build: route releases through OSS Exit Gate (b/515767982) - #25
Merged
Merged
Conversation
Repoint the Cloud Build pipeline at the OSS Exit Gate AR repository so
that tag-triggered builds publish via the Exit Gate to PyPI instead of
to a private AR repo.
Changes:
- AR target: us-central1-python.pkg.dev/colab-cli-external/colab-cli/
-> us-python.pkg.dev/oss-exit-gate-prod/google-colab-cli--pypi
(us multi-region, not us-central1; Exit Gate owns the project.)
- New step `trigger-release`: after AR upload succeeds, write a
`{"publish_all": true}` manifest and upload it to
gs://oss-exit-gate-prod-projects-bucket/google-colab-cli/pypi/manifests/
Exit Gate watches this path and starts the PyPI publish on upload.
- Renamed step `publish` -> `publish-to-ar` for clarity now that there
are two publish-shaped steps.
`publish_all: true` is correct for this pipeline because the trigger
fires on a single tag push, the AR repo only contains the artifacts
for that tag at this moment, and Exit Gate auto-removes artifacts on
successful release.
The AR upload + manifest trigger run in the same Cloud Build (BCID L0).
If/when we move to BCID L1+ they must be split into two builds; see
go/oss-exit-gate-faq#why-manifest.
The Cloud Build service account (435011601433@cloudbuild.gserviceaccount.com)
is registered as the builder in
google3/configs/security/opensource/exit_gate/prod/projects/google-colab-cli/pypi/project.txtpb
which grants it write access to both the AR repo and the trigger bucket.
sethtroisi
approved these changes
May 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Configure OSS exit gate via build