Repository navigation
feat(release): step 3, add GoReleaser build, packaging, and release workflows - #41
seantronsen wants to merge 3 commits into
Conversation
|
Since we're already going to |
|
@seantronsen , this needs to provide an example |
|
@seantronsen another todo: need to create another stacked PR for the actual deployment of these packages to the remote repo (e.g., yum/dnf/apt etc.). |
89dd220 to
5b8f3de
Compare
|
@seantronsen You've requested my review, but I notice there are still outstanding items in the description and #41 (comment). Are those complete and do they need to be updated? |
It's ready. Two of the outstanding items are large enough to merit their own PRs. The third is just a note I need to delete. |
| # PKG_NAME is a glob; sort makes the pick deterministic if it | ||
| # matches more than one file. | ||
| pkg=$(find dist -type f -name "${PKG_NAME}" | sort | head -n 1) | ||
| if [[ -z "$pkg" ]]; then | ||
| echo "::error::no package in dist matches ${PKG_NAME}" | ||
| exit 1 | ||
| fi |
There was a problem hiding this comment.
This is the way we did it specifically for the release, but we may want to reconsider how to handle globbing for a generic action. Currently, this just selects the first package passed in the glob, but for instance if a package has multiple architectures, whichever is alphabetically first will get checked and the rest will want.
The expected behavior should probably be to check each package found by the glob, or maybe even be explicit by requiring explicit package names in a YAML array.
| args="release --clean" | ||
| if [[ "$IS_PR_BUILD" == true ]]; then | ||
| # nfpm: package versions can't be derived from a `pr-<N>` tag (deb | ||
| # requires a leading digit). Validate PR packages with | ||
| # build-check-goreleaser (snapshot) instead. | ||
| skip="announce,validate,archive,nfpm" | ||
| [[ "$SKIP_PUBLISH" == true ]] && skip+=",publish" | ||
| args+=" --skip=${skip}" | ||
| else |
There was a problem hiding this comment.
Unless we add --snapshot, container builds will be skipped entirely.
args="release --clean"
if [[ "$IS_PR_BUILD" == true ]]; then
if [[ "$SKIP_PUBLISH" == true ]]; then
args+=" --snapshot --skip=archive,nfpm"
else
args+=" --skip=announce,validate,archive,nfpm"
fi
else
# Existing release argument handling.
fi| digest=$(jq -r ' | ||
| [.[] | select(.extra.Digest != null)] as $a | ||
| | ([$a[] | select(.type == "Docker Manifest")] | ||
| + [$a[] | select(.type == "Docker Image")] | ||
| + [$a[] | select(.type == "Published Docker Image")])[0].extra.Digest // empty | ||
| ' <<< "$ARTIFACTS") |
There was a problem hiding this comment.
This selects the first image by type without checking registry-subject-name. The attestation then combines that digest with the caller's independently supplied image name here (lines 288-290):
github-actions/.github/workflows/build-release-goreleaser.yml
Lines 284 to 290 in 5b8f3de
With two image artifacts, foo followed by bar, this query returns foo's digest even when the requested subject is bar. For distinct images, pushing the attestation to bar can fail because that digest belongs to foo.
env:
SUBJECT: ${{ inputs.registry-subject-name }}
TAG: ${{ github.ref_name }}
run: |
digest=$(docker buildx imagetools inspect "${SUBJECT}:${TAG}" \
--format '{{json .Manifest}}' | jq -er '.digest')
echo "digest=${digest}" >> "$GITHUB_OUTPUT"We should resolve the digest for the named image. Something like the following (with the added env vars) should be sufficient:
env:
SUBJECT: ${{ inputs.registry-subject-name }}
TAG: ${{ github.ref_name }}
run: |
digest=$(docker buildx imagetools inspect "${SUBJECT}:${TAG}" \
--format '{{json .Manifest}}' | jq -er '.digest')
echo "digest=${digest}" >> "$GITHUB_OUTPUT"…releaser Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
…on workflows Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
Signed-off-by: Sean Tronsen <sean.tronsen@gmail.com>
5b8f3de to
1969d90
Compare
Description
Moves building, packaging, and releasing onto GoReleaser, driven by each repo's
.goreleaser.yaml, with sanity checks kept in Make.build-check-goreleaser: snapshot build of everything (binaries, archives, rpm/deb, images); publishes nothing, fork safe.build-release-goreleaser: mode chosen from the event.pull_requestpushespr-<N>images;v*tags publish semver images, packages (signed whengpg-keyis passed), a draft release with generated notes, attestations, and the derived GPG public key.validate-packages: rpm/deb file list, signature, install test, report-only lint; gatespublish-release..goreleaser.example.yml: annotated reference config.Important
Future PR: secure signing key procurement. Keys are currently passed as secrets by callers and only used on tag pushes; anyone with write access to a caller can still read them. Proper key handling is a separate PR.
Important
Future PR: deploy packages to remote distro repos. Packages are only attached to the GitHub release. Publishing to yum/apt repositories is a separate post-release workflow, out of scope for GoReleaser.
Checklist
make test(or equivalent) locally and all tests passgit commit -s) with my real name and email<filename>.licensesidecarLICENSES/directoryType of Change