diff --git a/.gitea/workflows/publish.yml b/.gitea/workflows/publish.yml index 047f8bb..c7a9282 100644 --- a/.gitea/workflows/publish.yml +++ b/.gitea/workflows/publish.yml @@ -76,7 +76,7 @@ jobs: # Build from REPO ROOT (T-08-10): the Dockerfile copies the pnpm workspace manifest + # lockfile from the root context; building from apps/api/ would fail to find them. - - name: Build and push + - name: Build production image run: | set -euo pipefail docker build --target production \ @@ -84,11 +84,15 @@ jobs: -t ${{ steps.tags.outputs.latest }} \ -t ${{ steps.tags.outputs.sha_tag }} \ . - # Push the IMMUTABLE :- tag FIRST. set -euo pipefail stops on - # the first failed push, so :latest is only moved after the immutable, - # rollback-traceable tag has landed — a failed second push can never leave - # :latest advanced without a corresponding rollback tag (WR-04). - docker push ${{ steps.tags.outputs.sha_tag }} # immutable first + + # Push the IMMUTABLE :- tag FIRST. set -euo pipefail stops on + # the first failed push, so :latest is only moved after the immutable, + # rollback-traceable tag has landed — a failed second push can never leave + # :latest advanced without a corresponding rollback tag (WR-04). + - name: Push image + run: | + set -euo pipefail + docker push ${{ steps.tags.outputs.sha_tag }} # immutable first (WR-04) docker push ${{ steps.tags.outputs.latest }} # move pointer only after immutable lands # Always drop the stored credential from the runner after push (defence in depth).