From ccaa1aeaa17bdbc3a751b67d6bdaa8a86c53557b Mon Sep 17 00:00:00 2001 From: Mehran Mazhar Date: Fri, 25 Sep 2026 19:12:26 +0300 Subject: [PATCH] ci: name the image's tag in the deploy-stage dispatch clutch-deploy now pins every image to an exact tag and deploys only what is pinned (clutch-deploy #103). So the dispatch after an image build carries the tag that build pushed, sha-, as client_payload.set_images. clutch-deploy pins it for stage only. The mainnet validators keep their own pin, which moves only in a planned upgrade. This merge rebuilds the image, because the workflow lists its own file in its paths. The stage validators then run that build of the same code. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/docker-build-push.yml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/workflows/docker-build-push.yml b/.github/workflows/docker-build-push.yml index f4f73e5..bfa6b0a 100644 --- a/.github/workflows/docker-build-push.yml +++ b/.github/workflows/docker-build-push.yml @@ -178,12 +178,21 @@ jobs: exit 1 fi + # clutch-deploy pins every image to an exact tag and deploys only what is pinned, so the + # dispatch names the tag this run pushed: metadata-action's type=sha, sha-. clutch-deploy checks that ghcr.io has it and pins it for STAGE only. The mainnet + # validators keep their own pin, which moves only in a planned upgrade. + - name: Name the tag this run pushed + id: tag + run: echo "sha=sha-${GITHUB_SHA::7}" >> "$GITHUB_OUTPUT" + - name: Trigger deploy-stage in clutch-deploy uses: peter-evans/repository-dispatch@v3 with: token: ${{ secrets.CLUTCH_DEPLOY_DISPATCH_TOKEN }} repository: clutchprotocol/clutch-deploy event-type: deploy-stage + client-payload: '{"set_images": "clutch-node=${{ steps.tag.outputs.sha }}"}' - name: What this proves, and what it does not run: |