fix(ci): resolve HOME before writing the registry token, unblocking main #505

Merged
gmackie merged 1 commit from fix/npmrc-home-on-runners into main 2026-08-27 21:42:02 +00:00
Owner

main has not deployed since #499. Every deploy job is skipped because its test dependency fails with ERR_PNPM_FETCH_401 fetching @preflight/runreport.

The token was never missing. The FG_REGISTRY_TOKEN unset warning #499 added never fired, so the secret is present. These runners start without HOME, so "$HOME/.npmrc" wrote to /.npmrc, while pnpm resolved ~ through the passwd entry and read /root/.npmrc. The auth line landed somewhere nothing reads.

That is why the error is so misleading: pnpm reports "No authorization header was set" and then lists the @preflight:registry scope mapping — which reads like a missing secret rather than a file written to the wrong path.

This is the same HOME-less-runner gotcha release-agent.yml already works around (it burned a 30-minute release run earlier today). Applies the same resolution before the npmrc write, in all five places: ci.yml x2, deploy.yml x2, deploy-staging.yml.

Verified with scripts/test-workflow-yaml.mjs (added by #499) — 7 workflows parse cleanly.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CMpzX1b6swjezEptw3T71f

**main has not deployed since #499.** Every `deploy` job is skipped because its `test` dependency fails with `ERR_PNPM_FETCH_401` fetching `@preflight/runreport`. **The token was never missing.** The `FG_REGISTRY_TOKEN unset` warning #499 added never fired, so the secret is present. These runners start **without HOME**, so `"$HOME/.npmrc"` wrote to `/.npmrc`, while pnpm resolved `~` through the passwd entry and read `/root/.npmrc`. The auth line landed somewhere nothing reads. That is why the error is so misleading: pnpm reports *"No authorization header was set"* and then lists the `@preflight:registry` scope mapping — which reads like a missing secret rather than a file written to the wrong path. This is the same HOME-less-runner gotcha `release-agent.yml` already works around (it burned a 30-minute release run earlier today). Applies the same resolution before the npmrc write, in all five places: `ci.yml` x2, `deploy.yml` x2, `deploy-staging.yml`. Verified with `scripts/test-workflow-yaml.mjs` (added by #499) — 7 workflows parse cleanly. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01CMpzX1b6swjezEptw3T71f
fix(ci): resolve HOME before writing the registry token, unblocking main
All checks were successful
CI / gitleaks (pull_request) Successful in 6s
CI / storybook (pull_request) Successful in 1m43s
forgegraph/ci CI passed
CI / ci (pull_request) Successful in 9m32s
02029de013
Since #499 every deploy on main has been skipped because its `test`
dependency failed with ERR_PNPM_FETCH_401 on @preflight/runreport. The
token was present — the 'FG_REGISTRY_TOKEN unset' warning never fired —
but these runners start without HOME, so "$HOME/.npmrc" wrote to
/.npmrc while pnpm resolved ~ through the passwd entry and read
/root/.npmrc. The auth line went somewhere nothing looks, and pnpm
reported 'No authorization header was set' with the scope mapping
present, which reads like a missing secret rather than a missing file.

Resolves HOME the same way release-agent.yml already does, before the
npmrc write, in all five places (ci, deploy x2, deploy-staging).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CMpzX1b6swjezEptw3T71f
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
gmackie/ForgeGraph!505
No description provided.