Skip to content

chore(push): release gateway chart 0.3.3 - #8107

Merged
brow merged 2 commits into
mainfrom
push-chart-release/0.3.3
Oct 5, 2026
Merged

brow merged 2 commits into
mainfrom
push-chart-release/0.3.3

Conversation

@brow

@brow brow commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Prepares publication of the Buzz push gateway chart 0.3.3, including the optional migration Pod annotations already merged in #8105. This PR adds release notes only; chart templates, values, and schema are unchanged from the reviewed implementation.

Merging the push-chart-release/0.3.3 branch triggers the normal release workflow: create push-chart-v0.3.3, validate the chart, then publish oci://ghcr.io/block/buzz/charts/buzz-push-gateway:0.3.3. Keep this PR in draft until publication is explicitly authorized. It does not deploy a gateway.

Validation

Focused migration annotation renders, release contract checks, and local chart packaging pass. The merged implementation passed chart CI and Jude's automated review in #8105. The earlier repository-wide local just ci run failed in unchanged ACP tests; it was not rerun for release notes. The registry manifest digest can only be verified after publication.

Signed-off-by: Tom Brow <tomb@block.xyz>
@brow

brow commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T18:56:37.099477Z 5ad2830 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5ad2830d52

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread deploy/charts/buzz-push-gateway/CHANGELOG.md
@brow
brow marked this pull request as ready for review October 5, 2026 18:54
@brow
brow requested a review from a team as a code owner October 5, 2026 18:54
@brow
brow deployed to codex-review October 5, 2026 18:54 — with GitHub Actions Active
@github-actions github-actions Bot added the codex-security-review-current The posted Codex security review matches its recorded range. label Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

🔐 Codex Security Review

Note: This is an automated, security-focused review generated by Codex.
Use it as a supplement to human review; false positives are possible.

Scope

  • Exact PR diff: fcf5f044b3af56f3855a417e61e4389fa925c1bd...4c8a1901490b744216e09dfdea4be4d08168f424
  • Model: gpt-5.6-sol

💡 Click "edited" above to see earlier reviews for this PR.


Review Summary

Overall Risk: NONE

The authorized range only adds release notes. The documented gatewayOrigin and migration.podAnnotations behavior matches the existing chart schema, values, templates, and tests. No concrete security, correctness, or reliability findings were identified.

Findings

No concrete security, correctness, or reliability findings were identified.

Notes

  • No additional limitations were reported.

Generated by Codex Security Review |
Requested by: @brow |
Workflow run

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5ad2830d52

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread deploy/charts/buzz-push-gateway/CHANGELOG.md

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review result: changes requested

Reviewed as :bot: Jude’s code review agent at exact head 5ad2830d52e562d4c4bceb2b77a1e57e582c7351 against base 0a070dfd3f3c233ea71bf390813abee4032068cb.

Blocking defect

The 0.3.3 release notes omit an operator-visible chart behavior change shipped since published 0.3.2.

deploy/charts/buzz-push-gateway/CHANGELOG.md:3-13 documents only #8105 (migration.podAnnotations). But the candidate package also includes #7877, which:

  • removes BUZZ_PUSH_GATEWAY_ORIGIN from the Deployment (templates/deployment.yaml:32-35);
  • makes gatewayOrigin optional at the chart root (values.schema.json:312-320); and
  • treats it solely as the routing origin required when httpRoute.enabled=true (values.schema.json:14-18, values.yaml:23-24).

The first-parent chart history from push-chart-v0.3.2 to this head contains #7877 and #8105, and the package delta against published 0.3.2 contains both changes. As written, operators relying on the in-chart changelog receive an incomplete account of upgrade behavior.

Author action: add a 0.3.3 bullet linking #7877 and stating that gatewayOrigin is now only an HTTPRoute routing input, is required only when the chart renders an HTTPRoute, and is no longer passed to the gateway container. Keep the existing migration-annotation note.

Verification owner: after the note is updated, :bot: Jude’s code review agent will re-check the new exact head against the published 0.3.2 package delta and rerun the release contract/package inspection.

Release integration and residual risk

The release machinery itself is coherent: merging the same-repo push-chart-release/0.3.3 branch creates push-chart-v0.3.3 at the merge commit; an existing tag is accepted only at that same SHA; the tag-triggered workflow validates the chart/version before OCI publication; and it does not deploy a gateway. Required approval plus authorized merge is the publication decision.

OCI digest stability is a pre-existing confidence gap, not a defect introduced by this PR: the workflow does not establish create-only registry semantics or record a digest, and reruns can invoke helm push for the same immutable source tag/version. The release owner should confirm post-merge tag binding, successful validation/publication, pull/show 0.3.3, and record/inspect the GHCR manifest digest. A bad published artifact must be corrected with a higher patch release, never by moving the tag or repairing 0.3.3 in place.

Evidence

  • Exact-head CI passed: chart lint/unit/render matrix, release validation, Semgrep, zizmor, DCO, and security review.
  • Local package inspection produced chart 0.3.3 with the changelog included.
  • Published 0.3.2 resolved at digest sha256:f3fdadd44bf95f72236a881e617792058982bce6f17ec147da5a632f775725a2; 0.3.3 correctly does not exist before merge.
  • git diff --check passed for the reviewed head.

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:bot: Jude’s code review agent

Verdict: REQUEST CHANGES
Reviewed: 0a070dfd3f3c233ea71bf390813abee4032068cb..5ad2830d52e562d4c4bceb2b77a1e57e582c7351 (exact live head 5ad2830d52e562d4c4bceb2b77a1e57e582c7351)
Risk: high — although the diff is one changelog file, merging this release branch authorizes tag creation and OCI publication of chart 0.3.3.

Behavior/contracts traced: published 0.3.2 → candidate 0.3.3 package delta; changelog completeness; release-branch merge trigger; chart-version/tag/merge-SHA binding; validation-before-publish; Git tag immutability; OCI publication and post-release recovery/verification; separation from gateway deployment.

Finding — blocking release-note defect: deploy/charts/buzz-push-gateway/CHANGELOG.md:3-13 describes 0.3.3 as only the migration Pod annotation change from #8105, but the candidate package differs from published 0.3.2 in a second operator-visible chart behavior from merged #7877. The 0.3.2 Deployment injects required BUZZ_PUSH_GATEWAY_ORIGIN (templates/deployment.yaml:35 at tag push-chart-v0.3.2); the 0.3.3 candidate removes that container environment variable and makes gatewayOrigin optional except when rendering an HTTPRoute (values.schema.json:14-18,312-320). Operators would receive an incomplete account of upgrade behavior from the in-chart changelog.

Author action: add a 0.3.3 bullet linking #7877 and state that gatewayOrigin is now only an optional HTTPRoute routing input, required when that route is enabled, and is no longer passed to the gateway container. Retain the migration annotation note.

Verification owner: author updates the notes; reviewer rechecks the new exact head against the published 0.3.2 package delta and exact-head release validation/package contents.

Release integration findings: the merge-triggered pipeline is otherwise coherent. The release branch/version creates immutable push-chart-v0.3.3 at the merge commit, the tag-triggered workflow validates chart version and renders before helm push, and no gateway deployment occurs. An existing tag at a different SHA fails closed. Registry digest stability/create-only behavior is not established pre-publication; that is a post-merge release-owner confidence gap, not a second author defect.

Validation at matching head:

  • PASS — exact live base/head, clean detached review trees, git diff --check.
  • PASS — local UTF-8 release-contract.sh and chart packaging; package reports chart 0.3.3 and includes the changelog.
  • PASS — exact-head Helm validate/render matrix, Semgrep, zizmor, DCO, and security checks.
  • PASS — published tag/package comparison establishes the omitted #7877 chart delta; first-parent release history contains #7877 and #8105 since push-chart-v0.3.2.

Manual/native evidence: not applicable; this is package/release workflow scope.

Residual risk / post-merge owner: release owner must verify tag→merge-SHA binding, successful validate/publish, helm show/pull --version 0.3.3, and record the GHCR digest. If publication fails, retry only from the immutable tag; if published content is wrong, issue a higher patch version rather than moving the tag or repairing 0.3.3 in place. Local full render was blocked by reviewer-host Xcode licensing, while exact-head Linux CI ran it successfully.

Signed-off-by: Tom Brow <tomb@block.xyz>
@brow

brow commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Added the missing #7877 routing-origin release note in 4c8a190. Verified the chart schema/template behavior and confirmed the packaged changelog describes both changes; release-contract validation passes.

@brow
brow dismissed stale reviews from jedwards27 and jedwards27 October 5, 2026 19:08

blockers resolved

@brow
brow requested a review from jedwards27 October 5, 2026 19:08
@brow
brow deployed to codex-review October 5, 2026 19:08 — with GitHub Actions Active
@github-actions github-actions Bot added codex-security-review-current The posted Codex security review matches its recorded range. and removed codex-security-review-current The posted Codex security review matches its recorded range. labels Oct 5, 2026

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review result: approved

Reviewed as :bot: Jude’s code review agent at exact head 4c8a1901490b744216e09dfdea4be4d08168f424 against base 0a070dfd3f3c233ea71bf390813abee4032068cb.

The remediation resolves the prior finding. Reconciliation against the published push-chart-v0.3.2 baseline found exactly two shipped operator behavior changes, and the 0.3.3 notes now cover both:

  • #7877: gatewayOrigin is HTTPRoute-only, optional unless httpRoute.enabled=true, and no longer passed to the gateway container as BUZZ_PUSH_GATEWAY_ORIGIN.
  • #8105: optional string-valued migration.podAnnotations, empty by default and scoped independently to the migration Job Pod template.

No additional shipped chart behavior was omitted; remaining package differences are the version bump and tests adapting/proving those behaviors.

Author action: none.

Validation

  • Exact live head and reviewed local head matched 4c8a1901490b744216e09dfdea4be4d08168f424; worktree was clean and git diff --check passed.
  • release-contract.sh, migration-annotations.sh, helm lint, default helm template, and helm package passed locally.
  • The package was version 0.3.3 and contained the reviewed changelog and complete chart payload.
  • Exact-head CI was terminal-green, including release validate, chart lint/unit/render matrix, DCO, Semgrep, zizmor, and security review.
  • Full local render.sh was blocked only by this reviewer host's unaccepted Xcode license in its Rust-backed subtest; exact-head Linux CI ran that lane successfully. This is a reviewer-tooling confidence limitation, not an author defect.

Release ownership / residual risk

Merge remains the publication authorization and does not deploy a gateway. The release owner owns post-merge confirmation that push-chart-v0.3.3 binds to the merge commit, publication succeeds, the OCI artifact is pullable, and the GHCR manifest digest/package contents match the reviewed release. A bad publication should be corrected with a higher patch release, never by moving the tag or mutating 0.3.3.

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:bot: Jude’s code review agent

Verdict: APPROVE
Reviewed: 0a070dfd3f3c233ea71bf390813abee4032068cb..4c8a1901490b744216e09dfdea4be4d08168f424 (exact live head 4c8a1901490b744216e09dfdea4be4d08168f424)
Risk: high — merging this release branch authorizes immutable tag creation and OCI publication of chart 0.3.3, despite the source delta being release notes only.

Behavior/contracts traced: complete published push-chart-v0.3.2→candidate package delta; changelog completeness; #7877 and #8105 behavior; merge-triggered tag/version/SHA binding; validation-before-publish; retry/recovery and separation from deployment.

Findings: no unresolved defect. The new #7877 note accurately states that gatewayOrigin is HTTPRoute-only, optional unless httpRoute.enabled=true, and no longer passed as BUZZ_PUSH_GATEWAY_ORIGIN. Together with the existing #8105 migration Pod annotation note, it covers every operator-visible chart behavior change since published 0.3.2. Remaining chart changes are version/test updates proving those two behaviors.

Author action: none.
Verification owner: release owner — after merge, verify push-chart-v0.3.3 targets the merge commit, validate/publish succeed, helm show/pull --version 0.3.3 works, package contents match the reviewed tree, and record the GHCR manifest digest.

Validation at matching head:

  • PASS — exact live base/head, clean trees, git diff --check.
  • PASS — release-contract.sh, focused migration-annotations.sh, helm lint, default render, and local helm package; archive identifies 0.3.3 and contains the exact changelog/chart payload.
  • PASS — full push-chart-v0.3.2..HEAD package/history reconciliation found only #7877 and #8105 operator behavior.
  • PASS — exact-head Helm validate/render matrix, DCO, Semgrep, zizmor, and security checks.

Manual/native evidence: not applicable; package/release workflow review.

Residual risk: the registry artifact/digest correctly cannot exist before publication. Git tag retries fail closed on a different target SHA, but OCI create-only/digest stability remains post-merge release-owner verification. If published content is wrong, issue a higher patch release; never move the tag or repair 0.3.3 in place. Local full render was blocked by reviewer-host Xcode licensing, while exact-head Linux CI ran the required render successfully.

@brow
brow merged commit c9143ed into main Oct 5, 2026
41 checks passed
@brow
brow deleted the push-chart-release/0.3.3 branch October 5, 2026 19:23

This branch was successfully deployed

1 active deployment
codex-review — 4c8a1901 Deployed Oct 5, 2026 by brow via Run Codex Security Review #6922
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

codex-security-review-current The posted Codex security review matches its recorded range.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants