Skip to content

Add automated Logic4 QA beta releases - #81

Merged
rubenwebparking merged 3 commits into
masterfrom
feature/beta-tracking
Sep 17, 2026
Merged

rubenwebparking merged 3 commits into
masterfrom
feature/beta-tracking

Conversation

@lreijmer

@lreijmer lreijmer commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Add a secure beta-release pipeline that generates the client from the Logic4 QA API documentation without affecting stable production releases.

Changes

  • Add selectable production and qa documentation sources.
  • Add composer generate-beta-endpoints.
  • Keep production and QA OpenAPI caches separate.
  • Add fixture-based tests for source discovery and URL validation.
  • Add documentation for generating and installing beta versions.

Beta-release workflow

The new workflow runs daily at 08:00 UTC.

Scheduled runs:

  1. Generate the client from the named QA v3 and v3.1 schemas.
  2. Stop when the generated source has not changed.
  3. Run all quality gates when changes are detected.
  4. Upload a checksummed beta-candidate artifact.
  5. Never publish automatically.

Publishing requires a manual run from master with:

  • publish enabled.
  • A base_version, or the BETA_BASE_VERSION repository variable.
  • Approval through the protected beta-release environment.

The workflow then creates the next prerelease tag, such as v4.1.0-beta.1. It skips publishing when the generated source already matches the latest beta in that version series.

Security

  • Generation runs with read-only repository permissions.
  • Publishing is restricted to master.
  • Write permission is isolated to the environment-protected release job.
  • Checkout credentials are not persisted.
  • Candidate artifacts are checksummed and retested before publishing.
  • External actions are pinned to immutable commit SHAs.
  • Scalar source URLs are restricted to the selected Logic4 environment.

Verification

  • Production endpoint generation
  • QA endpoint generation
  • Actionlint
  • Composer validation
  • PHPStan level 8
  • PHP-CS-Fixer
  • PHPUnit: 18 tests, 80 assertions
  • 100% code coverage
  • Composer security audit: no known advisories

At the time of testing, QA and production generated identical client source, so the workflow correctly produced no beta changes.

@lreijmer lreijmer self-assigned this Sep 16, 2026
@rubenwebparking
rubenwebparking merged commit e02efb4 into master Sep 17, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants