name: release description: Playbook for cutting a proxyforward release — a tag drives the pipeline, which stops at a draft you must smoke-test and publish by hand. Releases are an escalation trigger: confirm with the human first.
Cut a release (playbook F)
Cutting or tagging a release is an escalation trigger — confirm with the human.
.github/workflows/release.yml does the build. It stops at a draft on purpose:
the smoke test below is the part that cannot be automated, and a draft is what
gives you the chance to run it before anyone can download the binary.
- Clean tree on
master; CI green (go test ./...,cd frontend && npm run build). - Tag and push:
git tag vX.Y.Z && git push origin vX.Y.Z. The workflow builds the exe and the NSIS installer, stamps the version via-ldflagsintointernal/version, asserts--versionreports the tag, writesSHA256SUMS.txtand an SPDX SBOM, and attaches a build-provenance attestation. - Smoke the draft's artifacts — download them, don't trust the build:
proxyforward.exe --versionshowsvX.Y.Z.- The exe launches to the wizard/console.
- The installer installs, launches, and uninstalls.
- A loopback pair (
gateway+agentheadless,docs/agent/commands.md) moves bytes.
- Publish the draft in the GitHub Releases UI.
- Update README + root CLAUDE.md if commands or claims changed.
What can go wrong
- A missing installer is silent.
wails build -nsisexits 0 and just skips the installer whenmakensisisn't on PATH, so the workflow installs NSIS itself and then asserts the file exists. If that assert fires, the toolchain broke — don't "fix" it by dropping-nsis. - The binaries are unsigned (no certificate). SmartScreen warns on first run.
The honest substitute is the attestation:
gh attestation verify <exe> -R xeri/proxyforward. - Windows only. The linux/macOS artifacts CI builds are never release assets — the engine can't start there (see the Reality check in CLAUDE.md).
Skills similaires
Architecte Docker Compose
DevOps
Concoit des configurations Docker Compose optimisees.
Claude CodeCopilotadvanced
430
156
1,651
Rapport de Post-Mortem
DevOps
Rédige des rapports post-mortem d'incidents structurés et blameless.
claudeCursorWindsurfintermediate
141
43
568
Créateur de Runbooks
DevOps
Crée des runbooks opérationnels clairs pour les procédures DevOps courantes.
claudeCursorWindsurfintermediate
108
32
501