Skip to content

ci: publish images to SWR and limit the workflow token permissions - #30

Merged
Aloento merged 2 commits into
mainfrom
chore/swr-image-publishing
Sep 23, 2026
Merged

Aloento merged 2 commits into
mainfrom
chore/swr-image-publishing

Conversation

@Aloento

@Aloento Aloento commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

Publishes images to OTC SWR instead of quay.io, mirroring the StatusDashboard-Backend workflow: stackmon-preprod for main and manual runs, stackmon for releases, and the change_<pr>_latest tag is dropped. Zuul is retired and no quay.io credentials exist in this repository, so the previous path never ran.

Also sets permissions: contents: read in ci.yml; both jobs only read the repository, and CodeQL reported actions/missing-workflow-permissions for them.

Verified with actionlint (no findings) and a diff against the backend workflow, which differs only in PROJECT and target: metrics-processor. The publish-preprod and publish jobs run only on main or a release, so the SWR login and push are not exercised by this PR.

@Aloento
Aloento added this pull request to stack #31 September 23, 2026 17:05
Base automatically changed from chore/migrate-ci-to-gha to main September 23, 2026 17:05
Zuul is retired and the repository has no quay.io credentials, so the previous
publish path could never run. SWR is the native OTC registry and
StatusDashboard-Backend already publishes there; align both workflows.
The test and coverage jobs inherited the default write token, which CodeQL reports as actions/missing-workflow-permissions; both only read the repository.
@Aloento
Aloento force-pushed the chore/swr-image-publishing branch from d1eacde to 6bd1741 Compare September 23, 2026 17:10
@Aloento Aloento changed the title chore: publish images to SWR ci: publish images to SWR and limit the workflow token permissions Sep 23, 2026
@Aloento
Aloento merged commit 80e2aec into main Sep 23, 2026
9 checks passed
@Aloento
Aloento deleted the chore/swr-image-publishing branch September 23, 2026 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant