Skip to content

feat(release): step 3, add GoReleaser build, packaging, and release workflows - #41

Open
seantronsen wants to merge 3 commits into
seantronsen/feat/workflow-portsfrom
seantronsen/feat/redesign-deployment
Open

seantronsen wants to merge 3 commits into
seantronsen/feat/workflow-portsfrom
seantronsen/feat/redesign-deployment

Conversation

@seantronsen

@seantronsen seantronsen commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Description

Moves building, packaging, and releasing onto GoReleaser, driven by each repo's .goreleaser.yaml, with sanity checks kept in Make.

  • build-check-goreleaser: snapshot build of everything (binaries, archives, rpm/deb, images); publishes nothing, fork safe.
  • build-release-goreleaser: mode chosen from the event. pull_request pushes pr-<N> images; v* tags publish semver images, packages (signed when gpg-key is passed), a draft release with generated notes, attestations, and the derived GPG public key.
  • validate-packages: rpm/deb file list, signature, install test, report-only lint; gates publish-release.
  • .goreleaser.example.yml: annotated reference config.
  • Deprecates the workflows/actions these replace (GoReleaser/Docker build workflows, quadlet RPM build, GPG signing chain, signed-artifact release, quadlet validation). They warn at runtime and stay for pinned callers.

Important

Future PR: secure signing key procurement. Keys are currently passed as secrets by callers and only used on tag pushes; anyone with write access to a caller can still read them. Proper key handling is a separate PR.

Important

Future PR: deploy packages to remote distro repos. Packages are only attached to the GitHub release. Publishing to yum/apt repositories is a separate post-release workflow, out of scope for GoReleaser.

Checklist

  • My code follows the style guidelines of this project
  • I have added/updated comments where needed
  • I have added tests that prove my fix is effective or my feature works
  • I have run make test (or equivalent) locally and all tests pass
  • I have updated the relevant documentation (CLI examples, man pages, README, other docs, etc.)
  • DCO Sign-off: All commits are signed off (git commit -s) with my real name and email
  • REUSE Compliance:
    • Each new/modified source file has SPDX copyright and license headers
    • Any non-commentable files include a <filename>.license sidecar
    • All referenced licenses are present in the LICENSES/ directory

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Dependency update
  • Build system/CI

@seantronsen seantronsen self-assigned this Oct 6, 2026
@seantronsen

Copy link
Copy Markdown
Contributor Author

Since we're already going to v4, we should consider deleting the now deprecated old deployment methodology in favor of the new one.

@seantronsen
seantronsen requested a review from synackd October 6, 2026 04:03
@seantronsen
seantronsen marked this pull request as ready for review October 6, 2026 04:04
@seantronsen
seantronsen added this pull request to stack #40 October 6, 2026 04:04
@seantronsen

Copy link
Copy Markdown
Contributor Author

@seantronsen , this needs to provide an example .goreleaser.yml file.

@seantronsen

Copy link
Copy Markdown
Contributor Author

@seantronsen another todo: need to create another stacked PR for the actual deployment of these packages to the remote repo (e.g., yum/dnf/apt etc.).

@seantronsen
seantronsen force-pushed the seantronsen/feat/redesign-deployment branch from 89dd220 to 5b8f3de Compare October 6, 2026 15:22
@synackd synackd added this to the v4 milestone Oct 7, 2026
@synackd synackd changed the title v4: step 3, deployment sanity. feat(release): step 3, add GoReleaser build, packaging, and release workflows Oct 7, 2026
@synackd

synackd commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@seantronsen You've requested my review, but I notice there are still outstanding items in the description and #41 (comment). Are those complete and do they need to be updated?

@seantronsen

Copy link
Copy Markdown
Contributor Author

@seantronsen You've requested my review, but I notice there are still outstanding items in the description and #41 (comment). Are those complete and do they need to be updated?

It's ready. Two of the outstanding items are large enough to merit their own PRs. The third is just a note I need to delete.

Comment on lines +99 to +105
# PKG_NAME is a glob; sort makes the pick deterministic if it
# matches more than one file.
pkg=$(find dist -type f -name "${PKG_NAME}" | sort | head -n 1)
if [[ -z "$pkg" ]]; then
echo "::error::no package in dist matches ${PKG_NAME}"
exit 1
fi

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the way we did it specifically for the release, but we may want to reconsider how to handle globbing for a generic action. Currently, this just selects the first package passed in the glob, but for instance if a package has multiple architectures, whichever is alphabetically first will get checked and the rest will want.

The expected behavior should probably be to check each package found by the glob, or maybe even be explicit by requiring explicit package names in a YAML array.

Comment on lines +221 to +229
args="release --clean"
if [[ "$IS_PR_BUILD" == true ]]; then
# nfpm: package versions can't be derived from a `pr-<N>` tag (deb
# requires a leading digit). Validate PR packages with
# build-check-goreleaser (snapshot) instead.
skip="announce,validate,archive,nfpm"
[[ "$SKIP_PUBLISH" == true ]] && skip+=",publish"
args+=" --skip=${skip}"
else

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unless we add --snapshot, container builds will be skipped entirely.

args="release --clean"
if [[ "$IS_PR_BUILD" == true ]]; then
  if [[ "$SKIP_PUBLISH" == true ]]; then
    args+=" --snapshot --skip=archive,nfpm"
  else
    args+=" --skip=announce,validate,archive,nfpm"
  fi
else
  # Existing release argument handling.
fi

Comment on lines +270 to +275
digest=$(jq -r '
[.[] | select(.extra.Digest != null)] as $a
| ([$a[] | select(.type == "Docker Manifest")]
+ [$a[] | select(.type == "Docker Image")]
+ [$a[] | select(.type == "Published Docker Image")])[0].extra.Digest // empty
' <<< "$ARTIFACTS")

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This selects the first image by type without checking registry-subject-name. The attestation then combines that digest with the caller's independently supplied image name here (lines 288-290):

- name: Attest image
if: ${{ env.IS_PR_BUILD == 'false' && env.SKIP_PUBLISH == 'false' && inputs.registry-subject-name != '' && steps.metadata.outputs.digest != '' }}
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-name: ${{ inputs.registry-subject-name }}
subject-digest: ${{ steps.metadata.outputs.digest }}
push-to-registry: true

With two image artifacts, foo followed by bar, this query returns foo's digest even when the requested subject is bar. For distinct images, pushing the attestation to bar can fail because that digest belongs to foo.

env:
  SUBJECT: ${{ inputs.registry-subject-name }}
  TAG: ${{ github.ref_name }}
run: |
  digest=$(docker buildx imagetools inspect "${SUBJECT}:${TAG}" \
    --format '{{json .Manifest}}' | jq -er '.digest')
  echo "digest=${digest}" >> "$GITHUB_OUTPUT"

We should resolve the digest for the named image. Something like the following (with the added env vars) should be sufficient:

env:
  SUBJECT: ${{ inputs.registry-subject-name }}
  TAG: ${{ github.ref_name }}
run: |
  digest=$(docker buildx imagetools inspect "${SUBJECT}:${TAG}" \
    --format '{{json .Manifest}}' | jq -er '.digest')
  echo "digest=${digest}" >> "$GITHUB_OUTPUT"

…releaser

Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
…on workflows

Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
@synackd
synackd force-pushed the seantronsen/feat/redesign-deployment branch from 5b8f3de to 1969d90 Compare October 8, 2026 21:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants