From f615c3f4d519bc47d56550e86f9385f97c24520d Mon Sep 17 00:00:00 2001 From: Matthew Meszaros Date: Sun, 20 Sep 2026 15:57:02 +0200 Subject: [PATCH] feat: serialize release workflow runs on one concurrency group so two tags pushed close together queue instead of racing the shared buildx cache scope and failing the second build on a missing layer blob --- .github/workflows/release.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 1b39ed8f4..038d3cf49 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -5,6 +5,19 @@ on: tags: - "v*.*.*" +# One release at a time. Every build writes a buildx cache scope named after +# the service, so two releases running together export to the same scope and +# one of them loses the race: the layer blob it is writing disappears under it +# and the whole build ends on "error writing layer blob: not_found", after the +# compile succeeded. Tagging twice in quick succession is the ordinary way to +# hit that, and it reads as a broken build rather than a collision. +# +# Not cancel-in-progress: a release that is half-way through pushing images is +# the last thing that should be interrupted. The second tag waits its turn. +concurrency: + group: release + cancel-in-progress: false + env: REGISTRY: ghcr.io IMAGE_PREFIX: ghcr.io/${{ github.repository_owner }}/warmbly