The 'Upload to release server' step in .github/workflows/release.yml fails with 'deploy@releases.experiencenet.com: Permission denied (publickey)' since v1.18.0 (2026-08-11), and again on v1.19.0 (2026-08-17). Tests, binary builds, and the GitHub release all succeed; only the rsync-over-SSH upload to /var/www/releases/hydrarelease is broken, so the hydrarelease CLI is missing from releases.experiencenet.com for both versions.
Fix: migrate the step to the publish API, the same pattern hydraheadflatscreen release.yml uses (POST /api/v1/publish/{project}/{channel}/{version}/{file} plus finalize, bearer HYDRARELEASE_PUBLISH_TOKEN). The hydrarelease repo has no HYDRARELEASE_PUBLISH_TOKEN secret yet, only the dead RELEASES_SSH_KEY, so set the secret first. Alternative: restore the deploy key on the release server, but the API path is the convention now and removes the SSH key entirely.