Skip to content

build: route releases through OSS Exit Gate (b/515767982) - #25

Merged
teeler merged 1 commit into
googlecolab:mainfrom
teeler:oss-exit-gate-publish
May 26, 2026
Merged

teeler merged 1 commit into
googlecolab:mainfrom
teeler:oss-exit-gate-publish

Conversation

@teeler

@teeler teeler commented May 26, 2026 •

Copy link
Copy Markdown
Contributor

Configure OSS exit gate via build

Repoint the Cloud Build pipeline at the OSS Exit Gate AR repository so
that tag-triggered builds publish via the Exit Gate to PyPI instead of
to a private AR repo.

Changes:
- AR target: us-central1-python.pkg.dev/colab-cli-external/colab-cli/
  -> us-python.pkg.dev/oss-exit-gate-prod/google-colab-cli--pypi
  (us multi-region, not us-central1; Exit Gate owns the project.)
- New step `trigger-release`: after AR upload succeeds, write a
  `{"publish_all": true}` manifest and upload it to
  gs://oss-exit-gate-prod-projects-bucket/google-colab-cli/pypi/manifests/
  Exit Gate watches this path and starts the PyPI publish on upload.
- Renamed step `publish` -> `publish-to-ar` for clarity now that there
  are two publish-shaped steps.

`publish_all: true` is correct for this pipeline because the trigger
fires on a single tag push, the AR repo only contains the artifacts
for that tag at this moment, and Exit Gate auto-removes artifacts on
successful release.

The AR upload + manifest trigger run in the same Cloud Build (BCID L0).
If/when we move to BCID L1+ they must be split into two builds; see
go/oss-exit-gate-faq#why-manifest.

The Cloud Build service account (435011601433@cloudbuild.gserviceaccount.com)
is registered as the builder in
google3/configs/security/opensource/exit_gate/prod/projects/google-colab-cli/pypi/project.txtpb
which grants it write access to both the AR repo and the trigger bucket.
@teeler
teeler requested a review from sethtroisi May 26, 2026 17:49
@teeler
teeler merged commit 0aa77e5 into googlecolab:main May 26, 2026
6 checks passed
@teeler
teeler deleted the oss-exit-gate-publish branch May 26, 2026 20:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants