Files
GitLite/.gitea/workflows/app_builder.yaml
T
Christoph a1325d85e8
publish / Build and publish Arch package (release) Failing after 2m17s
publish / publish-tauri (appimage, 1, ubuntu-22.04, linux-x86_64) (release) Successful in 19m45s
publish / publish-tauri (nsis, , windows-latest, windows-x86_64) (release) Canceled after 0s
chore(ci): prepare arch container dependencies for building
Added initial setup steps to the GitLite job within the continuous integration workflow. This ensures that the underlying Arch Linux environment is fully updated and contains all necessary system packages (like nodejs, git, and docker) before the main build process begins, improving overall build reliability.
2026-07-23 15:33:45 +02:00

232 lines
8.7 KiB
YAML

name: "publish"
on:
release:
types: [published]
jobs:
publish-tauri:
permissions:
contents: write
environment: production
env:
# --- Gitea (unchanged) ---
GITEA_API: https://git.cbsk-tech.de/api/v1
OWNER: Christoph
REPO: GitLite
GITEA_TOKEN: ${{ secrets.ACTIONS_TOKEN }}
GITEA_FALLBACK_TOKEN: ${{ github.token }}
# --- MinIO / S3-compatible upload ---
MINIO_ENDPOINT: ${{ vars.MINIO_ENDPOINT }} # e.g. https://updates.example.com
S3_BUCKET: ${{ vars.S3_BUCKET }} # e.g. updates
AWS_ACCESS_KEY_ID: ${{ secrets.S3_ACCESS_KEY }} # used by aws cli
AWS_SECRET_ACCESS_KEY: ${{ secrets.S3_SECRET_KEY }} # used by aws cli
ARTIFACT_BASE_URL: ${{ vars.ARTIFACT_BASE_URL }} # e.g. https://updates.example.com
S3_ACCESS_KEY: ${{ secrets.S3_ACCESS_KEY }} # used by cicd_tool
S3_SECRET_KEY: ${{ secrets.S3_SECRET_KEY }} # used by cicd_tool
defaults:
run:
working-directory: GitLite
strategy:
fail-fast: false
max-parallel: 1
matrix:
include:
# - platform: 'macos-latest'
# args: '--target aarch64-apple-darwin'
# - platform: 'macos-latest'
# args: '--target x86_64-apple-darwin'
- platform: "windows-latest"
bundles: "nsis"
updater_platform: "windows-x86_64"
no_strip: ""
- platform: "ubuntu-22.04"
bundles: "appimage"
updater_platform: "linux-x86_64"
no_strip: "1"
runs-on: ${{ matrix.platform }}
steps:
# cicd_tool/main.py expects the repo at <workspace>/GitLite, so check out there.
- uses: actions/checkout@v5
with:
path: GitLite
- name: install dependencies (ubuntu only)
if: matrix.platform == 'ubuntu-22.04'
run: |
sudo apt-get update
sudo apt-get install -y build-essential curl wget file libssl-dev libwebkit2gtk-4.1-dev libayatana-appindicator3-dev librsvg2-dev patchelf libxdo-dev libfuse2
- name: setup node
uses: actions/setup-node@v4
with:
node-version: lts/*
- name: Install uv
if: matrix.platform == 'ubuntu-22.04'
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
- name: install rust toolchain
if: matrix.platform == 'ubuntu-22.04'
uses: dtolnay/rust-toolchain@stable
- name: install frontend dependencies
run: npm ci
- name: Update package.json Version
run: npm version ${{ github.ref_name }} --no-git-tag-version --allow-same-version
- name: Update tauri.conf.json Version
env:
RELEASE_VERSION: ${{ github.ref_name }}
run: |
node -e "const fs=require('fs'); const path='src-tauri/tauri.conf.json'; const config=JSON.parse(fs.readFileSync(path,'utf8')); config.version=process.env.RELEASE_VERSION; fs.writeFileSync(path, JSON.stringify(config,null,2)+'\n');"
- name: Update PKGBUILD Version
run: |
node -e "const fs=require('fs'); const version=require('./package.json').version; const pkgbuild=fs.readFileSync('PKGBUILD','utf8').replace(/^pkgver=.*$/m, 'pkgver='+version).replace(/^pkgrel=.*$/m, 'pkgrel=1'); fs.writeFileSync('PKGBUILD', pkgbuild);"
- name: Commit and Push Changes
if: matrix.platform == 'windows-latest'
shell: powershell
run: |
git config user.name '${{ vars.USERNAME_GIT }}'
git config user.email '${{ vars.EMAIL_GIT }}'
# npm version also bumps the version inside package-lock.json, so stage it
# too -- otherwise it stays as an unstaged change and blocks the rebase.
git add package.json package-lock.json src-tauri/tauri.conf.json PKGBUILD
git commit -m 'Update version to ${{ github.ref_name }}'
if ($LASTEXITCODE -ne 0) {
# Version files already match the tag -> nothing to push, succeed quietly.
Write-Host 'No version changes to commit; skipping push.'
exit 0
}
# The release build runs in detached HEAD on the tag. Resolve the branch
# that should receive the version bump.
$branch = '${{ github.event.release.target_commitish }}'
if ([string]::IsNullOrEmpty($branch) -or $branch -match '^[0-9a-f]{40}$') {
$branch = (
git branch -r --contains $env:GITHUB_SHA |
ForEach-Object { $_.Trim() } |
Where-Object { $_ -and ($_ -notmatch '->') } |
ForEach-Object { $_ -replace '^(?:remotes/)?[^/]+/', '' } |
Select-Object -First 1
)
}
if ([string]::IsNullOrEmpty($branch)) {
Write-Host 'Could not determine branch for push.'
git branch -a
exit 1
}
# The tag may be behind the branch tip. Replay the bump commit on top of
# the current remote branch so the push is a clean fast-forward.
git fetch origin $branch
git rebase "origin/$branch"
if ($LASTEXITCODE -ne 0) {
git rebase --abort
Write-Host "Rebase onto origin/$branch failed."
exit 1
}
git push origin "HEAD:refs/heads/$branch"
- name: Build Tauri App
env:
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD}}
NO_STRIP: ${{ matrix.no_strip }}
run: npm run tauri -- build --bundles ${{ matrix.bundles }}
# ----------------------
# Upload to MinIO (via mc) and create latest.json
# ----------------------
- name: Upload artifacts to MinIO with cicd_tool
working-directory: GitLite/cicd_tool
env:
PUBLISH_PLATFORM: ${{ matrix.updater_platform }}
run: |
uv sync
uv run main.py
publish-arch:
name: Build and publish Arch package
runs-on: archlinux
environment: production
env:
MINIO_ENDPOINT: ${{ vars.MINIO_ENDPOINT }}
S3_BUCKET: ${{ vars.S3_BUCKET }}
S3_ACCESS_KEY: ${{ secrets.S3_ACCESS_KEY }}
S3_SECRET_KEY: ${{ secrets.S3_SECRET_KEY }}
defaults:
run:
working-directory: GitLite
steps:
- name: Prepare Arch job container
working-directory: /
run: |
pacman -Syu --noconfirm
pacman -S --needed --noconfirm nodejs npm git docker
- uses: actions/checkout@v5
with:
path: GitLite
- name: Set release version
env:
RELEASE_VERSION: ${{ github.ref_name }}
run: |
npm version "$RELEASE_VERSION" --no-git-tag-version --allow-same-version
node -e "const fs=require('fs'); const version=require('./package.json').version; const path='src-tauri/tauri.conf.json'; const config=JSON.parse(fs.readFileSync(path,'utf8')); config.version=version; fs.writeFileSync(path,JSON.stringify(config,null,2)+'\n');"
PACKAGE_VERSION="$(node -p "require('./package.json').version")"
sed -i "s/^pkgver=.*/pkgver=$PACKAGE_VERSION/; s/^pkgrel=.*/pkgrel=1/" PKGBUILD
- name: Install uv
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
- name: Restore pacman repository database
working-directory: GitLite/cicd_tool
run: |
uv sync
uv run arch_repo.py download-db --output ../arch-repo/gitty.db.tar.gz
- name: Build pkg.tar.zst with PKGBUILD
run: |
mkdir -p arch-output
docker run --rm \
-v "$PWD:/source:ro" \
-v "$PWD/arch-output:/output" \
archlinux:base-devel bash -lc '
pacman -Syu --noconfirm git nodejs npm rust webkit2gtk-4.1 gtk3 hicolor-icon-theme libappindicator-gtk3 librsvg xdotool &&
useradd --create-home builder &&
cp -a /source /build &&
chown -R builder:builder /build &&
runuser -u builder -- bash -lc "cd /build && makepkg --cleanbuild --noconfirm" &&
cp /build/*.pkg.tar.zst /output/ &&
chmod 0644 /output/*.pkg.tar.zst
'
- name: Update pacman repository database
run: |
mkdir -p arch-repo
docker run --rm \
-v "$PWD/arch-output:/packages:ro" \
-v "$PWD/arch-repo:/repo" \
archlinux:base-devel bash -lc '
cd /repo &&
repo-add gitty.db.tar.gz /packages/*.pkg.tar.zst
'
- name: Upload package and repository database to CDN
working-directory: GitLite/cicd_tool
run: uv run arch_repo.py publish --packages-dir ../arch-output --repo-dir ../arch-repo