The CI/CD pipeline has been significantly refactored to improve efficiency and reduce dependency on Docker containers during the build process. The core logic now uses temporary directories and direct execution commands, streamlining both the packaging of tarballs and the generation of the repository database. This change results in a faster and more robust build environment within the runner. - Removed reliance on docker run for package building - Simplified the mechanism for updating the pacman repository database - Added necessary dependencies to base system installation steps
231 lines
8.4 KiB
YAML
231 lines
8.4 KiB
YAML
name: "publish"
|
|
|
|
on:
|
|
release:
|
|
types: [published]
|
|
|
|
jobs:
|
|
publish-tauri:
|
|
permissions:
|
|
contents: write
|
|
environment: production
|
|
env:
|
|
# --- Gitea (unchanged) ---
|
|
GITEA_API: https://git.cbsk-tech.de/api/v1
|
|
OWNER: Christoph
|
|
REPO: GitLite
|
|
GITEA_TOKEN: ${{ secrets.ACTIONS_TOKEN }}
|
|
GITEA_FALLBACK_TOKEN: ${{ github.token }}
|
|
|
|
# --- MinIO / S3-compatible upload ---
|
|
MINIO_ENDPOINT: ${{ vars.MINIO_ENDPOINT }} # e.g. https://updates.example.com
|
|
S3_BUCKET: ${{ vars.S3_BUCKET }} # e.g. updates
|
|
AWS_ACCESS_KEY_ID: ${{ secrets.S3_ACCESS_KEY }} # used by aws cli
|
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.S3_SECRET_KEY }} # used by aws cli
|
|
ARTIFACT_BASE_URL: ${{ vars.ARTIFACT_BASE_URL }} # e.g. https://updates.example.com
|
|
S3_ACCESS_KEY: ${{ secrets.S3_ACCESS_KEY }} # used by cicd_tool
|
|
S3_SECRET_KEY: ${{ secrets.S3_SECRET_KEY }} # used by cicd_tool
|
|
|
|
defaults:
|
|
run:
|
|
working-directory: GitLite
|
|
|
|
strategy:
|
|
fail-fast: false
|
|
max-parallel: 1
|
|
matrix:
|
|
include:
|
|
# - platform: 'macos-latest'
|
|
# args: '--target aarch64-apple-darwin'
|
|
# - platform: 'macos-latest'
|
|
# args: '--target x86_64-apple-darwin'
|
|
- platform: "windows-latest"
|
|
bundles: "nsis"
|
|
updater_platform: "windows-x86_64"
|
|
no_strip: ""
|
|
- platform: "ubuntu-22.04"
|
|
bundles: "appimage"
|
|
updater_platform: "linux-x86_64"
|
|
no_strip: "1"
|
|
|
|
runs-on: ${{ matrix.platform }}
|
|
|
|
steps:
|
|
# cicd_tool/main.py expects the repo at <workspace>/GitLite, so check out there.
|
|
- uses: actions/checkout@v5
|
|
with:
|
|
path: GitLite
|
|
|
|
- name: install dependencies (ubuntu only)
|
|
if: matrix.platform == 'ubuntu-22.04'
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y build-essential curl wget file libssl-dev libwebkit2gtk-4.1-dev libayatana-appindicator3-dev librsvg2-dev patchelf libxdo-dev libfuse2
|
|
|
|
- name: setup node
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: lts/*
|
|
|
|
- name: Install uv
|
|
if: matrix.platform == 'ubuntu-22.04'
|
|
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
|
|
|
|
- name: install rust toolchain
|
|
if: matrix.platform == 'ubuntu-22.04'
|
|
uses: dtolnay/rust-toolchain@stable
|
|
|
|
- name: install frontend dependencies
|
|
run: npm ci
|
|
|
|
- name: Update package.json Version
|
|
run: npm version ${{ github.ref_name }} --no-git-tag-version --allow-same-version
|
|
|
|
- name: Update tauri.conf.json Version
|
|
env:
|
|
RELEASE_VERSION: ${{ github.ref_name }}
|
|
run: |
|
|
node -e "const fs=require('fs'); const path='src-tauri/tauri.conf.json'; const config=JSON.parse(fs.readFileSync(path,'utf8')); config.version=process.env.RELEASE_VERSION; fs.writeFileSync(path, JSON.stringify(config,null,2)+'\n');"
|
|
|
|
- name: Update PKGBUILD Version
|
|
run: |
|
|
node -e "const fs=require('fs'); const version=require('./package.json').version; const pkgbuild=fs.readFileSync('PKGBUILD','utf8').replace(/^pkgver=.*$/m, 'pkgver='+version).replace(/^pkgrel=.*$/m, 'pkgrel=1'); fs.writeFileSync('PKGBUILD', pkgbuild);"
|
|
|
|
- name: Commit and Push Changes
|
|
if: matrix.platform == 'windows-latest'
|
|
shell: powershell
|
|
run: |
|
|
git config user.name '${{ vars.USERNAME_GIT }}'
|
|
git config user.email '${{ vars.EMAIL_GIT }}'
|
|
# npm version also bumps the version inside package-lock.json, so stage it
|
|
# too -- otherwise it stays as an unstaged change and blocks the rebase.
|
|
git add package.json package-lock.json src-tauri/tauri.conf.json PKGBUILD
|
|
|
|
git commit -m 'Update version to ${{ github.ref_name }}'
|
|
if ($LASTEXITCODE -ne 0) {
|
|
# Version files already match the tag -> nothing to push, succeed quietly.
|
|
Write-Host 'No version changes to commit; skipping push.'
|
|
exit 0
|
|
}
|
|
|
|
# The release build runs in detached HEAD on the tag. Resolve the branch
|
|
# that should receive the version bump.
|
|
$branch = '${{ github.event.release.target_commitish }}'
|
|
if ([string]::IsNullOrEmpty($branch) -or $branch -match '^[0-9a-f]{40}$') {
|
|
$branch = (
|
|
git branch -r --contains $env:GITHUB_SHA |
|
|
ForEach-Object { $_.Trim() } |
|
|
Where-Object { $_ -and ($_ -notmatch '->') } |
|
|
ForEach-Object { $_ -replace '^(?:remotes/)?[^/]+/', '' } |
|
|
Select-Object -First 1
|
|
)
|
|
}
|
|
|
|
if ([string]::IsNullOrEmpty($branch)) {
|
|
Write-Host 'Could not determine branch for push.'
|
|
git branch -a
|
|
exit 1
|
|
}
|
|
|
|
# The tag may be behind the branch tip. Replay the bump commit on top of
|
|
# the current remote branch so the push is a clean fast-forward.
|
|
git fetch origin $branch
|
|
git rebase "origin/$branch"
|
|
if ($LASTEXITCODE -ne 0) {
|
|
git rebase --abort
|
|
Write-Host "Rebase onto origin/$branch failed."
|
|
exit 1
|
|
}
|
|
|
|
git push origin "HEAD:refs/heads/$branch"
|
|
|
|
- name: Build Tauri App
|
|
env:
|
|
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
|
|
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD}}
|
|
NO_STRIP: ${{ matrix.no_strip }}
|
|
run: npm run tauri -- build --bundles ${{ matrix.bundles }}
|
|
# ----------------------
|
|
# Upload to MinIO (via mc) and create latest.json
|
|
# ----------------------
|
|
- name: Upload artifacts to MinIO with cicd_tool
|
|
working-directory: GitLite/cicd_tool
|
|
env:
|
|
PUBLISH_PLATFORM: ${{ matrix.updater_platform }}
|
|
run: |
|
|
uv sync
|
|
uv run main.py
|
|
|
|
publish-arch:
|
|
name: Build and publish Arch package
|
|
runs-on: archlinux
|
|
environment: production
|
|
env:
|
|
MINIO_ENDPOINT: ${{ vars.MINIO_ENDPOINT }}
|
|
S3_BUCKET: ${{ vars.S3_BUCKET }}
|
|
S3_ACCESS_KEY: ${{ secrets.S3_ACCESS_KEY }}
|
|
S3_SECRET_KEY: ${{ secrets.S3_SECRET_KEY }}
|
|
|
|
defaults:
|
|
run:
|
|
working-directory: GitLite
|
|
|
|
steps:
|
|
- name: Prepare Arch job container
|
|
working-directory: /
|
|
run: |
|
|
pacman -Syu --noconfirm
|
|
pacman -S --needed --noconfirm nodejs npm git
|
|
|
|
- uses: actions/checkout@v5
|
|
with:
|
|
path: GitLite
|
|
|
|
- name: Set release version
|
|
env:
|
|
RELEASE_VERSION: ${{ github.ref_name }}
|
|
run: |
|
|
npm version "$RELEASE_VERSION" --no-git-tag-version --allow-same-version
|
|
node -e "const fs=require('fs'); const version=require('./package.json').version; const path='src-tauri/tauri.conf.json'; const config=JSON.parse(fs.readFileSync(path,'utf8')); config.version=version; fs.writeFileSync(path,JSON.stringify(config,null,2)+'\n');"
|
|
PACKAGE_VERSION="$(node -p "require('./package.json').version")"
|
|
sed -i "s/^pkgver=.*/pkgver=$PACKAGE_VERSION/; s/^pkgrel=.*/pkgrel=1/" PKGBUILD
|
|
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b
|
|
|
|
- name: Restore pacman repository database
|
|
working-directory: GitLite/cicd_tool
|
|
run: |
|
|
uv sync
|
|
uv run arch_repo.py download-db --output ../arch-repo/gitty.db.tar.gz
|
|
|
|
- name: Build pkg.tar.zst with PKGBUILD
|
|
run: |
|
|
pacman -S --needed --noconfirm \
|
|
base-devel git nodejs npm rust \
|
|
webkit2gtk-4.1 gtk3 hicolor-icon-theme \
|
|
libappindicator-gtk3 librsvg xdotool
|
|
|
|
mkdir -p arch-output
|
|
|
|
BUILD_ROOT="$(mktemp -d)"
|
|
cp -a . "$BUILD_ROOT/source"
|
|
|
|
useradd --create-home builder
|
|
chown -R builder:builder "$BUILD_ROOT/source"
|
|
|
|
runuser -u builder -- \
|
|
bash -lc "cd '$BUILD_ROOT/source' && makepkg --cleanbuild --noconfirm"
|
|
|
|
cp "$BUILD_ROOT"/source/*.pkg.tar.zst arch-output/
|
|
chmod 0644 arch-output/*.pkg.tar.zst
|
|
|
|
- name: Update pacman repository database
|
|
run: |
|
|
mkdir -p arch-repo
|
|
repo-add arch-repo/gitty.db.tar.gz arch-output/*.pkg.tar.zst
|
|
|
|
- name: Upload package and repository database to CDN
|
|
working-directory: GitLite/cicd_tool
|
|
run: uv run arch_repo.py publish --packages-dir ../arch-output --repo-dir ../arch-repo
|