Publish to npm from a GitHub release - #24
Merged
Merged
Conversation
npm publish from Actions has been off since the docs got packed into the tarball: the build needs the product docs bundle, and that lives only in s3://mz-prod-docs-assets/export/mcp.json. Nothing serves it, and the CDN in front of that bucket caches for a day, so the release now reads the key from S3 like every other consumer. It assumes github-mcp-release, a new role in infra's iam-github-oidc that can GetObject that one key and nothing else. The existing github-ci role would also have worked, but it deploys lambdas, pushes images and assumes the sim deploy roles. npm auth is Trusted Publishing over OIDC, so there is no token to store and the tarball gets provenance. Two one-time setup steps, both in the README: the trusted publisher on npmjs.com, and the AWS_ROLE_ARN secret. Releasing by hand with make publish-all still works, and the workflow skips a version npm already has.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
npm publish from Actions has been off since #14 packed the docs into the tarball. The build needs the product docs bundle, and that lives only in
s3://mz-prod-docs-assets/export/mcp.json. Nothing serves it, and the CloudFront distribution in front of that bucket caches for a day, so the release reads the key from S3 like every other consumer does.It assumes
github-mcp-release, a new role in infra (mockzilla/infra PR below) that canGetObjectthat one key and nothing else. Adding this repo to the existinggithub-cirole would also have worked, but that role deploys lambdas, pushes images and assumes the sim deploy roles.npm auth is Trusted Publishing over OIDC, so there is no token to store and the tarball gets provenance.
Also bumps to 0.2.25, which is what this release ships.
Before merging
Two one-time setup steps, both written up in the README:
AWS_ROLE_ARNto thegithub_mcp_release_role_arnoutput.@mockzilla/mcp: repositorymockzilla/mockzilla-mcp, workflowpublish.yml.Notes
make publish-allby hand still works and stays the documented fallback.publish-mcp.ymlis untouched. It still runs by hand, and it already waits for the version to land on npm.