ci: rebuild :test docker image on every push to main - #666
Merged
Merged
Conversation
The workflow trigger was left pointing at the now-merged feature/create_docker_publish_action branch instead of main, so the :test image on ghcr.io has not rebuilt since 2026-01-13 despite dozens of merged commits since then (including a field-id rename in the Yubikey verification form, which broke devconf's Behat suite that already expects the current field id). Trigger on push to main instead so the :test tag stays in sync.
kayjoosten
force-pushed
the
fix/rebuild-test-image-on-main-push
branch
from
September 8, 2026 21:31
62156d2 to
3041348
Compare
phavekes
approved these changes
Sep 10, 2026
johanib
approved these changes
Sep 10, 2026
kayjoosten
added a commit
to OpenConext/Stepup-SelfService
that referenced
this pull request
Sep 17, 2026
The build-push-test-docker-image workflow's trigger was left pointing at feature/build-and-publish-test-container, a branch that is already merged. Since then it can only run via manual workflow_dispatch and never rebuilds on a normal merge to main, so the :test image silently goes stale (the same issue found and fixed in OpenConext/Stepup-Gateway#666). Trigger the workflow on push to main instead, so the :test tag stays in sync with the default branch going forward.
kayjoosten
added a commit
to OpenConext/Stepup-SelfService
that referenced
this pull request
Sep 17, 2026
* fix: point dev logout redirect at local test SP instead of surf.nl config/openconext/parameters.yaml.dist is the local-development default config: every other URL in it (gateway, middleware, SAML endpoints) points at *.dev.openconext.local, but logout_redirect_url was still hardcoded to the public www.surf.nl production pages. This forced OpenConext-devconf's stepup docker-compose stack to bind-mount a full 95-line replacement parameters.yaml just to override this one key, duplicating and needing to stay in sync with this dist file. Fixing the default here lets devconf drop that override, matching how gateway/ middleware/ra already work with no devconf-side config file. en_GB and nl_NL now both redirect to the local test SP (ssp.dev.openconext.local), consistent with the rest of this file. * ci: rebuild :test docker image on every push to main The build-push-test-docker-image workflow's trigger was left pointing at feature/build-and-publish-test-container, a branch that is already merged. Since then it can only run via manual workflow_dispatch and never rebuilds on a normal merge to main, so the :test image silently goes stale (the same issue found and fixed in OpenConext/Stepup-Gateway#666). Trigger the workflow on push to main instead, so the :test tag stays in sync with the default branch going forward.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The
build-push-test-docker-imageworkflow's trigger was left pointing atfeature/create_docker_publish_action, a branch that was merged and deleted back in January. Since then it has only ever run once (2026-01-13, via that push) and can otherwise only run via manualworkflow_dispatch— it has never rebuilt on a normal merge tomain.Impact
The
ghcr.io/openconext/stepup-gateway/stepup-gateway:testimage is frozen at commitfa1c0074(2026-01-13), ~19 commits behindmain. This includes the commit that renamed the Yubikey verification form field id (otp→yubikeyInput), which downstream consumers like OpenConext-devconf already updated their Behat fixtures for — causing ~88 Behat scenario failures there because the stale:testimage still serves the old field id.Fix
Trigger the workflow on push to
maininstead, so the:testtag stays in sync with the default branch going forward.Related: OpenConext/OpenConext-devconf#98, OpenConext/OpenConext-devconf#99