Skip to content

ci: delete release-legacy.yml, move upload-to-s3.sh into .circleci/ [IDE-2483] - #465

Draft
rrama wants to merge 1 commit into
ci/IDE-2483_add-publish-stable-jobfrom
ci/IDE-2483_remove-legacy-release-workflow
Draft

rrama wants to merge 1 commit into
ci/IDE-2483_add-publish-stable-jobfrom
ci/IDE-2483_remove-legacy-release-workflow

Conversation

@rrama

@rrama rrama commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Final milestone (4 of 4) of IDE-2483 — migrating S3 publishing off static AWS
keys onto CircleCI OIDC. Stacked on #468.

What this PR does (safe to merge from a code-review standpoint)

  • Deletes .github/workflows/release-legacy.yml — the GitHub Actions fallback
    kept while the CircleCI stable-release pipeline was unproven. Its function
    is fully replaced by the CircleCI publish-stable job (added in ci: add publish-stable job with CircleCI OIDC, rename release.yml to legacy fallback [IDE-2483] #468).
  • Moves .github/upload-to-s3.sh to .circleci/upload-to-s3.sh — nothing
    under .github/ uses it anymore once the legacy workflow is gone.
  • Updates the three .circleci/config.yml references to the script's new path
    (build-sign's persist_to_workspace, publish-preview, publish-stable).
  • Deletes the "CircleCI unproven, use release-legacy.yml as fallback" migration
    note from RELEASE.md — this PR is that migration.

circleci config validate passes.

Why this is do-not-merge

Merging now would delete the still-actively-used GitHub Actions fallback
before its CircleCI replacement is proven end-to-end. Per the ticket's own
"verify before deactivate, deactivate before delete" ordering, this PR stays
gated until:

Blocker before merge:

  1. One real stable release is cut successfully end-to-end through the new
    CircleCI stable-release pipeline (tag, GitHub release with asset, and
    s3://snyk-assets/eclipse/stable/ all confirmed).

(circleci-infra PR #66 formalizes the already-existing
snyk-eclipse-plugin-github-release CircleCI context in Terraform — it
doesn't gate this merge, since the context already works per #468.)

The diff is reviewable now regardless — opening it ready-for-review means
merge is one click the moment the gate lifts, matching #468's own convention.

Post-merge decommissioning runbook (execute in order — do NOT skip steps; each gates the next)

Prerequisite (already gates this PR's merge): at least one real stable
release has been cut successfully through the new CircleCI stable-release
pipeline.

  • 1. Merge this PR (deletes release-legacy.yml, moves the S3 upload
    script into .circleci/).
  • 2. AWS Console, account 198361731867 → IAM → Users → find the user
    that owns the access key currently populating the GitHub secret
    AWS_ACCESS_KEY_ID. Note the user's name and the access key's ID. Verify
    the key hasn't already been deactivated by someone else.
  • 3. In the same IAM Users page, deactivate the access key
    (Security credentials tab → Access keys → three-dot menu → Deactivate).
    Do NOT delete yet — deactivation is reversible; deletion is not.
  • 4. Wait ≥1 week OR one more natural stable release cycle, whichever
    comes first. During that window, cut at least one real stable release
    through CircleCI. Confirm it succeeds end-to-end: tag appears, GitHub
    release appears with the ZIP asset, s3://snyk-assets/eclipse/stable/
    has the fresh artifact. This is the "publishing confirmed still
    working" AC step.

    - Rollback if step 4 fails: re-activate the access key (reverse of
    step 3). Investigate why the CircleCI OIDC path failed. Do not
    proceed to step 5 until step 4 has been re-run and passed.
  • 5. IAM console: delete the access key.
  • 6. IAM console: check the IAM user's permissions and other attached
    policies. If it exists solely to hold this access key for this repo's
    publishing, delete the IAM user too. If it also holds other policies
    or roles used elsewhere, leave the user in place — flag it in the
    ticket comment at step 11.
  • 7. GitHub repo settings → Secrets and variables → Actions → delete
    AWS_ACCESS_KEY_ID.
  • 8. GitHub repo settings → Secrets and variables → Actions → delete
    AWS_SECRET_ACCESS_KEY.
  • 9. GitHub repo settings → Secrets and variables → Actions → delete
    AWS_S3_BUCKET_NAME. Nothing reads it after this PR merges —
    readme-sync.yml (the only other workflow left) only uses GITHUB_TOKEN.
  • 10. GitHub repo settings → Secrets and variables → Actions → delete
    KEYSTORE, KEYSTORE_SHA, KEYSTORE_PASS. These are only read by
    release-legacy.yml, which no longer exists after this PR merges.
    CircleCI's build-sign uses same-named variables but sources them from
    the snyk-eclipse-plugin-signing CircleCI context, not from GitHub
    secrets.
  • 11. Post a comment on IDE-2483 listing exactly which steps were
    executed and when (dates + IAM key ID + IAM user name if deleted).
    Transition IDE-2483 to Done. Notify #ide Slack channel that the
    decommissioning is complete.

Re-check (after step 11) — run in a fresh clone of main

git grep -n -E 'AWS_ACCESS_KEY_ID|AWS_SECRET_ACCESS_KEY'
git grep -n 'release-legacy\.yml'
git grep -n 'release\.yml'
git grep -n '\.github/upload-to-s3\.sh'
ls .github/upload-to-s3.sh 2>/dev/null
ls .github/workflows/release-legacy.yml 2>/dev/null

Every command must return zero hits / not exist.

PR stack — merge order

flowchart LR
    main(["main"])
    PR1["#460 build-sign\nCircleCI signing"]
    PR2["#462 publish-preview\nCircleCI OIDC publish"]
    PR3["#463 stable-release scaffold\nworkflow + build-sign-stable"]
    PR4["#468 publish-stable\nOIDC publish"]
    PR5["remove-legacy-release-workflow ← YOU ARE HERE\nDO NOT MERGE"]
    main --> PR1 --> PR2 --> PR3 --> PR4 --> PR5
    style PR5 fill:#ffd700,color:#000
Loading

Depends on: #468

Test plan

  • circleci config validate passes
  • git grep sweep for release-legacy.yml, AWS_ACCESS_KEY_ID,
    AWS_SECRET_ACCESS_KEY, old .github/upload-to-s3.sh path — zero hits
    repo-wide
  • Executable bit preserved on the moved script (mode 100755)
  • Real stable release cut through CircleCI (external merge-gate item, not
    verifiable by this PR alone)

🤖 Generated with Claude Code

@rrama rrama added depends-on-464 Depends on PR #464 do-not-merge Not safe to merge yet labels Sep 17, 2026
@snyk-io

snyk-io Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@rrama
rrama force-pushed the ci/IDE-2483_remove-legacy-release-workflow branch from fa15b26 to e845b43 Compare September 18, 2026 11:11
Base automatically changed from ci/IDE-2483_add-publish-stable-job to ci/IDE-2483_add-stable-release-workflow September 29, 2026 16:43
@rrama
rrama force-pushed the ci/IDE-2483_add-stable-release-workflow branch from 0ab2ada to c4d98e0 Compare September 30, 2026 10:03
@rrama
rrama changed the base branch from ci/IDE-2483_add-stable-release-workflow to ci/IDE-2483_add-publish-stable-job September 30, 2026 13:41
@rrama rrama added depends-on-468 Depends on PR #468 and removed depends-on-464 Depends on PR #464 labels Sep 30, 2026
@rrama
rrama force-pushed the ci/IDE-2483_remove-legacy-release-workflow branch from e845b43 to 71121c1 Compare September 30, 2026 14:21
@rrama
rrama force-pushed the ci/IDE-2483_add-publish-stable-job branch from ffec5ab to 3c2fda3 Compare September 30, 2026 14:21

rrama commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

@nick-y-snyk nick-y-snyk left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The code looks right. The script keeps mode 100755, SCRIPT_DIR/../update-site/... still resolves from .circleci/, and all three path references are updated. Merge stays gated on a real stable release, as the description says.

One gap in the runbook. Steps 7 to 9 don't delete the AWS_S3_BUCKET_NAME GitHub secret. After this PR nothing reads it (readme-sync.yml only uses GITHUB_TOKEN), so it should go with the others.

Nits:

  • Blocker 1 waits on circleci-infra#66, but #468 says the snyk-eclipse-plugin-github-release context already exists. #66 only brings it under Terraform, so it doesn't gate this merge.
  • The re-check commands exclude :!.local/, but the repo has no .local/ directory. It looks like it came from a local setup and can be dropped.

@rrama
rrama force-pushed the ci/IDE-2483_remove-legacy-release-workflow branch from 71121c1 to df083ed Compare October 5, 2026 13:43
@rrama
rrama force-pushed the ci/IDE-2483_add-publish-stable-job branch from 3c2fda3 to 6da9d96 Compare October 5, 2026 13:43
Deletes the GitHub Actions release-legacy.yml workflow that was kept as
a manual fallback while the CircleCI stable-release pipeline was
unproven. Its function is fully replaced by the CircleCI publish-stable
job (added in the prior stacked PR) — no on-repo GitHub Actions path to
S3 publishing remains.

Moves the shared .github/upload-to-s3.sh script to .circleci/, since
nothing under .github/ uses it anymore now that the legacy workflow is
gone — leaving it at .github/ would be a maintenance trap. The script's
path computation is directory-relative and works identically from the
new location; only the three .circleci/config.yml references (in
build-sign's persist_to_workspace, publish-preview, and publish-stable)
change to match.

Deletes the 'release-legacy.yml is a fallback until milestone 4'
migration note from RELEASE.md — this PR is that milestone.

Does NOT deactivate or delete the corresponding IAM access key, the IAM
user, or the AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY GitHub repo
secrets — those are live-infrastructure actions on real AWS/GitHub
credentials and are documented as a manual runbook in the PR
description, to be executed by the user after this PR merges. The PR is
labelled do-not-merge until at least one real stable release has been
cut through the new CircleCI pipeline, per the ticket's 'verify before
deactivate, deactivate before delete' ordering.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@rrama
rrama force-pushed the ci/IDE-2483_remove-legacy-release-workflow branch from df083ed to 496d452 Compare October 5, 2026 14:15
@rrama
rrama force-pushed the ci/IDE-2483_add-publish-stable-job branch from 4ae5adf to 33bfa0a Compare October 5, 2026 14:15
@rrama

rrama commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

One gap in the runbook. Steps 7 to 9 don't delete the AWS_S3_BUCKET_NAME GitHub secret. After this PR nothing reads it (readme-sync.yml only uses GITHUB_TOKEN), so it should go with the others.

Added.

Blocker 1 waits on circleci-infra#66, but #468 says the snyk-eclipse-plugin-github-release context already exists. #66 only brings it under Terraform, so it doesn't gate this merge.

Forgot to update the description, done now.

The re-check commands exclude :!.local/, but the repo has no .local/ directory. It looks like it came from a local setup and can be dropped.

My local AI being silly, removed.

@nick-y-snyk nick-y-snyk left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code looks good. Merge stays gated on a real stable release through CircleCI, as the label says.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

depends-on-468 Depends on PR #468 do-not-merge Not safe to merge yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants