Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 13 additions & 5 deletions .agents/skills/develop-maple-proxy/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -88,8 +88,8 @@ bodies as untrusted and potentially sensitive.

## Preserve publishing boundaries

Maple's current GitHub Release workflow builds, checksums, attests, uploads,
and re-verifies four native proxy archives. Maple v3.3.9 proved this integrated
Maple's GitHub Release workflow builds, checksums, attests, uploads, and
re-verifies four native proxy archives. Maple v3.3.9 proved this integrated
publication path for macOS arm64, Linux arm64, Linux x86_64, and Windows
x86_64. Never create a proxy GitHub tag or Release; a proxy-only binary fix
ships through a normal Maple patch release.
Expand All @@ -103,9 +103,17 @@ cargo package --locked --manifest-path proxy/Cargo.toml

If the proxy references a new `opensecret` version, publish that SDK crate
first. Do not publish either crate from Maple's application Release workflow.
The current root proxy container workflow builds without pushing; adding or
running a GHCR publisher is a separate production action requiring explicit
repository, version, image namespace, tag, and credential authority.
Root proxy container CI builds without pushing. After a successful stable Maple
Release, `.github/workflows/proxy-publish.yml` independently compares that
release's proxy version with the previous stable Maple Release. Unchanged
versions skip, including the unbackfilled 0.3.3 baseline. A strictly newer,
previously unpublished version automatically publishes Linux AMD64/ARM64 to
`ghcr.io/opensecretcloud/maple-proxy` with exact, minor, major, and `latest`
tags. The workflow is serialized, rejects rollback and stale releases, verifies
the public manifest, and supports manual retry from `master`. Maple's Actions
repository must retain write access to that existing organization-scoped GHCR
package. Treat any namespace, trigger, version policy, or package-access change
as a separate production-authority decision.

## Report

Expand Down
26 changes: 21 additions & 5 deletions .agents/skills/release-maple/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,10 @@ commit, external effect, and authority provided by the user.
their checksum manifest. Never create a separate proxy Release or proxy tag;
`/releases/latest` must continue to identify the Maple application release.
- Maple GitHub Releases do not publish `opensecret` or `maple-proxy` to
crates.io and do not push a GHCR image. Those are separately versioned,
separately authorized production mutations.
crates.io. A successful stable release starts a non-gating GHCR sibling that
publishes only when the proxy version changed from the previous stable Maple
Release; unchanged versions skip. The container remains separately versioned
at `ghcr.io/opensecretcloud/maple-proxy`.
- GitHub Release creation does not itself submit the release IPA or AAB to
Apple App Store review or Google Play.

Expand Down Expand Up @@ -165,6 +167,18 @@ gh run list --repo OpenSecretCloud/Maple --workflow 'Promote Pages production' \
--json databaseId,status,conclusion,headSha,createdAt,url
```

Also inspect the independent proxy-container publisher. It should either prove
the expected exact proxy version and public AMD64/ARM64 manifest or explicitly
skip because the proxy version did not change. Retry it with manual dispatch;
never create a proxy tag or Release and never rerun the core Release to repair
it:

```bash
gh run list --repo OpenSecretCloud/Maple --workflow 'Publish proxy container' \
--limit 10 \
--json databaseId,status,conclusion,headSha,createdAt,url
```

The updater workflow must publish the verified `latest.json` before reporting
the desktop updater control plane current. The Pages workflow advances the
machine-owned `pages-production` ref to the exact stable release SHA; its
Expand Down Expand Up @@ -228,9 +242,11 @@ nix develop --no-update-lock-file .#ci -c \
Confirm the release contains all four stable proxy archives and
`maple-proxy-release-final.sha256`, and that their attestations and the
published-asset verification job succeeded. Report the embedded proxy version
separately from the Maple application version. Do not report crates.io or GHCR
as updated unless their independent publisher was explicitly authorized and
verified.
separately from the Maple application version. Do not report crates.io as
updated unless its independent manual publisher was explicitly authorized and
verified. Report GHCR as published only after its sibling workflow and anonymous
manifest verification succeed; otherwise report the unchanged-version skip or
failure separately.

Verify that the hosted updater serves the same metadata as the GitHub Release:

Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/proxy-container.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ on:
branches: [master]
paths:
- ".github/workflows/proxy-container.yml"
- ".github/workflows/proxy-publish.yml"
- ".dockerignore"
- "proxy/Dockerfile"
- "proxy/Cargo.toml"
Expand All @@ -19,6 +20,7 @@ on:
pull_request:
paths:
- ".github/workflows/proxy-container.yml"
- ".github/workflows/proxy-publish.yml"
- ".dockerignore"
- "proxy/Dockerfile"
- "proxy/Cargo.toml"
Expand Down
Loading
Loading