Skip to content

Release operations

CCB's experimental release workflow is triggered by relevant pushes to master and supports manual dispatch. It creates timestamped prerelease metadata, release notes from Git history, and a GitHub release, then coordinates platform/data artifacts such as translations, tilesets, shaders, desktop packages, and Android bundles.

Authority and sequencing

.github/workflows/release.yml and .github/workflows/release-android-bundle.yaml define the actual jobs, permissions, dependencies, artifact names, and triggers. doc/RELEASE_PROCESS.md provides background. Always inspect the workflow at the release commit before operating it.

  1. Confirm the target commit and default-branch CI state.
  2. Confirm translations, shader/tiles generation, version metadata, and platform build inputs.
  3. Trigger only the intended workflow/event; do not rerun unrelated old commits.
  4. Monitor every dependent job and preserve the run URL/logs.
  5. Compare release target SHA, notes range, tags, checksums, artifact set, signatures, and smoke test results before announcing the release.

Failure handling

A created GitHub release does not prove every artifact succeeded. If a downstream job fails, state exactly which artifacts are absent or superseded; repair the workflow/input in a PR and rerun deliberately. Never upload a locally improvised replacement under a trusted release name.

Security and permissions

Release tokens/signing material stay in GitHub secrets or protected environments. Human review is required for workflow, permission, signing, and destination changes. Current broad permissions are a security-review target; documentation must not claim least privilege until settings and workflow scopes demonstrate it.

Records and rollback

Retain release commit, tag, run IDs, artifact checksums, toolchain/dependency revisions, signing identity, Responsible human, known issues, and supersession/rollback decision. Prefer publishing a corrected/superseding release to silently replacing artifacts.

Validation

Smoke-test each distributed platform from the published artifact and verify data, mods, Lua, translations, graphics/audio, save/load, and upgrade behavior. Archive matching symbols and the documentation/API snapshot needed to diagnose that exact release.