[ 
https://issues.apache.org/jira/browse/THRIFT-6327?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jens Geyer resolved THRIFT-6327.
--------------------------------
      Assignee: Jens Geyer
    Resolution: Fixed

> Document the credentials the release workflows need in one place
> ----------------------------------------------------------------
>
>                 Key: THRIFT-6327
>                 URL: https://issues.apache.org/jira/browse/THRIFT-6327
>             Project: Thrift
>          Issue Type: Improvement
>          Components: Build Process
>            Reporter: Jens Geyer
>            Assignee: Jens Geyer
>            Priority: Minor
>             Fix For: 0.26.0
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> h2. Situation
> Six workflows publish something when a release is published: {{pypi.yml}}, 
> {{release_ruby.yml}}, {{release_rust.yml}}, {{dotnet-tool.yml}}, 
> {{winget.yml}} and {{chocolatey.yml}}. Between them they need one repository 
> variable, two repository secrets and four trusted publishing policies 
> configured on the receiving side.
> Every one of those is documented, and no two of them are documented in the 
> same place. {{doc/ReleaseManagement.md}} mentions {{CHOCO_API_KEY}} inside 
> the Chocolatey prose, {{WINGET_TOKEN}} inside the WinGet prose, and the NuGet 
> policy and {{NUGET_USER}} inside a bullet under "Third Party Package 
> Managers"; the PyPI policy is in the pypi bullet; the crates.io and RubyGems 
> ones are not described at all.
> So a release manager who wants to know what has to be set up before their 
> first release has no way to find out other than reading the whole document, 
> and a new one cannot tell which failures are "not configured yet" from which 
> are real.
> h2. Change
> Add one section to {{doc/ReleaseManagement.md}} listing what the release 
> automation needs: the name, whether it is a secret or a variable, what it is, 
> which workflow consumes it, and what happens when it is missing.
> The per package prose stays where it is. The new section is the lookup, and 
> it links into that prose rather than repeating it.
> Worth recording in the same place, because it is not obvious from the outside:
> * Four of the six publish over trusted publishing and hold no stored 
> credential at all - PyPI, RubyGems, crates.io and NuGet. Only WinGet and 
> Chocolatey use a stored secret, and only because neither has an OIDC path.
> * {{WINGET_TOKEN}} has to be a *classic* personal access token. Fine grained 
> tokens are not supported by {{wingetcreate}}.
> * The WinGet and Chocolatey steps do not fail when their secret is absent: 
> they build and upload the artifact, write a warning and say in the run 
> summary how to publish by hand. That is deliberate, so that a missing secret 
> cannot fail a release, but it does mean a green run is not proof that 
> anything was published.
> _Drafted with AI assistance (Claude Opus 5); reviewed and posted by Jens 
> Geyer._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to