1118 lines
41 KiB
YAML
1118 lines
41 KiB
YAML
# Multi-platform build + packaging workflow
|
|
# - Builds a pyinstaller executable on Windows, Debian, Arch, Fedora.
|
|
# - Packages using fpm into .deb, .rpm, and pacman (.pkg.tar.zst) files with explicit filenames.
|
|
# - Creates a GitHub Release with the produced artifacts.
|
|
#
|
|
# Notes:
|
|
# - Poetry is installed via snok/install-poetry@v1 in all jobs.
|
|
# - fpm gem is pinned to 1.16.0 in the examples; change as needed.
|
|
# - Fedora job uses tarball downloads for pyenv and python-build (non-interactive, CI-friendly).
|
|
name: Build Multi-Platform Binaries
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
new_version:
|
|
description: "New version to release (e.g., 0.2.0)"
|
|
required: true
|
|
type: string
|
|
pr_check_timeout:
|
|
description: "Timeout in seconds for PR status checks (default: 1800)"
|
|
required: false
|
|
type: number
|
|
default: 1800
|
|
jobs:
|
|
description: "Comma-separated jobs to run (e.g., build-windows,build-debian,build-arch,build-rhel)"
|
|
required: true
|
|
default: "build-windows,build-debian,build-arch,build-rhel"
|
|
start_from_step:
|
|
description: "Start workflow from this step (all subsequent steps will run)"
|
|
required: false
|
|
type: choice
|
|
default: "bump-version"
|
|
options:
|
|
- "bump-version"
|
|
- "merge-develop-to-main"
|
|
- "build-artifacts"
|
|
- "do-release"
|
|
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
|
|
# Prevent multiple release workflows from running simultaneously
|
|
# This is critical to prevent concurrent rollbacks
|
|
concurrency:
|
|
group: release-workflow
|
|
cancel-in-progress: false
|
|
|
|
env:
|
|
# change this if you prefer a different pinned fpm version
|
|
FPM_VERSION: "1.16.0"
|
|
# Personal Access Token for HTTPS git operations (populate in repository secrets)
|
|
CI_CD_PAT: ${{ secrets.CI_CD_PAT }}
|
|
CI_CD: true
|
|
|
|
jobs:
|
|
bump-version:
|
|
if: ${{ github.event.inputs.start_from_step == 'bump-version' }}
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
outputs:
|
|
pr_number: ${{ steps.create-pr.outputs.pr_number }}
|
|
steps:
|
|
- name: Validate version format
|
|
run: |
|
|
VERSION="${{ github.event.inputs.new_version }}"
|
|
# Full semver regex supporting:
|
|
# - Basic: 1.2.3
|
|
# - Prerelease: 1.2.3-beta, 1.2.3-rc.1, 1.2.3-alpha.1.2
|
|
# - Build metadata: 1.2.3+build, 1.2.3+20130313144700
|
|
# - Combined: 1.2.3-beta.1+build.123
|
|
if ! [[ "$VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+(-[a-zA-Z0-9]+(\.[a-zA-Z0-9]+)*)?(\+[a-zA-Z0-9]+(\.[a-zA-Z0-9]+)*)?$ ]]; then
|
|
echo "::error::Invalid version format: $VERSION"
|
|
echo "::error::Expected semantic version format (e.g., 1.2.3, 1.2.3-beta.1, 1.2.3+build.123)"
|
|
exit 1
|
|
fi
|
|
echo "Version format is valid: $VERSION"
|
|
|
|
- name: Checkout develop branch
|
|
uses: actions/checkout@v4
|
|
with:
|
|
ref: develop
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Configure git
|
|
run: |
|
|
git config user.name "github-actions[bot]"
|
|
git config user.email "github-actions[bot]@users.noreply.github.com"
|
|
|
|
- name: Set up Python 3.13
|
|
uses: actions/setup-python@v5
|
|
with:
|
|
python-version: '3.13'
|
|
|
|
- name: Install Poetry
|
|
uses: snok/install-poetry@v1
|
|
|
|
- name: Check for existing PR or branch
|
|
id: check-existing
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: |
|
|
set -e
|
|
VERSION="${{ github.event.inputs.new_version }}"
|
|
BRANCH_NAME="release/v${VERSION}"
|
|
|
|
# Check if branch already exists
|
|
if git ls-remote --heads origin "$BRANCH_NAME" | grep -q "$BRANCH_NAME"; then
|
|
echo "::warning::Branch $BRANCH_NAME already exists"
|
|
|
|
# Check if there's an open PR for this branch
|
|
EXISTING_PR=$(gh pr list --base develop --head "$BRANCH_NAME" --state open --json number --jq '.[0].number' || echo "")
|
|
|
|
if [ -n "$EXISTING_PR" ]; then
|
|
echo "::error::PR #$EXISTING_PR already exists for version $VERSION"
|
|
echo "::error::Please close or merge the existing PR before creating a new release"
|
|
exit 1
|
|
fi
|
|
|
|
echo "::error::Branch $BRANCH_NAME exists but no open PR found"
|
|
echo "::error::Please delete the branch or use a different version number"
|
|
exit 1
|
|
fi
|
|
|
|
echo "✓ No existing branch or PR found for version $VERSION"
|
|
echo "branch_name=$BRANCH_NAME" >> $GITHUB_OUTPUT
|
|
|
|
- name: Create release branch and bump version
|
|
id: bump
|
|
run: |
|
|
set -e
|
|
VERSION="${{ github.event.inputs.new_version }}"
|
|
BRANCH_NAME="${{ steps.check-existing.outputs.branch_name }}"
|
|
|
|
# Create and checkout release branch
|
|
git checkout -b "$BRANCH_NAME"
|
|
|
|
# Update version in pyproject.toml
|
|
poetry version "$VERSION"
|
|
|
|
# Commit the version change
|
|
git add pyproject.toml
|
|
git commit -m "Bump version to ${VERSION}"
|
|
|
|
# Push the branch with error handling
|
|
if ! git push origin "$BRANCH_NAME"; then
|
|
echo "::error::Failed to push branch $BRANCH_NAME"
|
|
exit 1
|
|
fi
|
|
|
|
echo "branch_name=$BRANCH_NAME" >> $GITHUB_OUTPUT
|
|
|
|
- name: Create PR to develop
|
|
id: create-pr
|
|
env:
|
|
GH_TOKEN: ${{ secrets.CI_CD_PAT }}
|
|
run: |
|
|
set -e
|
|
VERSION="${{ github.event.inputs.new_version }}"
|
|
BRANCH_NAME="${{ steps.bump.outputs.branch_name }}"
|
|
|
|
# Create PR with auto-merge enabled
|
|
PR_URL=$(gh pr create \
|
|
--base develop \
|
|
--head "$BRANCH_NAME" \
|
|
--title "Release v${VERSION}" \
|
|
--body "This PR bumps the version to ${VERSION} as part of the release process.
|
|
|
|
**Auto-generated by release workflow**
|
|
|
|
Once status checks pass, this PR will be automatically merged." \
|
|
--repo ${{ github.repository }} || {
|
|
echo "::error::Failed to create PR"
|
|
exit 1
|
|
})
|
|
|
|
# Extract PR number from URL
|
|
PR_NUMBER=$(echo "$PR_URL" | grep -oP '\d+$')
|
|
echo "pr_number=$PR_NUMBER" >> $GITHUB_OUTPUT
|
|
echo "Created PR #$PR_NUMBER: $PR_URL"
|
|
|
|
# Enable auto-merge (rebase)
|
|
if ! gh pr merge "$PR_NUMBER" --auto --rebase --repo ${{ github.repository }}; then
|
|
echo "::error::Failed to enable auto-merge for PR #$PR_NUMBER"
|
|
exit 1
|
|
fi
|
|
echo "Auto-merge enabled for PR #$PR_NUMBER"
|
|
|
|
wait-for-version-pr:
|
|
needs: [bump-version]
|
|
if: ${{ github.event.inputs.start_from_step == 'bump-version' }}
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
pull-requests: read
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Wait for PR status checks and merge
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: |
|
|
set -e
|
|
PR_NUMBER="${{ needs.bump-version.outputs.pr_number }}"
|
|
echo "Monitoring PR #$PR_NUMBER for status checks..."
|
|
|
|
MAX_WAIT=${{ github.event.inputs.pr_check_timeout || 1800 }}
|
|
INITIAL_INTERVAL=10
|
|
MAX_INTERVAL=300 # 5 minutes maximum
|
|
BACKOFF_MULTIPLIER=1.5
|
|
SLEEP_INTERVAL=$INITIAL_INTERVAL
|
|
ELAPSED=0
|
|
RETRY_COUNT=0
|
|
MAX_RETRIES=3
|
|
echo "Max wait time: ${MAX_WAIT}s, using exponential backoff (max interval: ${MAX_INTERVAL}s)"
|
|
|
|
while [ $ELAPSED -lt $MAX_WAIT ]; do
|
|
# Get PR status with retry logic
|
|
if ! PR_STATE=$(gh pr view "$PR_NUMBER" --json state --jq '.state' --repo ${{ github.repository }} 2>&1); then
|
|
RETRY_COUNT=$((RETRY_COUNT + 1))
|
|
if [ $RETRY_COUNT -ge $MAX_RETRIES ]; then
|
|
echo "::error::Failed to fetch PR status after $MAX_RETRIES retries"
|
|
exit 1
|
|
fi
|
|
echo "::warning::Failed to fetch PR status (attempt $RETRY_COUNT/$MAX_RETRIES), retrying..."
|
|
sleep $((2 ** RETRY_COUNT))
|
|
continue
|
|
fi
|
|
RETRY_COUNT=0
|
|
|
|
if [ "$PR_STATE" = "MERGED" ]; then
|
|
echo "✓ PR #$PR_NUMBER has been merged successfully!"
|
|
exit 0
|
|
fi
|
|
|
|
if [ "$PR_STATE" = "CLOSED" ]; then
|
|
echo "::error::PR #$PR_NUMBER was closed without merging"
|
|
exit 1
|
|
fi
|
|
|
|
# Check status checks with retry logic
|
|
RETRY_COUNT=0
|
|
if ! STATUS_JSON=$(gh pr view "$PR_NUMBER" --json statusCheckRollup --jq '.statusCheckRollup' --repo ${{ github.repository }} 2>&1); then
|
|
RETRY_COUNT=$((RETRY_COUNT + 1))
|
|
if [ $RETRY_COUNT -ge $MAX_RETRIES ]; then
|
|
echo "::error::Failed to fetch status checks after $MAX_RETRIES retries"
|
|
exit 1
|
|
fi
|
|
echo "::warning::Failed to fetch status checks (attempt $RETRY_COUNT/$MAX_RETRIES), retrying..."
|
|
sleep $((2 ** RETRY_COUNT))
|
|
continue
|
|
fi
|
|
|
|
# Count check states
|
|
TOTAL=$(echo "$STATUS_JSON" | jq 'length')
|
|
COMPLETED=$(echo "$STATUS_JSON" | jq '[.[] | select(.conclusion != null)] | length')
|
|
SUCCESS=$(echo "$STATUS_JSON" | jq '[.[] | select(.conclusion == "SUCCESS" or .conclusion == "NEUTRAL" or .conclusion == "SKIPPED")] | length')
|
|
FAILED=$(echo "$STATUS_JSON" | jq '[.[] | select(.conclusion == "FAILURE" or .conclusion == "CANCELLED" or .conclusion == "TIMED_OUT")] | length')
|
|
|
|
echo "Status checks: $COMPLETED/$TOTAL completed, $SUCCESS passed, $FAILED failed (interval: ${SLEEP_INTERVAL}s)"
|
|
|
|
# Check for failures
|
|
if [ "$FAILED" -gt 0 ]; then
|
|
echo "::error::Status checks failed for PR #$PR_NUMBER"
|
|
gh pr view "$PR_NUMBER" --json statusCheckRollup --jq '.statusCheckRollup[] | select(.conclusion == "FAILURE" or .conclusion == "CANCELLED" or .conclusion == "TIMED_OUT") | "- " + .name + ": " + .conclusion' --repo ${{ github.repository }}
|
|
exit 1
|
|
fi
|
|
|
|
echo "Waiting for checks to complete... (${ELAPSED}s elapsed)"
|
|
sleep $SLEEP_INTERVAL
|
|
ELAPSED=$((ELAPSED + SLEEP_INTERVAL))
|
|
|
|
# Calculate next interval with exponential backoff (capped at MAX_INTERVAL)
|
|
NEXT_INTERVAL=$(awk "BEGIN {printf \"%.0f\", $SLEEP_INTERVAL * $BACKOFF_MULTIPLIER}")
|
|
if [ $NEXT_INTERVAL -gt $MAX_INTERVAL ]; then
|
|
SLEEP_INTERVAL=$MAX_INTERVAL
|
|
else
|
|
SLEEP_INTERVAL=$NEXT_INTERVAL
|
|
fi
|
|
done
|
|
|
|
echo "::error::Timeout waiting for PR #$PR_NUMBER to merge"
|
|
exit 1
|
|
|
|
merge-develop-to-main:
|
|
needs: [wait-for-version-pr]
|
|
if: |
|
|
${{
|
|
always() &&
|
|
(github.event.inputs.start_from_step == 'bump-version' || github.event.inputs.start_from_step == 'merge-develop-to-main') &&
|
|
(needs.wait-for-version-pr.result == 'success' || needs.wait-for-version-pr.result == 'skipped')
|
|
}}
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
# Ensure only one merge operation runs at a time
|
|
concurrency:
|
|
group: main-branch-merge
|
|
cancel-in-progress: false
|
|
outputs:
|
|
pr_number: ${{ steps.create-pr.outputs.pr_number }}
|
|
previous_main_sha: ${{ steps.check-branches.outputs.previous_main_sha }}
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@v4
|
|
with:
|
|
ref: develop
|
|
fetch-depth: 0
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Configure git
|
|
run: |
|
|
git config user.name "github-actions[bot]"
|
|
git config user.email "github-actions[bot]@users.noreply.github.com"
|
|
|
|
- name: Check branches and verify merge readiness
|
|
id: check-branches
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: |
|
|
set -e
|
|
git fetch origin main develop
|
|
|
|
# Store current main SHA for reference
|
|
PREVIOUS_MAIN_SHA=$(git rev-parse origin/main)
|
|
echo "previous_main_sha=$PREVIOUS_MAIN_SHA" >> $GITHUB_OUTPUT
|
|
echo "Previous main SHA: $PREVIOUS_MAIN_SHA"
|
|
|
|
# Verify develop is ahead of main
|
|
MERGE_BASE=$(git merge-base origin/main origin/develop)
|
|
MAIN_SHA=$(git rev-parse origin/main)
|
|
|
|
if [ "$MERGE_BASE" != "$MAIN_SHA" ]; then
|
|
echo "::error::Main branch has commits not in develop. Cannot fast-forward."
|
|
echo "::error::Please merge or rebase main into develop first."
|
|
exit 1
|
|
fi
|
|
|
|
# Ensure develop is actually ahead
|
|
DEVELOP_SHA=$(git rev-parse origin/develop)
|
|
if [ "$MAIN_SHA" = "$DEVELOP_SHA" ]; then
|
|
echo "::warning::Main is already up to date with develop. Nothing to merge."
|
|
exit 0
|
|
fi
|
|
|
|
# Check for existing open PR from develop to main
|
|
EXISTING_PR=$(gh pr list --base main --head develop --state open --json number --jq '.[0].number' || echo "")
|
|
if [ -n "$EXISTING_PR" ]; then
|
|
echo "::error::PR #$EXISTING_PR already exists from develop to main"
|
|
echo "::error::Please close or merge the existing PR before creating a new one"
|
|
exit 1
|
|
fi
|
|
|
|
echo "✓ Ready to create PR from develop to main"
|
|
|
|
- name: Create PR from develop to main
|
|
id: create-pr
|
|
env:
|
|
GH_TOKEN: ${{ secrets.CI_CD_PAT }}
|
|
run: |
|
|
set -e
|
|
VERSION="${{ github.event.inputs.new_version }}"
|
|
|
|
# Create PR with auto-merge enabled
|
|
PR_URL=$(gh pr create \
|
|
--base main \
|
|
--head develop \
|
|
--title "Release v${VERSION} - Merge develop into main" \
|
|
--body "This PR merges develop into main for release v${VERSION}.
|
|
|
|
**Auto-generated by release workflow**
|
|
|
|
Once status checks pass, this PR will be automatically merged." \
|
|
--repo ${{ github.repository }} || {
|
|
echo "::error::Failed to create PR"
|
|
exit 1
|
|
})
|
|
|
|
# Extract PR number from URL
|
|
PR_NUMBER=$(echo "$PR_URL" | grep -oP '\d+$')
|
|
echo "pr_number=$PR_NUMBER" >> $GITHUB_OUTPUT
|
|
echo "Created PR #$PR_NUMBER: $PR_URL"
|
|
|
|
# Enable auto-merge (merge commit to maintain history)
|
|
if ! gh pr merge "$PR_NUMBER" --auto --merge --repo ${{ github.repository }}; then
|
|
echo "::error::Failed to enable auto-merge for PR #$PR_NUMBER"
|
|
exit 1
|
|
fi
|
|
echo "Auto-merge enabled for PR #$PR_NUMBER"
|
|
|
|
wait-for-main-pr:
|
|
needs: [merge-develop-to-main]
|
|
if: |
|
|
${{
|
|
always() &&
|
|
(github.event.inputs.start_from_step == 'bump-version' || github.event.inputs.start_from_step == 'merge-develop-to-main') &&
|
|
needs.merge-develop-to-main.result == 'success'
|
|
}}
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
pull-requests: read
|
|
outputs:
|
|
merge_commit_sha: ${{ steps.wait-merge.outputs.merge_commit_sha }}
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Wait for PR status checks and merge
|
|
id: wait-merge
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: |
|
|
set -e
|
|
PR_NUMBER="${{ needs.merge-develop-to-main.outputs.pr_number }}"
|
|
echo "Monitoring PR #$PR_NUMBER for status checks..."
|
|
|
|
MAX_WAIT=${{ github.event.inputs.pr_check_timeout || 1800 }}
|
|
INITIAL_INTERVAL=10
|
|
MAX_INTERVAL=300 # 5 minutes maximum
|
|
BACKOFF_MULTIPLIER=1.5
|
|
SLEEP_INTERVAL=$INITIAL_INTERVAL
|
|
ELAPSED=0
|
|
RETRY_COUNT=0
|
|
MAX_RETRIES=3
|
|
echo "Max wait time: ${MAX_WAIT}s, using exponential backoff (max interval: ${MAX_INTERVAL}s)"
|
|
|
|
while [ $ELAPSED -lt $MAX_WAIT ]; do
|
|
# Get PR status with retry logic
|
|
if ! PR_STATE=$(gh pr view "$PR_NUMBER" --json state --jq '.state' --repo ${{ github.repository }} 2>&1); then
|
|
RETRY_COUNT=$((RETRY_COUNT + 1))
|
|
if [ $RETRY_COUNT -ge $MAX_RETRIES ]; then
|
|
echo "::error::Failed to fetch PR status after $MAX_RETRIES retries"
|
|
exit 1
|
|
fi
|
|
echo "::warning::Failed to fetch PR status (attempt $RETRY_COUNT/$MAX_RETRIES), retrying..."
|
|
sleep $((2 ** RETRY_COUNT))
|
|
continue
|
|
fi
|
|
RETRY_COUNT=0
|
|
|
|
if [ "$PR_STATE" = "MERGED" ]; then
|
|
echo "✓ PR #$PR_NUMBER has been merged successfully!"
|
|
|
|
# Get the merge commit SHA
|
|
MERGE_COMMIT_SHA=$(gh pr view "$PR_NUMBER" --json mergeCommit --jq '.mergeCommit.oid' --repo ${{ github.repository }})
|
|
echo "merge_commit_sha=$MERGE_COMMIT_SHA" >> $GITHUB_OUTPUT
|
|
echo "Merge commit SHA: $MERGE_COMMIT_SHA"
|
|
exit 0
|
|
fi
|
|
|
|
if [ "$PR_STATE" = "CLOSED" ]; then
|
|
echo "::error::PR #$PR_NUMBER was closed without merging"
|
|
exit 1
|
|
fi
|
|
|
|
# Check status checks with retry logic
|
|
RETRY_COUNT=0
|
|
if ! STATUS_JSON=$(gh pr view "$PR_NUMBER" --json statusCheckRollup --jq '.statusCheckRollup' --repo ${{ github.repository }} 2>&1); then
|
|
RETRY_COUNT=$((RETRY_COUNT + 1))
|
|
if [ $RETRY_COUNT -ge $MAX_RETRIES ]; then
|
|
echo "::error::Failed to fetch status checks after $MAX_RETRIES retries"
|
|
exit 1
|
|
fi
|
|
echo "::warning::Failed to fetch status checks (attempt $RETRY_COUNT/$MAX_RETRIES), retrying..."
|
|
sleep $((2 ** RETRY_COUNT))
|
|
continue
|
|
fi
|
|
|
|
# Count check states
|
|
TOTAL=$(echo "$STATUS_JSON" | jq 'length')
|
|
COMPLETED=$(echo "$STATUS_JSON" | jq '[.[] | select(.conclusion != null)] | length')
|
|
SUCCESS=$(echo "$STATUS_JSON" | jq '[.[] | select(.conclusion == "SUCCESS" or .conclusion == "NEUTRAL" or .conclusion == "SKIPPED")] | length')
|
|
FAILED=$(echo "$STATUS_JSON" | jq '[.[] | select(.conclusion == "FAILURE" or .conclusion == "CANCELLED" or .conclusion == "TIMED_OUT")] | length')
|
|
|
|
echo "Status checks: $COMPLETED/$TOTAL completed, $SUCCESS passed, $FAILED failed (interval: ${SLEEP_INTERVAL}s)"
|
|
|
|
# Check for failures
|
|
if [ "$FAILED" -gt 0 ]; then
|
|
echo "::error::Status checks failed for PR #$PR_NUMBER"
|
|
gh pr view "$PR_NUMBER" --json statusCheckRollup --jq '.statusCheckRollup[] | select(.conclusion == "FAILURE" or .conclusion == "CANCELLED" or .conclusion == "TIMED_OUT") | "- " + .name + ": " + .conclusion' --repo ${{ github.repository }}
|
|
exit 1
|
|
fi
|
|
|
|
echo "Waiting for checks to complete... (${ELAPSED}s elapsed)"
|
|
sleep $SLEEP_INTERVAL
|
|
ELAPSED=$((ELAPSED + SLEEP_INTERVAL))
|
|
|
|
# Calculate next interval with exponential backoff (capped at MAX_INTERVAL)
|
|
NEXT_INTERVAL=$(awk "BEGIN {printf \"%.0f\", $SLEEP_INTERVAL * $BACKOFF_MULTIPLIER}")
|
|
if [ $NEXT_INTERVAL -gt $MAX_INTERVAL ]; then
|
|
SLEEP_INTERVAL=$MAX_INTERVAL
|
|
else
|
|
SLEEP_INTERVAL=$NEXT_INTERVAL
|
|
fi
|
|
done
|
|
|
|
echo "::error::Timeout waiting for PR #$PR_NUMBER to merge"
|
|
exit 1
|
|
|
|
build-windows:
|
|
needs: [wait-for-main-pr]
|
|
if: |
|
|
${{
|
|
always() &&
|
|
contains(github.event.inputs.jobs, 'build-windows') &&
|
|
(github.event.inputs.start_from_step == 'bump-version' ||
|
|
github.event.inputs.start_from_step == 'merge-develop-to-main' ||
|
|
github.event.inputs.start_from_step == 'build-artifacts') &&
|
|
(needs.wait-for-main-pr.result == 'success' || needs.wait-for-main-pr.result == 'skipped')
|
|
}}
|
|
runs-on: windows-latest
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@v4
|
|
with:
|
|
ref: main
|
|
|
|
- name: Set up Python 3.13
|
|
uses: actions/setup-python@v5
|
|
with:
|
|
python-version: '3.13'
|
|
|
|
- name: Install Poetry
|
|
uses: snok/install-poetry@v1
|
|
with:
|
|
version: latest
|
|
virtualenvs-create: true
|
|
virtualenvs-in-project: true
|
|
|
|
- name: Ensure Poetry is on PATH (Windows)
|
|
shell: pwsh
|
|
run: |
|
|
# Add Poetry user bin to PATH for subsequent steps in this job
|
|
$poetryPath = Join-Path $env:USERPROFILE ".local\bin"
|
|
Write-Output $poetryPath >> $Env:GITHUB_PATH
|
|
|
|
- name: Install dependencies
|
|
run: |
|
|
poetry install
|
|
|
|
- name: Build Windows executable
|
|
run: |
|
|
# Use the Windows spec file so packaging is consistent and reproducible
|
|
poetry run pyinstaller scripts/spec_scripts/android-file-handler-windows.spec
|
|
|
|
- name: Import GPG key
|
|
shell: pwsh
|
|
run: |
|
|
$env:GPG_TTY = "not a tty"
|
|
echo "${{ secrets.GPG_PRIVATE_KEY }}" | gpg --batch --import
|
|
gpg --list-secret-keys
|
|
|
|
- name: Sign and hash Windows executable
|
|
shell: pwsh
|
|
run: |
|
|
$exePath = Get-ChildItem -Path dist -Filter "android-file-handler.exe" -Recurse | Select-Object -First 1 -ExpandProperty FullName
|
|
if (-not $exePath) {
|
|
Write-Error "Executable not found"
|
|
exit 1
|
|
}
|
|
Write-Output "Found executable: $exePath"
|
|
|
|
# Create temporary file for passphrase
|
|
$passphraseFile = New-TemporaryFile
|
|
try {
|
|
"${{ secrets.GPG_PASSPHRASE }}" | Out-File -FilePath $passphraseFile -Encoding ASCII -NoNewline
|
|
|
|
# Sign with GPG using passphrase file
|
|
gpg --batch --yes --passphrase-file "$passphraseFile" --detach-sign --armor "$exePath"
|
|
}
|
|
finally {
|
|
# Clean up passphrase file
|
|
if (Test-Path $passphraseFile) {
|
|
Remove-Item $passphraseFile -Force
|
|
}
|
|
}
|
|
|
|
# Generate SHA-256 hash
|
|
$hash = (Get-FileHash -Path "$exePath" -Algorithm SHA256).Hash.ToLower()
|
|
$hashFile = "dist/android-file-handler-windows.sha256"
|
|
"$hash $(Split-Path -Leaf $exePath)" | Out-File -FilePath $hashFile -Encoding ASCII -NoNewline
|
|
Write-Output "SHA-256: $hash"
|
|
|
|
- name: Upload Windows artifact
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: windows-binary
|
|
path: |
|
|
dist/**/android-file-handler*.exe
|
|
dist/**/android-file-handler*.exe.asc
|
|
dist/android-file-handler.exe
|
|
dist/android-file-handler.exe.asc
|
|
dist/android-file-handler-windows.sha256
|
|
|
|
build-debian:
|
|
needs: [wait-for-main-pr]
|
|
if: |
|
|
${{
|
|
always() &&
|
|
contains(github.event.inputs.jobs, 'build-debian') &&
|
|
(github.event.inputs.start_from_step == 'bump-version' ||
|
|
github.event.inputs.start_from_step == 'merge-develop-to-main' ||
|
|
github.event.inputs.start_from_step == 'build-artifacts') &&
|
|
(needs.wait-for-main-pr.result == 'success' || needs.wait-for-main-pr.result == 'skipped')
|
|
}}
|
|
permissions:
|
|
contents: read
|
|
packages: read
|
|
env:
|
|
DISTRO_TYPE: debian
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: ghcr.io/jmr-dev/android-file-handler-debian-builder:debian13-trixie
|
|
credentials:
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@v4
|
|
with:
|
|
ref: main
|
|
|
|
- name: Build executable
|
|
run: |
|
|
# Container has Poetry and all dependencies pre-installed
|
|
poetry install --no-interaction
|
|
poetry run python scripts/build_package_linux.py
|
|
|
|
- name: Package .deb (fpm)
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
VERSION="$(poetry version -s)"
|
|
PKG_DIR="pkg_dist_debian"
|
|
mkdir -p dist
|
|
echo "Packaging from $PKG_DIR"
|
|
ls -la "$PKG_DIR" || true
|
|
|
|
ICON_PATH="$PKG_DIR/usr/share/icons/hicolor/256x256/apps/android-file-handler.png"
|
|
PKG_ITEMS=( "usr/local/bin/android-file-handler" "usr/share/applications/android-file-handler.desktop" )
|
|
if [ -f "$ICON_PATH" ]; then
|
|
PKG_ITEMS+=( "usr/share/icons/hicolor/256x256/apps/android-file-handler.png" )
|
|
else
|
|
echo "Note: icon not present, packaging without icon"
|
|
fi
|
|
|
|
fpm -s dir -t deb -n android-file-handler -v "$VERSION" \
|
|
--architecture amd64 --deb-user root --deb-group root \
|
|
--after-install scripts/debian_postinst.sh \
|
|
-p "dist/android-file-handler_${VERSION}_amd64.deb" -C "$PKG_DIR" "${PKG_ITEMS[@]}"
|
|
|
|
- name: Import GPG key
|
|
shell: bash
|
|
run: |
|
|
export GPG_TTY=$(tty) || true
|
|
echo "${{ secrets.GPG_PRIVATE_KEY }}" | gpg --batch --import
|
|
gpg --list-secret-keys
|
|
|
|
- name: Sign and hash Debian package
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
DEB_FILE=$(find dist -name "android-file-handler_*.deb" -type f | head -n 1)
|
|
if [ -z "$DEB_FILE" ]; then
|
|
echo "Error: .deb file not found"
|
|
exit 1
|
|
fi
|
|
echo "Found package: $DEB_FILE"
|
|
|
|
# Create temporary file for passphrase
|
|
PASSPHRASE_FILE=$(mktemp)
|
|
trap "rm -f '$PASSPHRASE_FILE'" EXIT
|
|
|
|
# Write passphrase to temporary file
|
|
echo "${{ secrets.GPG_PASSPHRASE }}" > "$PASSPHRASE_FILE"
|
|
|
|
# Sign with GPG using passphrase file
|
|
gpg --batch --yes --passphrase-file "$PASSPHRASE_FILE" --detach-sign --armor "$DEB_FILE"
|
|
|
|
# Clean up passphrase file
|
|
rm -f "$PASSPHRASE_FILE"
|
|
|
|
# Generate SHA-256 hash
|
|
sha256sum "$DEB_FILE" | awk '{print $1 " " $2}' > dist/android-file-handler-debian.sha256
|
|
echo "SHA-256: $(cat dist/android-file-handler-debian.sha256)"
|
|
|
|
- name: Upload Debian .deb
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: debian-package
|
|
path: |
|
|
dist/android-file-handler_*.deb
|
|
dist/android-file-handler_*.deb.asc
|
|
dist/android-file-handler-debian.sha256
|
|
pkg_dist_debian/**
|
|
|
|
build-arch:
|
|
needs: [wait-for-main-pr]
|
|
if: |
|
|
${{
|
|
always() &&
|
|
contains(github.event.inputs.jobs, 'build-arch') &&
|
|
(github.event.inputs.start_from_step == 'bump-version' ||
|
|
github.event.inputs.start_from_step == 'merge-develop-to-main' ||
|
|
github.event.inputs.start_from_step == 'build-artifacts') &&
|
|
(needs.wait-for-main-pr.result == 'success' || needs.wait-for-main-pr.result == 'skipped')
|
|
}}
|
|
permissions:
|
|
contents: read
|
|
packages: read
|
|
env:
|
|
DISTRO_TYPE: arch
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@v4
|
|
with:
|
|
ref: main
|
|
|
|
- name: Log in to GitHub Container Registry
|
|
uses: docker/login-action@v2
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.CI_CD_PAT }}
|
|
|
|
- name: Pull Docker image
|
|
run: docker pull ghcr.io/jmr-dev/android-file-handler-arch-builder:latest
|
|
|
|
- name: Build executable inside container
|
|
run: |
|
|
docker run --rm \
|
|
-v ${{ github.workspace }}:/workspace \
|
|
-w /workspace \
|
|
-e DISTRO_TYPE=${{ env.DISTRO_TYPE }} \
|
|
-e FPM_VERSION=${{ env.FPM_VERSION }} \
|
|
-e CI_CD=${{ env.CI_CD }} \
|
|
ghcr.io/jmr-dev/android-file-handler-arch-builder:latest \
|
|
sh -c "poetry install --no-interaction && poetry run python scripts/build_package_linux.py"
|
|
|
|
- name: Package pacman (fpm) inside container
|
|
run: |
|
|
docker run --rm \
|
|
-v ${{ github.workspace }}:/workspace \
|
|
-w /workspace \
|
|
-e FPM_VERSION=${{ env.FPM_VERSION }} \
|
|
ghcr.io/jmr-dev/android-file-handler-arch-builder:latest \
|
|
sh -c 'set -euo pipefail && \
|
|
VERSION="$(poetry version -s)" && \
|
|
PKG_DIR="pkg_dist_arch" && \
|
|
mkdir -p dist && \
|
|
echo "Packaging from $PKG_DIR" && \
|
|
ls -la "$PKG_DIR" || true && \
|
|
ICON_PATH="$PKG_DIR/usr/share/icons/hicolor/256x256/apps/android-file-handler.png" && \
|
|
if [ -f "$ICON_PATH" ]; then \
|
|
fpm -s dir -t pacman -n android-file-handler -v "$VERSION" \
|
|
--architecture x86_64 \
|
|
-p "dist/android-file-handler-${VERSION}-1-x86_64.pkg.tar.zst" \
|
|
-C "$PKG_DIR" \
|
|
"usr/bin/android-file-handler" \
|
|
"usr/share/applications/android-file-handler.desktop" \
|
|
"usr/share/icons/hicolor/256x256/apps/android-file-handler.png"; \
|
|
else \
|
|
echo "Note: icon not present, packaging without icon" && \
|
|
fpm -s dir -t pacman -n android-file-handler -v "$VERSION" \
|
|
--architecture x86_64 \
|
|
-p "dist/android-file-handler-${VERSION}-1-x86_64.pkg.tar.zst" \
|
|
-C "$PKG_DIR" \
|
|
"usr/bin/android-file-handler" \
|
|
"usr/share/applications/android-file-handler.desktop"; \
|
|
fi'
|
|
|
|
- name: Import GPG key
|
|
shell: bash
|
|
run: |
|
|
export GPG_TTY=$(tty) || true
|
|
echo "${{ secrets.GPG_PRIVATE_KEY }}" | gpg --batch --import
|
|
gpg --list-secret-keys
|
|
|
|
- name: Sign and hash Arch package
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
PKG_FILE=$(find dist -name "android-file-handler-*.pkg.tar.zst" -type f | head -n 1)
|
|
if [ -z "$PKG_FILE" ]; then
|
|
echo "Error: .pkg.tar.zst file not found"
|
|
exit 1
|
|
fi
|
|
echo "Found package: $PKG_FILE"
|
|
|
|
# Create temporary file for passphrase
|
|
PASSPHRASE_FILE=$(mktemp)
|
|
trap "rm -f '$PASSPHRASE_FILE'" EXIT
|
|
|
|
# Write passphrase to temporary file
|
|
echo "${{ secrets.GPG_PASSPHRASE }}" > "$PASSPHRASE_FILE"
|
|
|
|
# Sign with GPG using passphrase file
|
|
gpg --batch --yes --passphrase-file "$PASSPHRASE_FILE" --detach-sign --armor "$PKG_FILE"
|
|
|
|
# Clean up passphrase file
|
|
rm -f "$PASSPHRASE_FILE"
|
|
|
|
# Generate SHA-256 hash
|
|
sha256sum "$PKG_FILE" | awk '{print $1 " " $2}' > dist/android-file-handler-arch.sha256
|
|
echo "SHA-256: $(cat dist/android-file-handler-arch.sha256)"
|
|
|
|
- name: Upload Arch package
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: arch-package
|
|
path: |
|
|
dist/*.pkg.tar.*
|
|
dist/android-file-handler-arch.sha256
|
|
pkg_dist_arch/**
|
|
|
|
|
|
build-rhel:
|
|
needs: [wait-for-main-pr]
|
|
if: |
|
|
${{
|
|
always() &&
|
|
contains(github.event.inputs.jobs, 'build-rhel') &&
|
|
(github.event.inputs.start_from_step == 'bump-version' ||
|
|
github.event.inputs.start_from_step == 'merge-develop-to-main' ||
|
|
github.event.inputs.start_from_step == 'build-artifacts') &&
|
|
(needs.wait-for-main-pr.result == 'success' || needs.wait-for-main-pr.result == 'skipped')
|
|
}}
|
|
permissions:
|
|
contents: read
|
|
packages: read
|
|
env:
|
|
DISTRO_TYPE: rhel
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: ghcr.io/jmr-dev/android-file-handler-rhel-builder:fedora42
|
|
credentials:
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@v4
|
|
with:
|
|
ref: main
|
|
|
|
- name: Build RHEL package
|
|
run: |
|
|
set -euo pipefail
|
|
# Container has Poetry and all dependencies pre-installed
|
|
poetry install --no-interaction
|
|
poetry run python scripts/build_package_linux.py
|
|
|
|
- name: Package RHEL (fpm)
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
VERSION="$(poetry version -s)"
|
|
PKG_DIR="pkg_dist_rhel"
|
|
mkdir -p dist
|
|
echo "Packaging from $PKG_DIR (version=$VERSION)"
|
|
ls -la "$PKG_DIR" || true
|
|
|
|
ICON_PATH="$PKG_DIR/usr/share/icons/hicolor/256x256/apps/android-file-handler.png"
|
|
PKG_ITEMS=( "usr/bin/android-file-handler" "usr/share/applications/android-file-handler.desktop" )
|
|
if [ -f "$ICON_PATH" ]; then
|
|
PKG_ITEMS+=( "usr/share/icons/hicolor/256x256/apps/android-file-handler.png" )
|
|
else
|
|
echo "Note: icon not present, packaging without icon"
|
|
fi
|
|
|
|
fpm -s dir -t rpm -n android-file-handler -v "$VERSION" --architecture x86_64 --prefix /usr/bin --after-install scripts/rhel_postinst.sh -p "dist/android-file-handler-${VERSION}.x86_64.rpm" -C "$PKG_DIR" "${PKG_ITEMS[@]}"
|
|
|
|
- name: Import GPG key
|
|
shell: bash
|
|
run: |
|
|
export GPG_TTY=$(tty) || true
|
|
echo "${{ secrets.GPG_PRIVATE_KEY }}" | gpg --batch --import
|
|
gpg --list-secret-keys
|
|
|
|
- name: Sign and hash RHEL package
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
RPM_FILE=$(find dist -name "android-file-handler-*.rpm" -type f | head -n 1)
|
|
if [ -z "$RPM_FILE" ]; then
|
|
echo "Error: .rpm file not found"
|
|
exit 1
|
|
fi
|
|
echo "Found package: $RPM_FILE"
|
|
|
|
# Create temporary file for passphrase
|
|
PASSPHRASE_FILE=$(mktemp)
|
|
trap "rm -f '$PASSPHRASE_FILE'" EXIT
|
|
|
|
# Write passphrase to temporary file
|
|
echo "${{ secrets.GPG_PASSPHRASE }}" > "$PASSPHRASE_FILE"
|
|
|
|
# Sign with GPG using passphrase file
|
|
gpg --batch --yes --passphrase-file "$PASSPHRASE_FILE" --detach-sign --armor "$RPM_FILE"
|
|
|
|
# Clean up passphrase file
|
|
rm -f "$PASSPHRASE_FILE"
|
|
|
|
# Generate SHA-256 hash
|
|
sha256sum "$RPM_FILE" | awk '{print $1 " " $2}' > dist/android-file-handler-rhel.sha256
|
|
echo "SHA-256: $(cat dist/android-file-handler-rhel.sha256)"
|
|
|
|
- name: Upload RHEL artifacts
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: rhel-package
|
|
path: |
|
|
dist/*.rpm
|
|
dist/*.rpm.asc
|
|
dist/android-file-handler-rhel.sha256
|
|
pkg_dist_rhel/**
|
|
|
|
rollback-on-build-failure:
|
|
needs: [wait-for-main-pr, build-windows, build-debian, build-arch, build-rhel]
|
|
if: |
|
|
${{
|
|
always() &&
|
|
(github.event.inputs.start_from_step == 'bump-version' ||
|
|
github.event.inputs.start_from_step == 'merge-develop-to-main' ||
|
|
github.event.inputs.start_from_step == 'build-artifacts') &&
|
|
needs.wait-for-main-pr.result == 'success' &&
|
|
(needs.build-windows.result == 'failure' ||
|
|
needs.build-debian.result == 'failure' ||
|
|
needs.build-arch.result == 'failure' ||
|
|
needs.build-rhel.result == 'failure')
|
|
}}
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write
|
|
# Prevent multiple rollback operations from running concurrently
|
|
concurrency:
|
|
group: main-branch-rollback
|
|
cancel-in-progress: false
|
|
steps:
|
|
- name: Checkout main branch
|
|
uses: actions/checkout@v4
|
|
with:
|
|
ref: main
|
|
fetch-depth: 0
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Rollback merge commit on build failure
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: |
|
|
set -e
|
|
echo "::error::One or more build jobs failed - initiating rollback"
|
|
|
|
# Configure git
|
|
git config user.name "github-actions[bot]"
|
|
git config user.email "github-actions[bot]@users.noreply.github.com"
|
|
|
|
# Fetch latest
|
|
git fetch origin main
|
|
|
|
# Get the merge commit that needs to be reverted
|
|
MERGE_COMMIT="${{ needs.wait-for-main-pr.outputs.merge_commit_sha }}"
|
|
echo "Reverting merge commit: $MERGE_COMMIT"
|
|
|
|
# Checkout main and create revert commit
|
|
git checkout main
|
|
git revert "$MERGE_COMMIT" --no-edit -m 1
|
|
|
|
# Push the revert commit with error handling
|
|
if ! git push origin main; then
|
|
echo "::error::Failed to push revert commit"
|
|
exit 1
|
|
fi
|
|
|
|
echo "::error::Reverted merge commit $MERGE_COMMIT on main branch"
|
|
echo "::error::Build failures detected:"
|
|
|
|
# Report which builds failed
|
|
if [ "${{ needs.build-windows.result }}" = "failure" ]; then
|
|
echo "::error:: - build-windows: FAILED"
|
|
fi
|
|
if [ "${{ needs.build-debian.result }}" = "failure" ]; then
|
|
echo "::error:: - build-debian: FAILED"
|
|
fi
|
|
if [ "${{ needs.build-arch.result }}" = "failure" ]; then
|
|
echo "::error:: - build-arch: FAILED"
|
|
fi
|
|
if [ "${{ needs.build-rhel.result }}" = "failure" ]; then
|
|
echo "::error:: - build-rhel: FAILED"
|
|
fi
|
|
|
|
exit 1
|
|
|
|
|
|
do-release:
|
|
needs: [rollback-on-build-failure, build-windows, build-debian, build-arch, build-rhel]
|
|
if: |
|
|
${{
|
|
always() &&
|
|
(github.event.inputs.start_from_step == 'bump-version' ||
|
|
github.event.inputs.start_from_step == 'merge-develop-to-main' ||
|
|
github.event.inputs.start_from_step == 'build-artifacts' ||
|
|
github.event.inputs.start_from_step == 'do-release') &&
|
|
needs.rollback-on-build-failure.result != 'failure' &&
|
|
(needs.build-windows.result == 'success' || needs.build-windows.result == 'skipped') &&
|
|
(needs.build-debian.result == 'success' || needs.build-debian.result == 'skipped') &&
|
|
(needs.build-arch.result == 'success' || needs.build-arch.result == 'skipped') &&
|
|
(needs.build-rhel.result == 'success' || needs.build-rhel.result == 'skipped')
|
|
}}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@v4
|
|
with:
|
|
ref: main
|
|
|
|
- name: Install Poetry
|
|
uses: snok/install-poetry@v1
|
|
|
|
- name: Get version
|
|
id: version
|
|
run: echo "version=$(poetry version -s)" >> $GITHUB_OUTPUT
|
|
|
|
- name: Download all artifacts
|
|
uses: actions/download-artifact@v4
|
|
with:
|
|
merge-multiple: true
|
|
path: ./binaries
|
|
|
|
- name: Prepare release files
|
|
run: |
|
|
mkdir -p ./release-files
|
|
# Copy binary packages
|
|
find ./binaries -name "*.exe" -exec cp {} ./release-files/ \; || true
|
|
find ./binaries -name "*.deb" -exec cp {} ./release-files/ \; || true
|
|
find ./binaries -name "*.rpm" -exec cp {} ./release-files/ \; || true
|
|
find ./binaries -name "*.pkg.tar.*" -exec cp {} ./release-files/ \; || true
|
|
# Copy GPG signatures
|
|
find ./binaries -name "*.asc" -exec cp {} ./release-files/ \; || true
|
|
# Copy SHA-256 hashes
|
|
find ./binaries -name "*.sha256" -exec cp {} ./release-files/ \; || true
|
|
|
|
echo "Release files prepared:"
|
|
ls -lh ./release-files/
|
|
|
|
- name: Create Release
|
|
uses: softprops/action-gh-release@v1
|
|
with:
|
|
tag_name: v${{ steps.version.outputs.version }}
|
|
name: Release v${{ steps.version.outputs.version }}
|
|
files: ./release-files/*
|
|
draft: false
|
|
prerelease: false
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
upload-s3:
|
|
needs: [rollback-on-build-failure, build-windows, build-debian, build-arch, build-rhel]
|
|
if: |
|
|
${{
|
|
always() &&
|
|
(github.event.inputs.start_from_step == 'bump-version' ||
|
|
github.event.inputs.start_from_step == 'merge-develop-to-main' ||
|
|
github.event.inputs.start_from_step == 'build-artifacts' ||
|
|
github.event.inputs.start_from_step == 'do-release') &&
|
|
needs.rollback-on-build-failure.result != 'failure' &&
|
|
(needs.build-windows.result == 'success' || needs.build-windows.result == 'skipped') &&
|
|
(needs.build-debian.result == 'success' || needs.build-debian.result == 'skipped') &&
|
|
(needs.build-arch.result == 'success' || needs.build-arch.result == 'skipped') &&
|
|
(needs.build-rhel.result == 'success' || needs.build-rhel.result == 'skipped')
|
|
}}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@v4
|
|
with:
|
|
ref: main
|
|
|
|
- name: Install AWS CLI
|
|
run: |
|
|
python -m pip install --upgrade pip awscli
|
|
|
|
- name: Download build artifacts
|
|
uses: actions/download-artifact@v4
|
|
with:
|
|
merge-multiple: true
|
|
path: ./binaries
|
|
|
|
- name: Configure AWS credentials
|
|
uses: aws-actions/configure-aws-credentials@v2
|
|
with:
|
|
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
|
|
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
|
aws-region: ${{ secrets.AWS_REGION }}
|
|
|
|
- name: Upload artifacts to S3
|
|
run: |
|
|
set -euo pipefail
|
|
if [ -z "${{ secrets.S3_BUCKET }}" ]; then
|
|
echo "S3_BUCKET secret not set; skipping upload"
|
|
exit 0
|
|
fi
|
|
aws s3 sync ./binaries s3://${{ secrets.S3_BUCKET }}/builds/${{ github.run_id }}/ --acl private
|
|
env:
|
|
AWS_PAGER: ""
|
|
|
|
sync-wiki:
|
|
needs: do-release
|
|
if: always() && needs.do-release.result == 'success'
|
|
uses: ./.github/workflows/sync-wiki.yml
|
|
with:
|
|
branch: main
|
|
secrets: inherit |