-
Notifications
You must be signed in to change notification settings - Fork 0
172 lines (146 loc) Β· 6.2 KB
/
Copy pathrelease.yaml
File metadata and controls
172 lines (146 loc) Β· 6.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
name: Release
run-name: Release ${{ github.ref_name }}
# Build + test + publish on push of a revision tag (r1, r2, ...).
# Rolling: every rev tag triggers a new release. Only the latest GitHub
# release survives -- it is always named "downloads" and carries the
# inlined/*.yaml distribution artefacts + precompiled spread binaries
# (with sha256 sidecars and cosign keyless signature bundles).
# ghcr image tags are versioned per-flavour
# (ghcr.io/<repo>/{bread,bread-chisel-releases}:<ver>) and stay around
# as overwrite-on-push tags.
on:
push:
tags:
- 'r[0-9]*'
workflow_dispatch:
jobs:
binaries:
uses: ./.github/workflows/binaries.yaml
build-and-test:
needs: binaries
uses: ./.github/workflows/build-and-test.yaml
build-oci-native:
needs: [binaries, build-and-test]
uses: ./.github/workflows/build-oci.yaml
with:
matrix: >-
[{"runner": "ubuntu-24.04", "arch": "amd64"},
{"runner": "ubuntu-24.04-arm", "arch": "arm64"}]
# qemu lanes publish untested, so they skip the build-and-test gate and
# overlap with it. Publishing still waits on the gated native lanes.
build-oci-qemu:
needs: binaries
uses: ./.github/workflows/build-oci.yaml
with:
matrix: >-
[{"runner": "ubuntu-24.04", "arch": "s390x", "qemu": true},
{"runner": "ubuntu-24.04", "arch": "ppc64le", "qemu": true}]
push-ghcr:
needs: [build-oci-native, build-oci-qemu]
uses: ./.github/workflows/push-ghcr.yaml
permissions:
contents: read
packages: write
id-token: write
publish-release:
needs: [binaries, build-oci-native, build-oci-qemu]
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
contents: write
id-token: write
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Regenerate inlined yamls
run: make inline
- name: Restore cached binaries (all arches)
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: binaries-*
merge-multiple: true
path: .
- name: Assemble release assets
run: |
set -e
mkdir -p release-out
# inlined yamls verbatim
cp inlined/*.yaml release-out/
# spread + chisel-hacked binaries: rename to canonical
# go-release-style names
for arch in amd64 arm64 s390x ppc64le; do
cp "cache/binaries/spread-$arch" "release-out/spread-linux-$arch"
cp "cache/binaries/chisel-hacked-$arch" "release-out/chisel-hacked-linux-$arch"
done
chmod +x release-out/spread-linux-* release-out/chisel-hacked-linux-*
# sha256 sidecars (standard sha256sum format)
cd release-out
for f in spread-linux-* chisel-hacked-linux-*; do
sha256sum -b "$f" > "$f.sha256"
done
- name: Install cosign
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
- name: Cosign keyless sign binaries (produce .cosign.bundle sidecars)
run: |
set -e
cd release-out
for f in spread-linux-{amd64,arm64,s390x,ppc64le} chisel-hacked-linux-{amd64,arm64,s390x,ppc64le}; do
cosign sign-blob --yes \
--bundle "$f.cosign.bundle" \
"$f"
done
- name: Delete prior r* release objects (keep their refs)
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
KEEP: ${{ github.ref_name }}
run: |
set -e
gh release list --json tagName --jq '.[].tagName' | \
grep -E '^r[0-9]+$' | \
while read -r t; do
if [ "$t" != "$KEEP" ]; then
echo "Deleting prior release object: $t (ref preserved)"
gh release delete "$t" --yes || true
fi
done
- name: Create release "downloads" w/ yamls + spread binaries attached
uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3
with:
tag_name: ${{ github.ref_name }}
name: downloads
files: release-out/*
make_latest: true
fail_on_unmatched_files: true
body: |
rolling distribution release for the spread-bread project.
**inlined spread yamls** -- self-contained spread configs for the
bread + bread-chisel-releases ghcr images. each yaml has the
allocate / discard glue inlined and points at the matching ghcr
multiarch image (ghcr.io/lczyk/spread-bread/<flavour>:<ver>).
drop one into your project as `spread.yaml`:
```
curl -fsSL https://github.com/lczyk/spread-bread/releases/latest/download/bread-chisel-releases-26.04.yaml -o spread.yaml
spread
```
**precompiled spread binaries** -- statically-linked spread CLI
for linux amd64 / arm64 / s390x / ppc64le, cross-compiled with
go 1.25.x. each
binary ships with a `.sha256` checksum sidecar and a
`.cosign.bundle` keyless signature bundle.
```
curl -fsSL https://github.com/lczyk/spread-bread/releases/latest/download/spread-linux-amd64 -o /usr/local/bin/spread
chmod +x /usr/local/bin/spread
```
**precompiled chisel-hacked binaries** -- chisel v1.5.0 with
CHISEL_HACKS patches applied. when `CHISEL_HACKS=1` is set,
skips release maintenance checks and validates releases with a
faster path conflict check -- used by chisel-releases tests
against in-development releases.
ships with `.sha256` and `.cosign.bundle` sidecars.
```
curl -fsSL https://github.com/lczyk/spread-bread/releases/latest/download/chisel-hacked-linux-amd64 -o /usr/local/bin/chisel-hacked
chmod +x /usr/local/bin/chisel-hacked
```
**ghcr image tags** stay around indefinitely under their
per-version tag (`ghcr.io/lczyk/spread-bread/<flavour>:<ver>`)
and are signed via cosign keyless OIDC at publish time.