Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
190 changes: 24 additions & 166 deletions .github/workflows/auto_tag.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,180 +19,38 @@ on:

jobs:
preparation:
runs-on: ubuntu-latest
# This should allow parallel runs in a chain, e.g. OSS->Headless->Experience->Commerce
# whilst allowing Satis to process
timeout-minutes: 30
runs-on: ubuntu-26.04

steps:
- name: Generate token
id: generate_token
uses: actions/create-github-app-token@v2
# No need to wait for the parent package (ibexa/oss) β€” it is available on Packagist, not via Satis
- name: Check for headless-assets package in Satis
uses: ibexa/gh-workflows/actions/check-composer-package@ibx-11778-metapackage-composite-actions
with:
app-id: ${{ secrets.AUTOMATION_CLIENT_ID }}
private-key: ${{ secrets.AUTOMATION_CLIENT_SECRET }}
owner: ${{ github.repository_owner }}
package: ibexa/headless-assets
version: v${{ inputs.version }}
repository-url: https://updates.ibexa.co
auth-key: ${{ secrets.SATIS_NETWORK_KEY }}
auth-token: ${{ secrets.SATIS_NETWORK_TOKEN }}

- name: Check for headless-assets tag
uses: octokit/request-action@v2.x
with:
owner: ibexa
repo: headless-assets
route: /repos/{owner}/{repo}/contents/package.json?ref=v${{ inputs.version }}
env:
GITHUB_TOKEN: ${{ steps.generate_token.outputs.token }}

# The jq command would return a zero exit status if it was able to filter the input JSON data and
# produce at least one matching object in the array, and a non-zero exit status if no matching object was found.
# This particular JQ filter expression:
# .packages."${{ env.PARENT }}"[]: accesses an array of objects in the packages object, with the key specified by the environment variable PARENT.
# select(.version == "${{ env.V_VERSION }}"): filters the array to only include objects where the version property is equal to the value of the environment variable V_VERSION.

# No need to validate for oss version in satis
- name: Validate satis for headless version
if: github.event.repository.name == 'experience'
env:
SATIS_NETWORK_KEY: ${{ secrets.SATIS_NETWORK_KEY }}
SATIS_NETWORK_TOKEN: ${{ secrets.SATIS_NETWORK_TOKEN }}
PARENT: ibexa/headless
V_VERSION: v${{ inputs.version }}
run: |
for EXPONENTIAL_BACKOFF in {1..10}; do
curl https://updates.ibexa.co/p2/${PARENT}.json -s -u $SATIS_NETWORK_KEY:$SATIS_NETWORK_TOKEN | jq -e '.packages."${{ env.PARENT }}"[] | select(.version == "${{ env.V_VERSION }}")' && break;
DELAY=$((2**$EXPONENTIAL_BACKOFF))
echo "${PARENT}:${V_VERSION} not yet available, sleeping for $DELAY seconds"
sleep $DELAY
done

- name: Validate satis for experience version
if: github.event.repository.name == 'commerce'
env:
SATIS_NETWORK_KEY: ${{ secrets.SATIS_NETWORK_KEY }}
SATIS_NETWORK_TOKEN: ${{ secrets.SATIS_NETWORK_TOKEN }}
PARENT: ibexa/experience
V_VERSION: v${{ inputs.version }}
run: |
for EXPONENTIAL_BACKOFF in {1..10}; do
curl https://updates.ibexa.co/p2/${PARENT}.json -s -u $SATIS_NETWORK_KEY:$SATIS_NETWORK_TOKEN | jq -e '.packages."${{ env.PARENT }}"[] | select(.version == "${{ env.V_VERSION }}")' && break;
DELAY=$((2**$EXPONENTIAL_BACKOFF))
echo "${PARENT}:${V_VERSION} not yet available, sleeping for $DELAY seconds"
sleep $DELAY
done

action:
needs: preparation
runs-on: ubuntu-22.04

steps:
- name: Install sponge
run: |
sudo apt-get install -y moreutils
runs-on: ubuntu-26.04

- name: Setup PHP Action
uses: shivammathur/setup-php@v2
with:
php-version: 8.3
coverage: none
extensions: pdo_sqlite, gd
tools: cs2pr

- name: Generate token
id: generate_token
uses: tibdex/github-app-token@v1
with:
app_id: ${{ secrets.AUTOMATION_CLIENT_ID }}
installation_id: ${{ secrets.AUTOMATION_CLIENT_INSTALLATION }}
private_key: ${{ secrets.AUTOMATION_CLIENT_SECRET }}

- uses: actions/checkout@v4
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false

- name: Get release information
uses: octokit/request-action@v2.x
id: release
- name: Set dependency versions, commit, tag and push
uses: ibexa/gh-workflows/actions/create-metapackage-tag@ibx-11778-metapackage-composite-actions
with:
owner: ibexa
repo: release-maker
route: /repos/{owner}/{repo}/contents/releases/${{ inputs.version }}/release.json
env:
GITHUB_TOKEN: ${{ steps.generate_token.outputs.token }}

# The effect of this jq command is to take a JSON array of objects,
# transform each object into a new object using its packageName and targetVersion properties,
# and return the result as a single JSON object.
# The sponge command is used to pipe the output of jq back into the same file, effectively replacing its contents with the updated JSON data.
- name: Process release information
run: |
cat > input.json <<'EOF'
${{ steps.release.outputs.data }}
EOF
jq -r '.["content"]' input.json | base64 --decode | jq -c . > release.json
jq -s '[ .[][] | { (.packageName): (.targetVersion) } ] | add' release.json | sponge release.json

- name: Set minimum stability
run: |
VERSION=$( echo ${{ inputs.version }} | cut -d '-' -f 2 )
SET_STABILITY="composer config minimum-stability"
$SET_STABILITY --unset
composer config prefer-stable --unset
case $VERSION in
alpha*|beta*|rc*) composer config prefer-stable true ;;&
alpha*) $SET_STABILITY alpha ;;
beta*) $SET_STABILITY beta ;;
rc*) $SET_STABILITY rc ;;
esac;

- name: Patch parent version for Headless
run: |
jq '.require["ibexa/headless-assets"] |= "${{ inputs.version }}"' composer.json | sponge composer.json
jq '.require["ibexa/oss"] |= "${{ inputs.version }}"' composer.json | sponge composer.json

# The effect of this jq command is to modify the require property of the input JSON object by using values from the $release object,
# if they exist, to update the values of the keys in the require object.
- name: Patch composer require versions
run: |
jq --slurpfile release <(cat release.json) '
.require |= (
to_entries |
map({
key: .key,
value: (if ($release[0][.key]) then $release[0][.key] else .value end)
}) | from_entries
)
' composer.json > composer.tmp
mv composer.tmp composer.json

- name: Reformat composer.json
run: cat composer.json | unexpand -t2 | expand -t4 | sponge composer.json

- name: Preview composer.json
run: cat composer.json

- name: Add composer keys for private packagist
run: |
composer config http-basic.updates.ibexa.co $SATIS_NETWORK_KEY $SATIS_NETWORK_TOKEN
composer config github-oauth.github.com $APP_GITHUB_TOKEN
env:
SATIS_NETWORK_KEY: ${{ secrets.SATIS_NETWORK_KEY }}
SATIS_NETWORK_TOKEN: ${{ secrets.SATIS_NETWORK_TOKEN }}
APP_GITHUB_TOKEN: ${{ steps.generate_token.outputs.token }}

- name: Composer update
run: |
composer update --no-scripts --no-plugins --no-install
composer validate

- name: Commit, tag and push
if: inputs.real_op
env:
GIT_PUSH_ARGS: ${{ inputs.git_push_args }}
ROBOT_TOKEN: ${{ secrets.EZROBOT_PAT }}
run: |
git config --local user.email "681611+ezrobot@users.noreply.github.com"
git config --local user.name "ezrobot"
git remote set-url origin https://x-access-token:${{ env.ROBOT_TOKEN }}@github.com/${{ github.repository }}
git add composer.*
git commit -m "[composer] Set dependencies for ${{ inputs.version }} release + .lock"
git tag "v${{ inputs.version }}"
git push origin "v${{ inputs.version }}" ${GIT_PUSH_ARGS}
version: ${{ inputs.version }}
pin-packages: |
ibexa/headless-assets
ibexa/oss
real-op: ${{ inputs.real_op }}
git-push-args: ${{ inputs.git_push_args }}
gh-client-id: ${{ secrets.AUTOMATION_CLIENT_ID }}
gh-client-secret: ${{ secrets.AUTOMATION_CLIENT_SECRET }}
satis-network-key: ${{ secrets.SATIS_NETWORK_KEY }}
satis-network-token: ${{ secrets.SATIS_NETWORK_TOKEN }}