diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 1b39ed8f4..038d3cf49 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -5,6 +5,19 @@ on: tags: - "v*.*.*" +# One release at a time. Every build writes a buildx cache scope named after +# the service, so two releases running together export to the same scope and +# one of them loses the race: the layer blob it is writing disappears under it +# and the whole build ends on "error writing layer blob: not_found", after the +# compile succeeded. Tagging twice in quick succession is the ordinary way to +# hit that, and it reads as a broken build rather than a collision. +# +# Not cancel-in-progress: a release that is half-way through pushing images is +# the last thing that should be interrupted. The second tag waits its turn. +concurrency: + group: release + cancel-in-progress: false + env: REGISTRY: ghcr.io IMAGE_PREFIX: ghcr.io/${{ github.repository_owner }}/warmbly