ci: keep prereleases off the latest tag

`release: published` fires for prereleases too, and every manifest job pushed
`latest` unconditionally, so publishing a release candidate by hand would have
made it the image everyone pulls. The backend image had the same hole, so fix
all three rather than only the two added here.

A release the backend-release workflow calls is always stable, so the
workflow_call path keeps moving `latest`; the release-event path moves it only
when the release is not a prerelease.
This commit is contained in:
Alex committed 2026-09-12 22:19:27 +01:00
1 parent 7dd59519be
commit c18e26f798
3 files changed
+18 -5

No files matched your search

+6 -2
View File
@@ -142,11 +142,15 @@ jobs:
- name: Create and push multi-arch manifests
env:
TAG: ${{ env.RELEASE_TAG }}${{ matrix.variant }}
LATEST: latest${{ matrix.variant }}
# A stable release moves `latest`; a prerelease published by hand
# moves only its own tag (the release trigger fires for those too).
LATEST: ${{ (inputs.version || !github.event.release.prerelease) && format('latest{0}', matrix.variant) || '' }}
run: |
set -e
# $LATEST is deliberately unquoted: it is empty for a prerelease, and
# an empty word would create a manifest named "$repo:".
for repo in "$DOCKERHUB_NAMESPACE/docsgpt" "ghcr.io/${{ github.repository_owner }}/docsgpt"; do
for name in "$TAG" "$LATEST"; do
for name in "$TAG" $LATEST; do
docker manifest create "$repo:$name" \
--amend "$repo:$TAG-amd64" \
--amend "$repo:$TAG-arm64"
+8 -1
View File
@@ -26,6 +26,10 @@ permissions:
env:
# The tag being published: passed in by the caller, or the release's own.
RELEASE_TAG: ${{ inputs.version || github.event.release.tag_name }}
# A stable release also moves `latest`. A prerelease published by hand moves
# only its own tag: the release trigger fires for those too, and they must not
# become `latest`.
MOVING_TAG: ${{ (inputs.version || !github.event.release.prerelease) && 'latest' || '' }}
jobs:
build:
@@ -139,10 +143,13 @@ jobs:
- name: Create and push multi-arch manifests
env:
TAG: ${{ env.RELEASE_TAG }}
MOVING: ${{ env.MOVING_TAG }}
run: |
set -e
# $MOVING is deliberately unquoted: it is empty for a prerelease, and
# an empty word would create a manifest named "$repo:".
for repo in "$DOCKERHUB_NAMESPACE/docsgpt-fe" "ghcr.io/${{ github.repository_owner }}/docsgpt-fe"; do
for name in "$TAG" latest; do
for name in "$TAG" $MOVING; do
docker manifest create "$repo:$name" \
--amend "$repo:$TAG-amd64" \
--amend "$repo:$TAG-arm64"
+4 -2
View File
@@ -38,8 +38,10 @@ permissions:
env:
# The version being published, or `develop` for a push to main.
RELEASE_TAG: ${{ inputs.version || github.event.release.tag_name || 'develop' }}
# A release also moves `latest`; a push to main moves nothing but `develop`.
MOVING_TAG: ${{ (inputs.version || github.event.release.tag_name) && 'latest' || '' }}
# A stable release also moves `latest`. A push to main moves nothing but
# `develop`, and a prerelease published by hand moves only its own tag: the
# release trigger fires for those too, and they must not become `latest`.
MOVING_TAG: ${{ (inputs.version || (github.event.release.tag_name && !github.event.release.prerelease)) && 'latest' || '' }}
jobs:
build: