Updated local development settings to include comprehensive Git status checks, improving developer workflow visibility. Additionally, the Arch package building job in the CI pipeline now targets archlinux runners for better environment parity during builds. - Added multiple bash commands for detailed git logging and status retrieval - Switched app builder workflow runner to archlinux
226 lines
8.5 KiB
YAML
226 lines
8.5 KiB
YAML
name: "publish"
|
|
|
|
on:
|
|
release:
|
|
types: [published]
|
|
|
|
jobs:
|
|
publish-tauri:
|
|
permissions:
|
|
contents: write
|
|
environment: production
|
|
env:
|
|
# --- Gitea (unchanged) ---
|
|
GITEA_API: https://git.cbsk-tech.de/api/v1
|
|
OWNER: Christoph
|
|
REPO: GitLite
|
|
GITEA_TOKEN: ${{ secrets.ACTIONS_TOKEN }}
|
|
GITEA_FALLBACK_TOKEN: ${{ github.token }}
|
|
|
|
# --- MinIO / S3-compatible upload ---
|
|
MINIO_ENDPOINT: ${{ vars.MINIO_ENDPOINT }} # e.g. https://updates.example.com
|
|
S3_BUCKET: ${{ vars.S3_BUCKET }} # e.g. updates
|
|
AWS_ACCESS_KEY_ID: ${{ secrets.S3_ACCESS_KEY }} # used by aws cli
|
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.S3_SECRET_KEY }} # used by aws cli
|
|
ARTIFACT_BASE_URL: ${{ vars.ARTIFACT_BASE_URL }} # e.g. https://updates.example.com
|
|
S3_ACCESS_KEY: ${{ secrets.S3_ACCESS_KEY }} # used by cicd_tool
|
|
S3_SECRET_KEY: ${{ secrets.S3_SECRET_KEY }} # used by cicd_tool
|
|
|
|
defaults:
|
|
run:
|
|
working-directory: GitLite
|
|
|
|
strategy:
|
|
fail-fast: false
|
|
max-parallel: 1
|
|
matrix:
|
|
include:
|
|
# - platform: 'macos-latest'
|
|
# args: '--target aarch64-apple-darwin'
|
|
# - platform: 'macos-latest'
|
|
# args: '--target x86_64-apple-darwin'
|
|
- platform: "windows-latest"
|
|
bundles: "nsis"
|
|
updater_platform: "windows-x86_64"
|
|
no_strip: ""
|
|
- platform: "ubuntu-22.04"
|
|
bundles: "appimage"
|
|
updater_platform: "linux-x86_64"
|
|
no_strip: "1"
|
|
|
|
runs-on: ${{ matrix.platform }}
|
|
|
|
steps:
|
|
# cicd_tool/main.py expects the repo at <workspace>/GitLite, so check out there.
|
|
- uses: actions/checkout@v5
|
|
with:
|
|
path: GitLite
|
|
|
|
- name: install dependencies (ubuntu only)
|
|
if: matrix.platform == 'ubuntu-22.04'
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y build-essential curl wget file libssl-dev libwebkit2gtk-4.1-dev libayatana-appindicator3-dev librsvg2-dev patchelf libxdo-dev libfuse2
|
|
|
|
- name: setup node
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: lts/*
|
|
|
|
- name: Install uv
|
|
if: matrix.platform == 'ubuntu-22.04'
|
|
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
|
|
|
|
- name: install rust toolchain
|
|
if: matrix.platform == 'ubuntu-22.04'
|
|
uses: dtolnay/rust-toolchain@stable
|
|
|
|
- name: install frontend dependencies
|
|
run: npm ci
|
|
|
|
- name: Update package.json Version
|
|
run: npm version ${{ github.ref_name }} --no-git-tag-version --allow-same-version
|
|
|
|
- name: Update tauri.conf.json Version
|
|
env:
|
|
RELEASE_VERSION: ${{ github.ref_name }}
|
|
run: |
|
|
node -e "const fs=require('fs'); const path='src-tauri/tauri.conf.json'; const config=JSON.parse(fs.readFileSync(path,'utf8')); config.version=process.env.RELEASE_VERSION; fs.writeFileSync(path, JSON.stringify(config,null,2)+'\n');"
|
|
|
|
- name: Update PKGBUILD Version
|
|
run: |
|
|
node -e "const fs=require('fs'); const version=require('./package.json').version; const pkgbuild=fs.readFileSync('PKGBUILD','utf8').replace(/^pkgver=.*$/m, 'pkgver='+version).replace(/^pkgrel=.*$/m, 'pkgrel=1'); fs.writeFileSync('PKGBUILD', pkgbuild);"
|
|
|
|
- name: Commit and Push Changes
|
|
if: matrix.platform == 'windows-latest'
|
|
shell: powershell
|
|
run: |
|
|
git config user.name '${{ vars.USERNAME_GIT }}'
|
|
git config user.email '${{ vars.EMAIL_GIT }}'
|
|
# npm version also bumps the version inside package-lock.json, so stage it
|
|
# too -- otherwise it stays as an unstaged change and blocks the rebase.
|
|
git add package.json package-lock.json src-tauri/tauri.conf.json PKGBUILD
|
|
|
|
git commit -m 'Update version to ${{ github.ref_name }}'
|
|
if ($LASTEXITCODE -ne 0) {
|
|
# Version files already match the tag -> nothing to push, succeed quietly.
|
|
Write-Host 'No version changes to commit; skipping push.'
|
|
exit 0
|
|
}
|
|
|
|
# The release build runs in detached HEAD on the tag. Resolve the branch
|
|
# that should receive the version bump.
|
|
$branch = '${{ github.event.release.target_commitish }}'
|
|
if ([string]::IsNullOrEmpty($branch) -or $branch -match '^[0-9a-f]{40}$') {
|
|
$branch = (
|
|
git branch -r --contains $env:GITHUB_SHA |
|
|
ForEach-Object { $_.Trim() } |
|
|
Where-Object { $_ -and ($_ -notmatch '->') } |
|
|
ForEach-Object { $_ -replace '^(?:remotes/)?[^/]+/', '' } |
|
|
Select-Object -First 1
|
|
)
|
|
}
|
|
|
|
if ([string]::IsNullOrEmpty($branch)) {
|
|
Write-Host 'Could not determine branch for push.'
|
|
git branch -a
|
|
exit 1
|
|
}
|
|
|
|
# The tag may be behind the branch tip. Replay the bump commit on top of
|
|
# the current remote branch so the push is a clean fast-forward.
|
|
git fetch origin $branch
|
|
git rebase "origin/$branch"
|
|
if ($LASTEXITCODE -ne 0) {
|
|
git rebase --abort
|
|
Write-Host "Rebase onto origin/$branch failed."
|
|
exit 1
|
|
}
|
|
|
|
git push origin "HEAD:refs/heads/$branch"
|
|
|
|
- name: Build Tauri App
|
|
env:
|
|
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
|
|
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD}}
|
|
NO_STRIP: ${{ matrix.no_strip }}
|
|
run: npm run tauri -- build --bundles ${{ matrix.bundles }}
|
|
# ----------------------
|
|
# Upload to MinIO (via mc) and create latest.json
|
|
# ----------------------
|
|
- name: Upload artifacts to MinIO with cicd_tool
|
|
working-directory: GitLite/cicd_tool
|
|
env:
|
|
PUBLISH_PLATFORM: ${{ matrix.updater_platform }}
|
|
run: |
|
|
uv sync
|
|
uv run main.py
|
|
|
|
publish-arch:
|
|
name: Build and publish Arch package
|
|
runs-on: archlinux
|
|
environment: production
|
|
env:
|
|
MINIO_ENDPOINT: ${{ vars.MINIO_ENDPOINT }}
|
|
S3_BUCKET: ${{ vars.S3_BUCKET }}
|
|
S3_ACCESS_KEY: ${{ secrets.S3_ACCESS_KEY }}
|
|
S3_SECRET_KEY: ${{ secrets.S3_SECRET_KEY }}
|
|
|
|
defaults:
|
|
run:
|
|
working-directory: GitLite
|
|
|
|
steps:
|
|
- uses: actions/checkout@v5
|
|
with:
|
|
path: GitLite
|
|
|
|
- name: Set release version
|
|
env:
|
|
RELEASE_VERSION: ${{ github.ref_name }}
|
|
run: |
|
|
npm version "$RELEASE_VERSION" --no-git-tag-version --allow-same-version
|
|
node -e "const fs=require('fs'); const version=require('./package.json').version; const path='src-tauri/tauri.conf.json'; const config=JSON.parse(fs.readFileSync(path,'utf8')); config.version=version; fs.writeFileSync(path,JSON.stringify(config,null,2)+'\n');"
|
|
PACKAGE_VERSION="$(node -p "require('./package.json').version")"
|
|
sed -i "s/^pkgver=.*/pkgver=$PACKAGE_VERSION/; s/^pkgrel=.*/pkgrel=1/" PKGBUILD
|
|
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
|
|
|
|
- name: Restore pacman repository database
|
|
working-directory: GitLite/cicd_tool
|
|
run: |
|
|
uv sync
|
|
uv run arch_repo.py download-db --output ../arch-repo/gitty.db.tar.gz
|
|
|
|
- name: Build pkg.tar.zst with PKGBUILD
|
|
run: |
|
|
mkdir -p arch-output
|
|
docker run --rm \
|
|
-v "$PWD:/source:ro" \
|
|
-v "$PWD/arch-output:/output" \
|
|
archlinux:base-devel bash -lc '
|
|
pacman -Syu --noconfirm git nodejs npm rust webkit2gtk-4.1 gtk3 hicolor-icon-theme libappindicator-gtk3 librsvg xdotool &&
|
|
useradd --create-home builder &&
|
|
cp -a /source /build &&
|
|
chown -R builder:builder /build &&
|
|
runuser -u builder -- bash -lc "cd /build && makepkg --cleanbuild --noconfirm" &&
|
|
cp /build/*.pkg.tar.zst /output/ &&
|
|
chmod 0644 /output/*.pkg.tar.zst
|
|
'
|
|
|
|
- name: Update pacman repository database
|
|
run: |
|
|
mkdir -p arch-repo
|
|
docker run --rm \
|
|
-v "$PWD/arch-output:/packages:ro" \
|
|
-v "$PWD/arch-repo:/repo" \
|
|
archlinux:base-devel bash -lc '
|
|
cd /repo &&
|
|
repo-add gitty.db.tar.gz /packages/*.pkg.tar.zst
|
|
'
|
|
|
|
- name: Upload package and repository database to CDN
|
|
working-directory: GitLite/cicd_tool
|
|
run: uv run arch_repo.py publish --packages-dir ../arch-output --repo-dir ../arch-repo
|