clockworklabs/SpacetimeDB · warning

Publish aborted by user

Error message

Publish aborted by user

What it means

`publish_only` warns when the target server's hostname is neither `localhost` nor `127.0.0.1` and asks for confirmation before sending environment values to a remote server. If the user answers "no" (or auto-confirm via `--yes` flags is not enabled and the prompt is declined), `ensure!` aborts with this message. This is a deliberate safety guard against leaking environment secrets to remote hosts.

Solutions

  1. Answer 'y' at the confirmation prompt if publishing to the remote server is intended.
  2. Pass the auto-confirm flag for remote publishes (the option behind `yes.publish_to_remote`, e.g. `--yes`) when running non-interactively.
  3. Publish to a local server if the values were not meant to leave the machine.

Example fix

// before (CI, non-interactive)
spacetime publish -s https://prod.example mydb   # aborts at prompt
// after
spacetime publish -s https://prod.example --yes mydb
Defensive patterns

Strategy: validation

Validate before calling

// non-interactive runs must pass the auto-confirm flag
[[ -t 0 ]] || set -- "$@" --yes   # attach --yes when stdin is not a TTY

Try / catch

// CI: detect the abort and either add --yes or fail with context
if output=$(spacetime publish -s "$SERVER" "$DB" 2>&1); then :; else
  case "$output" in *"Publish aborted by user"*) echo "Set --yes for non-interactive runs";; esac
fi

Prevention

When it happens

Trigger: Running the environment publish flow against a remote server and typing anything other than 'y' at the "Are you sure you want to proceed?" prompt; running non-interactively without the auto-confirm flag (`yes.publish_to_remote`) so the prompt is declined/cancelled.

Common situations: CI jobs running non-interactively that hit the prompt; users who reconsider after seeing the remote-hostname warning; scripts piping input that doesn't match 'y'.

Related errors


AI-assisted analysis of clockworklabs/SpacetimeDB@eddf9f5014 (2026-09-20). Data as JSON: /api/errors/af95f389edd307cf. Report an issue: GitHub.

Appendix: source

Thrown at crates/cli/src/subcommands/publish/environment.rs:98

/// Update configuration without inspecting or building a local module.
pub(super) async fn publish_only(
    config: &mut crate::config::Config,
    server: Option<&str>,
    database: &str,
    anonymous: bool,
    yes: super::YesFlags,
    input: Option<&Value>,
    options: &super::EnvironmentOptions,
) -> anyhow::Result<()> {
    use crate::util::{add_auth_header_opt, get_auth_header, y_or_n};
    use spacetimedb_client_api_messages::publish::{EnvironmentMetadata, PublishRequest, CONTENT_TYPE};

    let host = config.get_host_url(server)?;
    let server_url = reqwest::Url::parse(&host)?;
    let hostname = server_url.host_str().context("Server URL has no hostname")?;
    if hostname != "localhost" && hostname != "127.0.0.1" {
        println!("You are about to publish environment values to a non-local server: {hostname}");
        anyhow::ensure!(
            y_or_n(yes.publish_to_remote, "Are you sure you want to proceed?")?,
            "Publish aborted by user"
        );
    }
    let auth = get_auth_header(config, anonymous, server, !yes.skip_login).await?;
    let encoded = percent_encoding::percent_encode(
        database.as_bytes(),
        const { &percent_encoding::NON_ALPHANUMERIC.remove(b'_').remove(b'-') },
    )
    .to_string();
    let url = format!("{host}/v1/database/{encoded}");
    // Neither credentials nor publish bodies may be forwarded to redirect destinations.
    let client = reqwest::Client::builder()
        .redirect(reqwest::redirect::Policy::none())
        .build()?;
    let response = add_auth_header_opt(client.get(format!("{url}/environment")), &auth)
        .send()
        .await?;

View on GitHub (pinned to eddf9f5014)