From 85c947ecf204da1517439ff4a4cb2b6a42af14f3 Mon Sep 17 00:00:00 2001 From: Jim Meyer Date: Fri, 2 Oct 2026 08:57:26 -0700 Subject: [PATCH 1/4] ci(release): notify duty engineers of prerelease failures Signed-off-by: Jim Meyer --- .github/workflows/release-tag.yml | 27 +++++++++++++++++++++++++++ CI.md | 7 +++++++ 2 files changed, 34 insertions(+) diff --git a/.github/workflows/release-tag.yml b/.github/workflows/release-tag.yml index da0ef42df2..0c4c253533 100644 --- a/.github/workflows/release-tag.yml +++ b/.github/workflows/release-tag.yml @@ -777,6 +777,33 @@ jobs: echo "Published qualification summary to \`${ref}\`." >> "${GITHUB_STEP_SUMMARY}" + notify-prerelease-failure: + name: Notify Prerelease Failure + needs: [release-helm, publish-qualification] + if: failure() && contains(inputs.tag || github.ref_name, '-pre.') + runs-on: ubuntu-latest + timeout-minutes: 2 + permissions: {} + steps: + - name: Send Slack notification + continue-on-error: true + env: + # Configure this repository secret once the triage webhook is approved. + SLACK_WEBHOOK_URL: ${{ secrets.SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL }} + RUN_URL: ${{ format('{0}/{1}/actions/runs/{2}/attempts/{3}', github.server_url, github.repository, github.run_id, github.run_attempt) }} + run: | + set -euo pipefail + if [[ -z "${SLACK_WEBHOOK_URL}" ]]; then + echo "::notice::SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL is unset; skipping Slack notification." + exit 0 + fi + + message=":x: OpenShell prerelease ${RELEASE_TAG} failed (attempt ${GITHUB_RUN_ATTEMPT}). " + jq -n --arg text "${message}" --arg run_url "${RUN_URL}" \ + '{text: ($text + "\n<" + $run_url + "|View failed release run>"), unfurl_links: false, unfurl_media: false}' | + curl --fail --silent --show-error --connect-timeout 5 --max-time 15 \ + --header 'Content-Type: application/json' --data-binary @- "${SLACK_WEBHOOK_URL}" + publish-fern-docs: name: Sync and Publish Fern Docs needs: [compute-versions, release, publish-sdk-typescript, release-helm, trigger-wheel-publish] diff --git a/CI.md b/CI.md index cb7121b2cf..aec42e257c 100644 --- a/CI.md +++ b/CI.md @@ -194,6 +194,13 @@ temporarily informational for tagged releases: the existing findings were reviewed and accepted for v0.1.0 and will be addressed in 0.1.x releases. Scanner failures still fail qualification. +Failed prerelease attempts send a Slack notification mentioning +`@openshell-duty-eng` and linking to the specific attempt. Configure the triage +channel's incoming webhook as the repository secret +`SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL` to enable notifications. The notification +skips sending when the secret is unset, and delivery failures do not affect +release results. + ```shell gh workflow run security-scan.yml --ref main \ -f candidate_ref=v0.1.1-pre.1 \ From b28c5b1e98368676428b731975c4f260640dbb6e Mon Sep 17 00:00:00 2001 From: Jim Meyer Date: Fri, 2 Oct 2026 09:05:51 -0700 Subject: [PATCH 2/4] ci(release): make Slack triage mention configurable Signed-off-by: Jim Meyer --- .github/workflows/release-tag.yml | 7 +++++-- CI.md | 15 +++++++++------ 2 files changed, 14 insertions(+), 8 deletions(-) diff --git a/.github/workflows/release-tag.yml b/.github/workflows/release-tag.yml index 0c4c253533..b1b52d097d 100644 --- a/.github/workflows/release-tag.yml +++ b/.github/workflows/release-tag.yml @@ -788,8 +788,8 @@ jobs: - name: Send Slack notification continue-on-error: true env: - # Configure this repository secret once the triage webhook is approved. SLACK_WEBHOOK_URL: ${{ secrets.SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL }} + SLACK_MENTION: ${{ vars.SLACK_OPENSHELL_TRIAGE_MENTION }} RUN_URL: ${{ format('{0}/{1}/actions/runs/{2}/attempts/{3}', github.server_url, github.repository, github.run_id, github.run_attempt) }} run: | set -euo pipefail @@ -798,7 +798,10 @@ jobs: exit 0 fi - message=":x: OpenShell prerelease ${RELEASE_TAG} failed (attempt ${GITHUB_RUN_ATTEMPT}). " + message=":x: OpenShell prerelease ${RELEASE_TAG} failed (attempt ${GITHUB_RUN_ATTEMPT})." + if [[ -n "${SLACK_MENTION}" ]]; then + message+=" ${SLACK_MENTION}" + fi jq -n --arg text "${message}" --arg run_url "${RUN_URL}" \ '{text: ($text + "\n<" + $run_url + "|View failed release run>"), unfurl_links: false, unfurl_media: false}' | curl --fail --silent --show-error --connect-timeout 5 --max-time 15 \ diff --git a/CI.md b/CI.md index aec42e257c..2c7c0c9ea3 100644 --- a/CI.md +++ b/CI.md @@ -194,12 +194,15 @@ temporarily informational for tagged releases: the existing findings were reviewed and accepted for v0.1.0 and will be addressed in 0.1.x releases. Scanner failures still fail qualification. -Failed prerelease attempts send a Slack notification mentioning -`@openshell-duty-eng` and linking to the specific attempt. Configure the triage -channel's incoming webhook as the repository secret -`SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL` to enable notifications. The notification -skips sending when the secret is unset, and delivery failures do not affect -release results. +Failed prerelease attempts send a Slack notification linking to the specific +attempt. Configure the triage channel's incoming webhook as the repository +secret `SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL` to enable notifications. Set the +repository variable `SLACK_OPENSHELL_TRIAGE_MENTION` to the full Slack mention, +such as `` for `@openshell-duty-eng` or `<@USER_ID>` for a +user. Update both settings when moving to another Slack workspace. If the +mention variable is unset, the notification sends without a mention. The +notification skips sending when the secret is unset, and delivery failures do +not affect release results. ```shell gh workflow run security-scan.yml --ref main \ From 8273909514377cc3006c229e76b5a5e50093362a Mon Sep 17 00:00:00 2001 From: Jim Meyer Date: Fri, 2 Oct 2026 09:17:44 -0700 Subject: [PATCH 3/4] ci(release): keep Slack triage configuration in secrets Signed-off-by: Jim Meyer --- .github/workflows/release-tag.yml | 2 +- CI.md | 16 +++++++--------- 2 files changed, 8 insertions(+), 10 deletions(-) diff --git a/.github/workflows/release-tag.yml b/.github/workflows/release-tag.yml index b1b52d097d..c8c0f04a20 100644 --- a/.github/workflows/release-tag.yml +++ b/.github/workflows/release-tag.yml @@ -789,7 +789,7 @@ jobs: continue-on-error: true env: SLACK_WEBHOOK_URL: ${{ secrets.SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL }} - SLACK_MENTION: ${{ vars.SLACK_OPENSHELL_TRIAGE_MENTION }} + SLACK_MENTION: ${{ secrets.SLACK_OPENSHELL_TRIAGE_MENTION }} RUN_URL: ${{ format('{0}/{1}/actions/runs/{2}/attempts/{3}', github.server_url, github.repository, github.run_id, github.run_attempt) }} run: | set -euo pipefail diff --git a/CI.md b/CI.md index 2c7c0c9ea3..8b254ed1d2 100644 --- a/CI.md +++ b/CI.md @@ -194,15 +194,13 @@ temporarily informational for tagged releases: the existing findings were reviewed and accepted for v0.1.0 and will be addressed in 0.1.x releases. Scanner failures still fail qualification. -Failed prerelease attempts send a Slack notification linking to the specific -attempt. Configure the triage channel's incoming webhook as the repository -secret `SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL` to enable notifications. Set the -repository variable `SLACK_OPENSHELL_TRIAGE_MENTION` to the full Slack mention, -such as `` for `@openshell-duty-eng` or `<@USER_ID>` for a -user. Update both settings when moving to another Slack workspace. If the -mention variable is unset, the notification sends without a mention. The -notification skips sending when the secret is unset, and delivery failures do -not affect release results. +Notifications are sent to the triage channel via a webhook specified in +`SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL` and will at-mention the triage engineer so +that they can respond. The webhook and mention are stored in repository +secrets; the mention uses `SLACK_OPENSHELL_TRIAGE_MENTION`. Notifications link +to the specific failed prerelease attempt. An unset webhook skips sending, +and an unset mention sends without a mention. Delivery failures do not affect +release results. ```shell gh workflow run security-scan.yml --ref main \ From 4ef213029fbd1b5c224306716f23691cf4bfe55d Mon Sep 17 00:00:00 2001 From: Jim Meyer Date: Fri, 2 Oct 2026 09:26:50 -0700 Subject: [PATCH 4/4] docs(ci): clarify prerelease Slack notifications Signed-off-by: Jim Meyer --- CI.md | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/CI.md b/CI.md index 8b254ed1d2..58a9514681 100644 --- a/CI.md +++ b/CI.md @@ -194,13 +194,12 @@ temporarily informational for tagged releases: the existing findings were reviewed and accepted for v0.1.0 and will be addressed in 0.1.x releases. Scanner failures still fail qualification. -Notifications are sent to the triage channel via a webhook specified in -`SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL` and will at-mention the triage engineer so -that they can respond. The webhook and mention are stored in repository -secrets; the mention uses `SLACK_OPENSHELL_TRIAGE_MENTION`. Notifications link -to the specific failed prerelease attempt. An unset webhook skips sending, -and an unset mention sends without a mention. Delivery failures do not affect -release results. +Failed pre-release builds send notifications via Slack using a webhook and +at-mentioning the triage engineer with a link to the failure. The webhook is +stored in the repository secret `SLACK_OPENSHELL_TRIAGE_WEBHOOK_URL` and the +mention is stored in the repository secret `SLACK_OPENSHELL_TRIAGE_MENTION`. +Notifications are non-blocking and do not affect release results; an unset +webhook skips sending; an unset mention sends without a mention. ```shell gh workflow run security-scan.yml --ref main \