Skip to content

chore: new release processes - #1090

Open
joaodordio wants to merge 6 commits into
masterfrom
chore/new-release-processes
Open

joaodordio wants to merge 6 commits into
masterfrom
chore/new-release-processes

Conversation

@joaodordio

@joaodordio joaodordio commented Sep 11, 2026 •

Copy link
Copy Markdown
Member

Summary

Replaces the existing ad-hoc release workflows with a standardized two-step process across all SDKs.

No customer facing changes

Workflow 1: Prepare Release (workflow_dispatch)

Inputs: version, ticket

  • Updates CHANGELOG.md (promotes [Unreleased] to new version section)
  • Bumps all version files
  • Opens a release PR with a checklist
  • Creates a GitHub draft release (no tag on master until Publish; premature tags from gh are removed)

Workflow 2: Publish Release (workflow_dispatch)

Input: version

  • Verifies the prepare-release PR has been merged (checks CHANGELOG on master/main)
  • Publishes the draft release (or retries Maven Central if the GitHub release is already public)
  • Forces the release tag to the merged master HEAD, then publishes to Maven Central (Sonatype)
  • Posts to #eng-sdk-team on Slack

Files changed

  • Added .github/workflows/publish-release.yml
  • Modified .github/workflows/prepare-release.yml (replaces legacy publish flow)
  • Deleted .github/workflows/publish.yml

Secrets and variables to configure

Before the first Prepare or Publish run, configure in repo Settings → Secrets and variables → Actions:

Kind Name Purpose
Variable ITERABLE_SDK_RELEASE_APP_ID GitHub App id for iterable-sdk-release (mint token for PR/release steps)
Secret ITERABLE_SDK_RELEASE_APP_PRIVATE_KEY PEM private key for that app
Secret SLACK_WEBHOOK #eng-sdk-team notification on successful/failed publish
Secret GPG_PRIVATE_KEY, GPG_PASSPHRASE, GPG_KEY_ID Artifact signing (publish only)
Secret SONATYPE_USERNAME, SONATYPE_PASSWORD Maven Central upload (publish only)

Related: [SDK Release Process Team Agreement 2026-09-11]

No customer facing changes

Replaces the monolithic release workflow with a two-step process:
- Prepare Release: bumps version, updates changelog, opens PR, creates GitHub draft release
- Publish Release: promotes draft, tags master/main, publishes to distribution, posts Slack

Ref: SDK release process team agreement 2026-09-11
@joaodordio
joaodordio requested a review from a team as a code owner September 11, 2026 18:04
@jferrao-itrbl

Copy link
Copy Markdown

This PR does not touch CHANGELOG.md and the body does not contain No customer facing changes. .github/workflows/changelog-check.yml and rules/reviewer.md require one or the other. this change is operator-facing CI, not an SDK behaviour change.

Either put No customer facing changes in the PR body (or add a changelog line if you consider this customer-facing).

… grep

- Add ref: master/main to actions/checkout in all prepare/publish workflows
  so workflows always operate on the default branch regardless of dispatch ref
- Replace shell-injection-prone ${{ steps...outputs.notes }} pattern with
  --notes-file using $RUNNER_TEMP/release-notes.md (safe from backticks/quotes
  in changelog content)
- Treat empty [Unreleased] section as a hard error in prepare-release
- Fix CHANGELOG verification grep: grep -qE "^## \[VERSION\]" (anchored,
  prevents substring matches and prefix collisions like 3.1.0 vs 3.1.0-rc1)
Replace SDK_RELEASE_TOKEN (iOS) and GITHUB_TOKEN (all repos) with a
short-lived installation token from the iterable-sdk-release GitHub App,
generated via actions/create-github-app-token@v1.

Benefits:
- App token triggers CI on PRs it creates (GITHUB_TOKEN cannot)
- 1h TTL vs long-lived PAT
- Workflow-scoped permissions so we can push .github/workflows/ files

Required credentials (repo variable + secret, or set at org level):
  vars.ITERABLE_SDK_RELEASE_APP_ID
  secrets.ITERABLE_SDK_RELEASE_APP_PRIVATE_KEY
@jferrao-itrbl

Copy link
Copy Markdown

*PR body “Secrets to add”: Still only mentions SLACK_WEBHOOK.

What the code does: Prepare and Publish require vars.ITERABLE_SDK_RELEASE_APP_ID and secrets.ITERABLE_SDK_RELEASE_APP_PRIVATE_KEY.

What the spec says: This PR’s “Secrets to add” is the operator checklist for the first run.

Why it conflicts: First Prepare/Publish will fail at token mint if those are missing; the PR body does not mention them.

Suggested action: Document the App id/variable and private-key secret alongside SLACK_WEBHOOK

Normalize Jira ticket input, add iterable-docs placeholder for validate-release,
publish GitHub release before Maven Central, and handle prerelease vs latest.
@jferrao-itrbl
jferrao-itrbl force-pushed the chore/new-release-processes branch from 7f2ee68 to cf931f9 Compare October 6, 2026 12:20
Allow Publish to re-run Maven Central when the GitHub release is already
public, force the release tag to merged master HEAD, strip premature draft
tags from Prepare, drop no-op version sed lines, and narrow Slack failure alerts.
Annotated -fa opens an editor on the runner; -f moves the tag without prompting.
@jferrao-itrbl
jferrao-itrbl self-requested a review October 6, 2026 13:48
Comment thread .github/workflows/publish-release.yml Outdated
Comment thread .github/workflows/prepare-release.yml
Comment thread .github/workflows/prepare-release.yml
Comment thread .github/workflows/publish-release.yml Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants