Summary
With an organization-scoped API token (no workspaceId claim) used via ASTRO_API_TOKEN in a non-interactive/CI context, astro deployment variable update (and other commands routing through coalesceWorkspace) fail with:
Error: failed to find a valid workspace: failed to get current Workspace: current workspace context not set
EVEN WHEN --workspace-id <id> is passed. The explicit flag is effectively ignored.
Affected versions
v1.40.1, v1.42.1 (latest stable), and v1.43.0-nightly — the relevant functions are byte-identical across these, so upgrading does not help.
Root cause (code)
In cmd/cloud/workspace.go, coalesceWorkspace() calls workspace.GetCurrentWorkspace() and returns its error BEFORE it checks the --workspace-id flag:
func coalesceWorkspace() (string, error) {
wsFlag := workspaceID
wsCfg, err := workspace.GetCurrentWorkspace() // called first
if err != nil {
return "", errors.Wrap(err, "failed to get current Workspace") // returns here — flag never read
}
if wsFlag != "" { return wsFlag, nil } // --workspace-id only honored after
if wsCfg != "" { return wsCfg, nil }
return "", errors.New("no valid Workspace source found")
}
GetCurrentWorkspace() (cloud/workspace/workspace.go) errors whenever c.Workspace == "". In the API-token path, checkAPIToken() (cmd/cloud/setup.go) derives the workspace from token claims, falling back to c.Workspace (if wsID == "" { wsID = c.Workspace }); an org-scoped token has no workspaceId claim, so in a fresh config home c.Workspace stays empty and the flag cannot rescue it.
Reproduction
ASTRO_HOME=$(mktemp -d), set ASTRO_API_TOKEN to an organization-scoped token, no astro workspace switch performed.
- Run
astro deployment variable update --workspace-id <valid-ws-id> --deployment-id <valid-dep-id> --key FOO --value bar.
- Observe the
current workspace context not set error despite --workspace-id.
- Running
astro workspace switch <ws-id> first makes it succeed.
Expected
An explicit --workspace-id should be honored before requiring a current-workspace context.
Suggested fix
In coalesceWorkspace(), return wsFlag when non-empty BEFORE calling GetCurrentWorkspace() (or have checkAPIToken seed the context workspace from --workspace-id for org-scoped tokens).
Related
This issue is specifically about the coalesceWorkspace ordering for deployment/variable commands.
Impact
Breaks non-interactive CI flows that use org-scoped tokens and pass --workspace-id explicitly.
Summary
With an organization-scoped API token (no
workspaceIdclaim) used viaASTRO_API_TOKENin a non-interactive/CI context,astro deployment variable update(and other commands routing throughcoalesceWorkspace) fail with:EVEN WHEN
--workspace-id <id>is passed. The explicit flag is effectively ignored.Affected versions
v1.40.1, v1.42.1 (latest stable), and v1.43.0-nightly — the relevant functions are byte-identical across these, so upgrading does not help.
Root cause (code)
In
cmd/cloud/workspace.go,coalesceWorkspace()callsworkspace.GetCurrentWorkspace()and returns its error BEFORE it checks the--workspace-idflag:GetCurrentWorkspace()(cloud/workspace/workspace.go) errors wheneverc.Workspace == "". In the API-token path,checkAPIToken()(cmd/cloud/setup.go) derives the workspace from token claims, falling back toc.Workspace(if wsID == "" { wsID = c.Workspace }); an org-scoped token has noworkspaceIdclaim, so in a fresh config homec.Workspacestays empty and the flag cannot rescue it.Reproduction
ASTRO_HOME=$(mktemp -d), setASTRO_API_TOKENto an organization-scoped token, noastro workspace switchperformed.astro deployment variable update --workspace-id <valid-ws-id> --deployment-id <valid-dep-id> --key FOO --value bar.current workspace context not seterror despite--workspace-id.astro workspace switch <ws-id>first makes it succeed.Expected
An explicit
--workspace-idshould be honored before requiring a current-workspace context.Suggested fix
In
coalesceWorkspace(), returnwsFlagwhen non-empty BEFORE callingGetCurrentWorkspace()(or havecheckAPITokenseed the context workspace from--workspace-idfor org-scoped tokens).Related
astro org switchstill prompts for workspace selection when--workspace-idflag is provided #1962 (analogous--workspace-idignored inorg switch)This issue is specifically about the
coalesceWorkspaceordering for deployment/variable commands.Impact
Breaks non-interactive CI flows that use org-scoped tokens and pass
--workspace-idexplicitly.