Skip to content

DEVOPS-1131: Use ref_name and add release tag validation in python_deploy_prod.yml - #92

Open
RomFloreani wants to merge 1 commit into
developfrom
DEVOPS-1131
Open

DEVOPS-1131: Use ref_name and add release tag validation in python_deploy_prod.yml#92
RomFloreani wants to merge 1 commit into
developfrom
DEVOPS-1131

Conversation

@RomFloreani

@RomFloreaniRomFloreani commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

DEVOPS-1131 - python_deploy_prod workflow to use tag from revision: no manual input
Use github.ref_name instead of workflow_dispatch input release-tag, and add a validate-release-tag job to fail fast when the workflow is not run from a tag.

Mirrors the change made in MiraGeoscience/simpeg#167.

CopilotAI lite review requested due to automatic review settings August 26, 2026 17:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the production Python deploy workflow to derive the release tag from the Git reference (github.ref_name) and adds an early validation step to prevent manual runs from non-tag refs, aligning release publishing behavior with the intended release-tag source.

Changes:

  • Removed workflow_dispatch input release-tag and switched consumers to github.ref_name.
  • Added a validate-release-tag job to fail fast when manually dispatched from a non-tag ref.
  • Updated concurrency grouping and downstream reusable workflow inputs to use the resolved tag name.
Suppressed comments (1)

.github/workflows/python_deploy_prod.yml:57

  • With validate-release-tag gated to only run on workflow_dispatch, this job’s if: should also explicitly allow needs.validate-release-tag.result == 'skipped' for release events (and still require success for workflow_dispatch). Otherwise the publish job can be skipped depending on how the validation job is conditioned.
 needs: validate-release-tag
if: ${{ github.event_name == 'release' || github.event.inputs.publish-pypi == 'true' }}

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +27 to 43
validate-release-tag:
name: Validate release tag
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Ensure this run was triggered from a tag
if: ${{ github.event_name == 'workflow_dispatch' && github.ref_type != 'tag' }}
env:
REF_TYPE: ${{ github.ref_type }}
REF_NAME: ${{ github.ref_name }}
run: |
echo "::error::This run was not triggered from a tag (ref_type=$REF_TYPE, ref_name=$REF_NAME). Re-run this workflow selecting the release tag under 'Use workflow from'."
exit 1
call-workflow-conda-release:
name: Publish production Conda package on JFrog Artifactory
needs: validate-release-tag
if: ${{ github.event_name == 'release' || github.event.inputs.publish-conda == 'true' }}
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@RomFloreani