-
Notifications
You must be signed in to change notification settings - Fork 358
197 lines (190 loc) · 7.36 KB
/
Copy pathcli-release.yml
File metadata and controls
197 lines (190 loc) · 7.36 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
name: cli-release
# Releases the Devbox CLI
concurrency: cli-release
on:
# Build/Release on demand
workflow_dispatch:
inputs:
create_edge_release:
description: "Create edge release?"
required: false
default: false
type: boolean
schedule:
- cron: "45 8 * * 4" # Create edge weekly on Thursdays.
push:
tags:
- "*" # Tags that trigger a new release version
permissions:
contents: write
pull-requests: read
id-token: write # Needed for aws-actions/configure-aws-credentials@v6
jobs:
tests:
uses: ./.github/workflows/cli-tests.yaml
report-test-failures:
runs-on: ubuntu-latest
needs: tests
if: failure() || cancelled()
steps:
- name: Notify jetpack.io slack of release status (only if tests fail)
id: slack
uses: slackapi/slack-github-action@v3.0.3
with:
# v2+ moved the webhook URL from the SLACK_WEBHOOK_URL env var to the
# `webhook` input and made `webhook-type` required.
webhook: ${{ secrets.SLACK_CLI_RELEASE_WEBHOOK_URL }}
webhook-type: incoming-webhook
payload: |
{
"status": "test ${{ needs.tests.result }}"
}
edge:
runs-on: ubuntu-latest
environment: release
needs: tests
if: ${{ inputs.create_edge_release || github.event.schedule }}
steps:
- name: Checkout source code
uses: actions/checkout@v7
with:
fetch-depth: 0 # Needed by goreleaser to browse history.
- name: Determine edge tag
# This tag is semver and works with semver.Compare
run: echo "EDGE_TAG=0.0.0-edge.$(date +%Y-%m-%d)" >> $GITHUB_ENV
- name: Set edge tag
# Force so a same-day rerun (the edge tag already exists) is idempotent.
run: |
git tag -f "$EDGE_TAG"
git push -f origin "refs/tags/$EDGE_TAG"
- name: Set up go
uses: actions/setup-go@v6
with:
go-version-file: ./go.mod
- name: Build snapshot with goreleaser
uses: goreleaser/goreleaser-action@v7
with:
distribution: goreleaser
version: latest
args: release --clean --skip=announce,publish --snapshot
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TELEMETRY_KEY: ${{ secrets.TELEMETRY_KEY }}
SENTRY_DSN: ${{ secrets.SENTRY_DSN }}
- name: Create Sentry release
uses: getsentry/action-release@v1
env:
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
SENTRY_ORG: ${{ vars.SENTRY_ORG }}
SENTRY_PROJECT: ${{ vars.SENTRY_PROJECT }}
with:
environment: development
version: ${{ env.EDGE_TAG }}
version_prefix: "devbox@"
- name: Publish snapshot release to GitHub
uses: softprops/action-gh-release@v3
with:
prerelease: true
body: "${{ env.EDGE_TAG }} edge release"
fail_on_unmatched_files: true
tag_name: ${{ env.EDGE_TAG }}
files: |
dist/checksums.txt
dist/*.tar.gz
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: ${{ secrets.AWS_ROLE }}
aws-region: us-west-2
- name: Update edge version in s3
run: |
tmp_file=$(mktemp)
echo "${{ env.EDGE_TAG }}" > $tmp_file
aws s3 cp $tmp_file s3://releases.jetpack.io/devbox/edge/version
release:
runs-on: ubuntu-latest
environment: release
needs: tests
# Only release when there's a tag for the release.
if: startsWith(github.ref, 'refs/tags/')
steps:
- name: Checkout source code
uses: actions/checkout@v7
with:
fetch-depth: 0 # Needed by goreleaser to browse history.
- name: Set up go
uses: actions/setup-go@v6
with:
go-version-file: ./go.mod
- name: Create Sentry release
uses: getsentry/action-release@v1
env:
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
SENTRY_ORG: ${{ vars.SENTRY_ORG }}
SENTRY_PROJECT: ${{ vars.SENTRY_PROJECT }}
with:
environment: production
# ref_name, not ref: `github.ref` is the full `refs/tags/0.17.5`, which
# produced Sentry releases named `devbox@refs/tags/0.17.5` that don't
# match the version the binary reports.
version: ${{ github.ref_name }}
version_prefix: "devbox@"
- name: Build with goreleaser
uses: goreleaser/goreleaser-action@v7
with:
distribution: goreleaser
version: latest
args: release --clean
env:
DISCORD_WEBHOOK_ID: ${{ secrets.DISCORD_WEBHOOK_ID }}
DISCORD_WEBHOOK_TOKEN: ${{ secrets.DISCORD_WEBHOOK_TOKEN }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TELEMETRY_KEY: ${{ secrets.TELEMETRY_KEY }}
SENTRY_DSN: ${{ secrets.SENTRY_DSN }}
# `release.disable` is set in .goreleaser.yaml, so goreleaser only builds
# dist/ — the GitHub release belongs to this step. Both ways of cutting a
# release land here and both work:
#
# * `devbox run draft-release` created the draft, with its real title and
# hand-written notes, before pushing the tag. We upload onto it.
# * the tag was pushed by hand with no draft. We create one, titled after
# the tag with GitHub's generated notes, and upload onto that. It stays
# a draft for a human to retitle, rewrite and publish.
#
# Either way the release is looked up by tag, so a tag always resolves to
# exactly one release. goreleaser used to do this itself, but it matched
# existing drafts by *title*, so any release with a real title went
# unmatched and got a silent duplicate. See .goreleaser.yaml.
- name: Attach artifacts to the release for this tag
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TAG: ${{ github.ref_name }}
run: |
if gh release view "$TAG" --repo "$GITHUB_REPOSITORY" >/dev/null 2>&1; then
echo "Release for $TAG already exists — attaching artifacts to it."
else
echo "No release for $TAG (tag pushed outside draft-release?) —" \
"creating a draft for it."
# Same rule as release.ts: a semver prerelease is anything with a "-".
prerelease=()
case "$TAG" in *-*) prerelease=(--prerelease) ;; esac
gh release create "$TAG" --repo "$GITHUB_REPOSITORY" --draft \
--title "$TAG" --generate-notes "${prerelease[@]}"
fi
# --clobber so a re-run of this workflow replaces the assets instead of
# failing on the ones already uploaded.
gh release upload "$TAG" dist/*.tar.gz dist/checksums.txt \
--repo "$GITHUB_REPOSITORY" --clobber
- name: Notify jetpack.io slack of release status
id: slack
if: always()
uses: slackapi/slack-github-action@v3.0.3
with:
# v2+ moved the webhook URL from the SLACK_WEBHOOK_URL env var to the
# `webhook` input and made `webhook-type` required.
webhook: ${{ secrets.SLACK_CLI_RELEASE_WEBHOOK_URL }}
webhook-type: incoming-webhook
payload: |
{
"status": "release ${{ job.status }}"
}