Skip to content

Use source revisions for non-release Docker builds - #3357

Merged
SamMorrowDrums merged 1 commit into
mainfrom
jidicula/mcp-immutable-container-versions-20261001
Oct 1, 2026
Merged

SamMorrowDrums merged 1 commit into
mainfrom
jidicula/mcp-immutable-container-versions-20261001

Conversation

@jidicula

@jidicula jidicula commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Use release-tag versions only for tagged Docker builds, so branch, nightly and pull-request builds identify their full source revision.

Why

As part of improving GraphQL observability to service teams, as well as improving our GraphQL Platform team's own observability of the platform at large, we want client services to clearly identify themselves with their service name and version. This helps us clearly attribute traffic, which aids incident troubleshooting and performance investigations.

Follow-up to #3323: branch names such as main were being supplied as release versions, taking precedence over the available commit SHA.

What changed

Gate the Docker VERSION build argument on the ref type and document the build behaviour.

MCP impact

  • No tool or API changes. Header construction and runtime fallback logic are unchanged.

Prompts tested (tool changes only)

Not applicable; no tool changes.

Security / limits

  • No security or limits impact. Authentication and permissions are unchanged.

Tool renaming

  • I am not renaming tools as part of this PR.

Lint & tests

  • Linted in the Codespace with ./script/lint.
  • Tested in the Codespace with ./script/test.

Offline checks of the actual workflow expression and resulting compiled-binary headers passed. Container image publication was not exercised.

Docs

  • Updated README build-attribution documentation.

Only tag builds should supply a release version. Other Docker builds use the existing linked-commit fallback instead of treating a branch or pull-request ref name as a release.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 6dde41da-ec25-4370-b26c-b036d0a53b3c

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The workflow change correctly preserves release tags while allowing non-tag builds to resolve the embedded commit revision.

Review effort: Balanced
Findings: None

What changed in this PR

Ensures non-release Docker builds report their source revision rather than a branch name.

Changes:

  • Supplies tag names as versions only for tagged builds.
  • Documents Docker build-version attribution.
File Description
.github/​workflows/​docker-publish.yml Gates release-version injection on tag refs.
README.md Documents tag and source-revision behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@jidicula jidicula assigned jidicula and unassigned jidicula Oct 1, 2026
@jidicula
jidicula force-pushed the jidicula/mcp-immutable-container-versions-20261001 branch from 71f3e8a to 158205d Compare October 1, 2026 11:54
@jidicula
jidicula marked this pull request as ready for review October 1, 2026 12:02
@jidicula
jidicula requested a review from a team as a code owner October 1, 2026 12:02
@SamMorrowDrums
SamMorrowDrums merged commit a1f6500 into main Oct 1, 2026
19 checks passed
@SamMorrowDrums
SamMorrowDrums deleted the jidicula/mcp-immutable-container-versions-20261001 branch October 1, 2026 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants