clockworklabs/SpacetimeDB · warning
Publish aborted by user
Error message
Publish aborted by user
What it means
`publish_only` warns when the target server's hostname is neither `localhost` nor `127.0.0.1` and asks for confirmation before sending environment values to a remote server. If the user answers "no" (or auto-confirm via `--yes` flags is not enabled and the prompt is declined), `ensure!` aborts with this message. This is a deliberate safety guard against leaking environment secrets to remote hosts.
Solutions
- Answer 'y' at the confirmation prompt if publishing to the remote server is intended.
- Pass the auto-confirm flag for remote publishes (the option behind `yes.publish_to_remote`, e.g. `--yes`) when running non-interactively.
- Publish to a local server if the values were not meant to leave the machine.
Example fix
// before (CI, non-interactive) spacetime publish -s https://prod.example mydb # aborts at prompt // after spacetime publish -s https://prod.example --yes mydb
Defensive patterns
Strategy: validation
Validate before calling
// non-interactive runs must pass the auto-confirm flag [[ -t 0 ]] || set -- "$@" --yes # attach --yes when stdin is not a TTY
Try / catch
// CI: detect the abort and either add --yes or fail with context if output=$(spacetime publish -s "$SERVER" "$DB" 2>&1); then :; else case "$output" in *"Publish aborted by user"*) echo "Set --yes for non-interactive runs";; esac fi
Prevention
- Always pass the auto-confirm flag in CI/non-interactive contexts targeting remote servers.
- Treat the remote-hostname warning as a prompt to double-check the --server URL.
- Keep secrets-bearing env values on local servers unless explicitly intended for remote.
When it happens
Trigger: Running the environment publish flow against a remote server and typing anything other than 'y' at the "Are you sure you want to proceed?" prompt; running non-interactively without the auto-confirm flag (`yes.publish_to_remote`) so the prompt is declined/cancelled.
Common situations: CI jobs running non-interactively that hit the prompt; users who reconsider after seeing the remote-hostname warning; scripts piping input that doesn't match 'y'.
Related errors
- Aborted.
- Aborted.
- Aborting because major version upgrade was not accepted.
- Cannot read environment schema: HTTP
- Environment key count exceeds limit
AI-assisted analysis of clockworklabs/SpacetimeDB@eddf9f5014 (2026-09-20).
Data as JSON: /api/errors/af95f389edd307cf.
Report an issue: GitHub.
Appendix: source
Thrown at crates/cli/src/subcommands/publish/environment.rs:98
/// Update configuration without inspecting or building a local module.
pub(super) async fn publish_only(
config: &mut crate::config::Config,
server: Option<&str>,
database: &str,
anonymous: bool,
yes: super::YesFlags,
input: Option<&Value>,
options: &super::EnvironmentOptions,
) -> anyhow::Result<()> {
use crate::util::{add_auth_header_opt, get_auth_header, y_or_n};
use spacetimedb_client_api_messages::publish::{EnvironmentMetadata, PublishRequest, CONTENT_TYPE};
let host = config.get_host_url(server)?;
let server_url = reqwest::Url::parse(&host)?;
let hostname = server_url.host_str().context("Server URL has no hostname")?;
if hostname != "localhost" && hostname != "127.0.0.1" {
println!("You are about to publish environment values to a non-local server: {hostname}");
anyhow::ensure!(
y_or_n(yes.publish_to_remote, "Are you sure you want to proceed?")?,
"Publish aborted by user"
);
}
let auth = get_auth_header(config, anonymous, server, !yes.skip_login).await?;
let encoded = percent_encoding::percent_encode(
database.as_bytes(),
const { &percent_encoding::NON_ALPHANUMERIC.remove(b'_').remove(b'-') },
)
.to_string();
let url = format!("{host}/v1/database/{encoded}");
// Neither credentials nor publish bodies may be forwarded to redirect destinations.
let client = reqwest::Client::builder()
.redirect(reqwest::redirect::Policy::none())
.build()?;
let response = add_auth_header_opt(client.get(format!("{url}/environment")), &auth)
.send()
.await?;View on GitHub (pinned to eddf9f5014)