Added initial setup steps to the GitLite job within the continuous integration workflow. This ensures that the underlying Arch Linux environment is fully updated and contains all necessary system packages (like nodejs, git, and docker) before the main build process begins, improving overall build reliability.
232 lines
8.7 KiB
YAML
232 lines
8.7 KiB
YAML
name: "publish"
|
|
|
|
on:
|
|
release:
|
|
types: [published]
|
|
|
|
jobs:
|
|
publish-tauri:
|
|
permissions:
|
|
contents: write
|
|
environment: production
|
|
env:
|
|
# --- Gitea (unchanged) ---
|
|
GITEA_API: https://git.cbsk-tech.de/api/v1
|
|
OWNER: Christoph
|
|
REPO: GitLite
|
|
GITEA_TOKEN: ${{ secrets.ACTIONS_TOKEN }}
|
|
GITEA_FALLBACK_TOKEN: ${{ github.token }}
|
|
|
|
# --- MinIO / S3-compatible upload ---
|
|
MINIO_ENDPOINT: ${{ vars.MINIO_ENDPOINT }} # e.g. https://updates.example.com
|
|
S3_BUCKET: ${{ vars.S3_BUCKET }} # e.g. updates
|
|
AWS_ACCESS_KEY_ID: ${{ secrets.S3_ACCESS_KEY }} # used by aws cli
|
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.S3_SECRET_KEY }} # used by aws cli
|
|
ARTIFACT_BASE_URL: ${{ vars.ARTIFACT_BASE_URL }} # e.g. https://updates.example.com
|
|
S3_ACCESS_KEY: ${{ secrets.S3_ACCESS_KEY }} # used by cicd_tool
|
|
S3_SECRET_KEY: ${{ secrets.S3_SECRET_KEY }} # used by cicd_tool
|
|
|
|
defaults:
|
|
run:
|
|
working-directory: GitLite
|
|
|
|
strategy:
|
|
fail-fast: false
|
|
max-parallel: 1
|
|
matrix:
|
|
include:
|
|
# - platform: 'macos-latest'
|
|
# args: '--target aarch64-apple-darwin'
|
|
# - platform: 'macos-latest'
|
|
# args: '--target x86_64-apple-darwin'
|
|
- platform: "windows-latest"
|
|
bundles: "nsis"
|
|
updater_platform: "windows-x86_64"
|
|
no_strip: ""
|
|
- platform: "ubuntu-22.04"
|
|
bundles: "appimage"
|
|
updater_platform: "linux-x86_64"
|
|
no_strip: "1"
|
|
|
|
runs-on: ${{ matrix.platform }}
|
|
|
|
steps:
|
|
# cicd_tool/main.py expects the repo at <workspace>/GitLite, so check out there.
|
|
- uses: actions/checkout@v5
|
|
with:
|
|
path: GitLite
|
|
|
|
- name: install dependencies (ubuntu only)
|
|
if: matrix.platform == 'ubuntu-22.04'
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y build-essential curl wget file libssl-dev libwebkit2gtk-4.1-dev libayatana-appindicator3-dev librsvg2-dev patchelf libxdo-dev libfuse2
|
|
|
|
- name: setup node
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: lts/*
|
|
|
|
- name: Install uv
|
|
if: matrix.platform == 'ubuntu-22.04'
|
|
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
|
|
|
|
- name: install rust toolchain
|
|
if: matrix.platform == 'ubuntu-22.04'
|
|
uses: dtolnay/rust-toolchain@stable
|
|
|
|
- name: install frontend dependencies
|
|
run: npm ci
|
|
|
|
- name: Update package.json Version
|
|
run: npm version ${{ github.ref_name }} --no-git-tag-version --allow-same-version
|
|
|
|
- name: Update tauri.conf.json Version
|
|
env:
|
|
RELEASE_VERSION: ${{ github.ref_name }}
|
|
run: |
|
|
node -e "const fs=require('fs'); const path='src-tauri/tauri.conf.json'; const config=JSON.parse(fs.readFileSync(path,'utf8')); config.version=process.env.RELEASE_VERSION; fs.writeFileSync(path, JSON.stringify(config,null,2)+'\n');"
|
|
|
|
- name: Update PKGBUILD Version
|
|
run: |
|
|
node -e "const fs=require('fs'); const version=require('./package.json').version; const pkgbuild=fs.readFileSync('PKGBUILD','utf8').replace(/^pkgver=.*$/m, 'pkgver='+version).replace(/^pkgrel=.*$/m, 'pkgrel=1'); fs.writeFileSync('PKGBUILD', pkgbuild);"
|
|
|
|
- name: Commit and Push Changes
|
|
if: matrix.platform == 'windows-latest'
|
|
shell: powershell
|
|
run: |
|
|
git config user.name '${{ vars.USERNAME_GIT }}'
|
|
git config user.email '${{ vars.EMAIL_GIT }}'
|
|
# npm version also bumps the version inside package-lock.json, so stage it
|
|
# too -- otherwise it stays as an unstaged change and blocks the rebase.
|
|
git add package.json package-lock.json src-tauri/tauri.conf.json PKGBUILD
|
|
|
|
git commit -m 'Update version to ${{ github.ref_name }}'
|
|
if ($LASTEXITCODE -ne 0) {
|
|
# Version files already match the tag -> nothing to push, succeed quietly.
|
|
Write-Host 'No version changes to commit; skipping push.'
|
|
exit 0
|
|
}
|
|
|
|
# The release build runs in detached HEAD on the tag. Resolve the branch
|
|
# that should receive the version bump.
|
|
$branch = '${{ github.event.release.target_commitish }}'
|
|
if ([string]::IsNullOrEmpty($branch) -or $branch -match '^[0-9a-f]{40}$') {
|
|
$branch = (
|
|
git branch -r --contains $env:GITHUB_SHA |
|
|
ForEach-Object { $_.Trim() } |
|
|
Where-Object { $_ -and ($_ -notmatch '->') } |
|
|
ForEach-Object { $_ -replace '^(?:remotes/)?[^/]+/', '' } |
|
|
Select-Object -First 1
|
|
)
|
|
}
|
|
|
|
if ([string]::IsNullOrEmpty($branch)) {
|
|
Write-Host 'Could not determine branch for push.'
|
|
git branch -a
|
|
exit 1
|
|
}
|
|
|
|
# The tag may be behind the branch tip. Replay the bump commit on top of
|
|
# the current remote branch so the push is a clean fast-forward.
|
|
git fetch origin $branch
|
|
git rebase "origin/$branch"
|
|
if ($LASTEXITCODE -ne 0) {
|
|
git rebase --abort
|
|
Write-Host "Rebase onto origin/$branch failed."
|
|
exit 1
|
|
}
|
|
|
|
git push origin "HEAD:refs/heads/$branch"
|
|
|
|
- name: Build Tauri App
|
|
env:
|
|
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
|
|
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD}}
|
|
NO_STRIP: ${{ matrix.no_strip }}
|
|
run: npm run tauri -- build --bundles ${{ matrix.bundles }}
|
|
# ----------------------
|
|
# Upload to MinIO (via mc) and create latest.json
|
|
# ----------------------
|
|
- name: Upload artifacts to MinIO with cicd_tool
|
|
working-directory: GitLite/cicd_tool
|
|
env:
|
|
PUBLISH_PLATFORM: ${{ matrix.updater_platform }}
|
|
run: |
|
|
uv sync
|
|
uv run main.py
|
|
|
|
publish-arch:
|
|
name: Build and publish Arch package
|
|
runs-on: archlinux
|
|
environment: production
|
|
env:
|
|
MINIO_ENDPOINT: ${{ vars.MINIO_ENDPOINT }}
|
|
S3_BUCKET: ${{ vars.S3_BUCKET }}
|
|
S3_ACCESS_KEY: ${{ secrets.S3_ACCESS_KEY }}
|
|
S3_SECRET_KEY: ${{ secrets.S3_SECRET_KEY }}
|
|
|
|
defaults:
|
|
run:
|
|
working-directory: GitLite
|
|
|
|
steps:
|
|
- name: Prepare Arch job container
|
|
working-directory: /
|
|
run: |
|
|
pacman -Syu --noconfirm
|
|
pacman -S --needed --noconfirm nodejs npm git docker
|
|
|
|
- uses: actions/checkout@v5
|
|
with:
|
|
path: GitLite
|
|
|
|
- name: Set release version
|
|
env:
|
|
RELEASE_VERSION: ${{ github.ref_name }}
|
|
run: |
|
|
npm version "$RELEASE_VERSION" --no-git-tag-version --allow-same-version
|
|
node -e "const fs=require('fs'); const version=require('./package.json').version; const path='src-tauri/tauri.conf.json'; const config=JSON.parse(fs.readFileSync(path,'utf8')); config.version=version; fs.writeFileSync(path,JSON.stringify(config,null,2)+'\n');"
|
|
PACKAGE_VERSION="$(node -p "require('./package.json').version")"
|
|
sed -i "s/^pkgver=.*/pkgver=$PACKAGE_VERSION/; s/^pkgrel=.*/pkgrel=1/" PKGBUILD
|
|
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
|
|
|
|
- name: Restore pacman repository database
|
|
working-directory: GitLite/cicd_tool
|
|
run: |
|
|
uv sync
|
|
uv run arch_repo.py download-db --output ../arch-repo/gitty.db.tar.gz
|
|
|
|
- name: Build pkg.tar.zst with PKGBUILD
|
|
run: |
|
|
mkdir -p arch-output
|
|
docker run --rm \
|
|
-v "$PWD:/source:ro" \
|
|
-v "$PWD/arch-output:/output" \
|
|
archlinux:base-devel bash -lc '
|
|
pacman -Syu --noconfirm git nodejs npm rust webkit2gtk-4.1 gtk3 hicolor-icon-theme libappindicator-gtk3 librsvg xdotool &&
|
|
useradd --create-home builder &&
|
|
cp -a /source /build &&
|
|
chown -R builder:builder /build &&
|
|
runuser -u builder -- bash -lc "cd /build && makepkg --cleanbuild --noconfirm" &&
|
|
cp /build/*.pkg.tar.zst /output/ &&
|
|
chmod 0644 /output/*.pkg.tar.zst
|
|
'
|
|
|
|
- name: Update pacman repository database
|
|
run: |
|
|
mkdir -p arch-repo
|
|
docker run --rm \
|
|
-v "$PWD/arch-output:/packages:ro" \
|
|
-v "$PWD/arch-repo:/repo" \
|
|
archlinux:base-devel bash -lc '
|
|
cd /repo &&
|
|
repo-add gitty.db.tar.gz /packages/*.pkg.tar.zst
|
|
'
|
|
|
|
- name: Upload package and repository database to CDN
|
|
working-directory: GitLite/cicd_tool
|
|
run: uv run arch_repo.py publish --packages-dir ../arch-output --repo-dir ../arch-repo
|