; human dry-run confirmation and real deletion remain unverified, and the documented release-first/tag-second partial-failure limitation remains.
The hosted snapshot shows all six new cleanup tests passing on the merged test tree, but required CI failed with WebKit shard 5 cancelled and Windows skipped; this is not merge-readiness certification.
wesbillman
left a comment
There was a problem hiding this comment.
No blocking findings. The change meets the 9/10 bar for minimalness, clarity, and correctness against the stated retention policy. Retention filtering, fail-closed planning, and serialized post-promotion execution are consistent; an independent workflow review found no blocker.
Carl, an automated reviewer, commenting via Wes’s GitHub account. COMMENT only, not approval.
Reviewed head e3b8e14510eab22d2cd9ca42fb78894080ccf2f6 against base bfe4c7f1832935ef5a4c93e11ba4725baac4b728.
- Validated: both complete affected Node test files passed, 9/9, in a clean exact-head worktree with Node 24.18.0. Deletion tests used a stubbed
gh. The live read-only command with gh 2.97.0 returnedDry run: 0 preview releases and tags; keeping 25 previews.No releases or tags were changed. - CI: the refreshed hosted run now has WebKit shard 5 and CI required successful; Windows native validation is skipped. This supersedes the earlier cancelled/in-progress snapshot.
- Remaining evidence: human dry-run confirmation and a real Actions-token deletion remain unverified. The documented release-first/tag-second operation can leave an orphan tag if its second operation fails; later release enumeration cannot retry that tag. The rulesets API currently returns only branch-target rulesets, but that is not proof of live deletion success. These are operational limits, not a newly established code blocker.
…followup * origin/main: fix(sidebar): save channel moves on desktop and move channels by drag (#474) perf(messages): stop re-rendering every row on each channel-list publish (#473) Unify workspace panels and add persistent channel tabs (#413) ci: prune expired preview releases after promotion (#461) feat(sidebar): show unread conversation counts and DM avatar previews (#472) fix(previews): dismiss hovered previews when their trigger scrolls (#460) perf(native): reduce crypto, upload and discovery overhead (#464) Signed-off-by: Tree Trunks <6ba22921d9dc2ad0aa6ecdf63787ddd24726e266d866da31af69f2e4e146ace5@buzz.block.builderlab.xyz> # Conflicts: # src/shared/design-system/icons/index.ts # tests/browser/layout.spec.mjs
What
After a successful preview promotion and feed read-back, the promote job prunes old versioned preview releases and their Git tags.
Kept (union):
published_at;preview-feed/latest.json.Only non-draft prereleases tagged exactly
v<app-version>-preview.<run>.<attempt>are candidates. Stable releases, drafts, the rollingpreview-feedrelease, and other tag formats (for examplev0.0.0-preview.19.1-windows-linux) are never deleted.Safety
scripts/prune-preview-releases.mjsis a dry run unless passed exactly--apply; any other argument aborts before a GitHub call.GH_REPOmust beblock/buzz-app.Evidence
Read-only dry run against the live repository at
e3b8e145:All 24 current previews are under 7 days old, so the first deletions happen once the oldest pass that age.
Tests, at
e3b8e145:tests/integration/prune-preview-releases.test.mjsadds 6 Node tests that run the script against a stubghonPATHwith a fixed clock: dry run, apply with excluded release classes, the 7-day boundary, abort conditions, argument/repository guards, and deletion failure. Each guard in the script was removed in turn and the suite checked for a failure. Three removals are knowingly not caught: accepting leading-zero tags, accepting--applyfollowed by extra arguments, and the feed version-format assert, which the target-present assert subsumes.preview-feed.test.mjsasserts the cleanup step is the last step of the promote job and runs with--apply.Known limits
gh release delete --cleanup-tagdeletes the release before the tag. If the tag deletion fails, the tag remains and later runs do not retry it, because they enumerate releases.darwin-aarch64. Adding a platform to the feed makes cleanup fail closed until the script is updated.Not yet done
--applyrun has not been exercised; nothing is old enough to delete yet.