From e1e3d399d350bc016b3adf3575b1d5f569f1c19e Mon Sep 17 00:00:00 2001 From: Josh Radcliff Date: Wed, 23 Sep 2026 10:42:32 -0400 Subject: [PATCH] ci(release): default DRY_RUN to true and validate boolean values Default DRY_RUN to "true" in .kokoro/release.sh when unset so that unparameterized or local builds cannot accidentally trigger a live release. Also validate at the start of the script that DRY_RUN is strictly "true" or "false" before building or modifying Artifact Registry staging packages. --- .kokoro/release.cfg | 3 +-- .kokoro/release.sh | 11 ++++++++++- 2 files changed, 11 insertions(+), 3 deletions(-) diff --git a/.kokoro/release.cfg b/.kokoro/release.cfg index f8051f7..ada8701 100644 --- a/.kokoro/release.cfg +++ b/.kokoro/release.cfg @@ -2,7 +2,7 @@ build_file: "github/data-manager-java/.kokoro/release.sh" -# Execute a dry run by default +# Default to DRY_RUN=true for safety; can be overridden via API or UI env_vars: { key: "DRY_RUN" value: "true" @@ -11,4 +11,3 @@ env_vars: { container_properties { docker_image: "us-central1-docker.pkg.dev/kokoro-container-bakery/kokoro/ubuntu/ubuntu2204/full:current" } - diff --git a/.kokoro/release.sh b/.kokoro/release.sh index 760a1cd..b4575fa 100755 --- a/.kokoro/release.sh +++ b/.kokoro/release.sh @@ -9,9 +9,18 @@ set -euo pipefail # Explicitly disable xtrace set +x +# Default to dry-run for safety unless DRY_RUN=false is explicitly passed. +DRY_RUN="${DRY_RUN:-true}" +if [[ "${DRY_RUN}" != "true" && "${DRY_RUN}" != "false" ]]; then + echo "ERROR: DRY_RUN must be 'true' or 'false' (got '${DRY_RUN}')." >&2 + exit 1 +fi + REPO_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" cd "${REPO_DIR}" +echo "=== Building and Releasing from: ${REPO_DIR} (DRY_RUN=${DRY_RUN}) ===" + # Ensure Java 17 is used on Kokoro Ubuntu 22.04 workers (which default to OpenJDK 11) if [[ ! -d "/usr/lib/jvm/java-17-openjdk-amd64" ]]; then echo "ERROR: Kokoro worker missing expected OpenJDK 17 at /usr/lib/jvm/java-17-openjdk-amd64" >&2 @@ -78,7 +87,7 @@ fi # ----------------------------------------------------------------------------- # 3. DRY_RUN Check # ----------------------------------------------------------------------------- -if [[ "${DRY_RUN:-false}" == "true" ]]; then +if [[ "${DRY_RUN}" == "true" ]]; then echo "=== DRY_RUN is enabled. Artifacts staged in Artifact Registry. ===" echo "Skipping GCS manifest upload to Exit Gate." exit 0