From 63e53f21bdd34f5e1cfb8b8a890b347203517a6f Mon Sep 17 00:00:00 2001 From: Josh Radcliff Date: Wed, 23 Sep 2026 10:42:17 -0400 Subject: [PATCH] ci(release): default DRY_RUN to true and validate boolean values Default DRY_RUN to "true" in .kokoro/release.sh when unset so that unparameterized or local builds cannot accidentally trigger a live release. Also validate at the start of the script that DRY_RUN is strictly "true" or "false" before building or modifying Artifact Registry staging packages. Change-Id: Icf2c57dd1407cb4ee5e563d98fa8f7ee22099845 --- .kokoro/release.cfg | 3 +-- .kokoro/release.sh | 11 +++++++++-- 2 files changed, 10 insertions(+), 4 deletions(-) diff --git a/.kokoro/release.cfg b/.kokoro/release.cfg index 815d569..4e1dfb0 100644 --- a/.kokoro/release.cfg +++ b/.kokoro/release.cfg @@ -2,7 +2,7 @@ build_file: "github/data-manager-python/.kokoro/release.sh" -# TODO: Remove after verifying uploads to artifact registry are WAI. +# Default to DRY_RUN=true for safety; can be overridden via API or UI env_vars: { key: "DRY_RUN" value: "true" @@ -11,4 +11,3 @@ env_vars: { container_properties { docker_image: "us-central1-docker.pkg.dev/kokoro-container-bakery/kokoro/ubuntu/ubuntu2204/full:current" } - diff --git a/.kokoro/release.sh b/.kokoro/release.sh index af6da48..fd66510 100755 --- a/.kokoro/release.sh +++ b/.kokoro/release.sh @@ -1,6 +1,13 @@ #!/bin/bash set -euo pipefail +# Default to dry-run for safety unless DRY_RUN=false is explicitly passed. +DRY_RUN="${DRY_RUN:-true}" +if [[ "${DRY_RUN}" != "true" && "${DRY_RUN}" != "false" ]]; then + echo "ERROR: DRY_RUN must be 'true' or 'false' (got '${DRY_RUN}')." >&2 + exit 1 +fi + # ----------------------------------------------------------------------------- # 1. Workspace & Directory Resolution # ----------------------------------------------------------------------------- @@ -8,7 +15,7 @@ set -euo pipefail REPO_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" cd "${REPO_DIR}" -echo "=== Building and Releasing from: ${REPO_DIR} ===" +echo "=== Building and Releasing from: ${REPO_DIR} (DRY_RUN=${DRY_RUN}) ===" # ----------------------------------------------------------------------------- # 2. Environment & Tooling Setup @@ -77,7 +84,7 @@ twine upload --repository-url "${EXIT_GATE_REPO}" dist/* # ----------------------------------------------------------------------------- # If DRY_RUN is set to "true", stop here so you can verify the AR staging # without publishing to public PyPI. -if [[ "${DRY_RUN:-false}" == "true" ]]; then +if [[ "${DRY_RUN}" == "true" ]]; then echo "=== DRY_RUN is enabled. Skipping manifest upload to Exit Gate. ===" echo "Artifacts are staged in Artifact Registry." exit 0