ci: Automate patch releases and pre-releases
This work by automatically pushing a new tag on main and release branches after each commit. The tag will be "devel" on main and the version from postgrest.cabal for release branches. The release workflow then runs as a tag pipeline, making the actual release. For release branches, the tag will only be created if a tag for this version doesn't exist, yet. This means to actually make a new patch release, we still need to bump the version in postgrest.cabal. We can automate this later as part of our backport-bot. Resolves #2006 Resolves #2997
This commit is contained in:
committed by
Wolfgang Walther
parent
cdcab34852
commit
dd8d51ab71
@@ -101,8 +101,15 @@ runs:
|
|||||||
}
|
}
|
||||||
archive="$(mktemp)"
|
archive="$(mktemp)"
|
||||||
artifacts="$(mktemp -d)"
|
artifacts="$(mktemp -d)"
|
||||||
curl --no-progress-meter --fail -o "${archive}" \
|
until curl --no-progress-meter --fail -o "${archive}" \
|
||||||
"https://api.cirrus-ci.com/v1/artifact/task/$(get_external_id)/${{ inputs.download }}.zip"
|
"https://api.cirrus-ci.com/v1/artifact/task/$(get_external_id)/${{ inputs.download }}.zip"
|
||||||
|
do
|
||||||
|
# This happens when a tag is pushed on the same commit. In this case the
|
||||||
|
# job is immediately marked as "completed" for us, so we end up here after a few
|
||||||
|
# seconds - but the actual Cirrus CI task is still running and didn't produce its artifact, yet.
|
||||||
|
echo "Artifact not found on Cirrus CI, yet. Waiting..."
|
||||||
|
sleep 30
|
||||||
|
done
|
||||||
unzip "${archive}" -d "${artifacts}"
|
unzip "${archive}" -d "${artifacts}"
|
||||||
echo "artifacts=${artifacts}" >> "$GITHUB_OUTPUT"
|
echo "artifacts=${artifacts}" >> "$GITHUB_OUTPUT"
|
||||||
- name: Save artifact to GitHub Actions
|
- name: Save artifact to GitHub Actions
|
||||||
|
|||||||
@@ -15,7 +15,6 @@ DOCKER_USER="$3"
|
|||||||
DOCKER_PASS="$4"
|
DOCKER_PASS="$4"
|
||||||
SCRIPT_DIR="$5"
|
SCRIPT_DIR="$5"
|
||||||
PGRST_VERSION="v$6"
|
PGRST_VERSION="v$6"
|
||||||
IS_PRERELEASE="$7"
|
|
||||||
|
|
||||||
DOCKER_BUILD_DIR="$SCRIPT_DIR/docker-env"
|
DOCKER_BUILD_DIR="$SCRIPT_DIR/docker-env"
|
||||||
|
|
||||||
@@ -45,6 +44,6 @@ sudo docker buildx build --build-arg PGRST_GITHUB_COMMIT=$PGRST_GITHUB_COMMIT \
|
|||||||
# NOTE: This assumes that there already is a `postgrest:<version>` image
|
# NOTE: This assumes that there already is a `postgrest:<version>` image
|
||||||
# for the amd64 architecture pushed to Docker Hub
|
# for the amd64 architecture pushed to Docker Hub
|
||||||
sudo docker buildx imagetools create --append -t $DOCKER_REPO/postgrest:$PGRST_VERSION $DOCKER_REPO/postgrest:$PGRST_VERSION-arm
|
sudo docker buildx imagetools create --append -t $DOCKER_REPO/postgrest:$PGRST_VERSION $DOCKER_REPO/postgrest:$PGRST_VERSION-arm
|
||||||
[ -z $IS_PRERELEASE ] && sudo docker buildx imagetools create --append -t $DOCKER_REPO/postgrest:latest $DOCKER_REPO/postgrest:$PGRST_VERSION-arm
|
[ "$PGRST_VERSION" != "devel" ] && sudo docker buildx imagetools create --append -t $DOCKER_REPO/postgrest:latest $DOCKER_REPO/postgrest:$PGRST_VERSION-arm
|
||||||
|
|
||||||
sudo docker logout
|
sudo docker logout
|
||||||
|
|||||||
+70
-49
@@ -6,6 +6,7 @@ on:
|
|||||||
- main
|
- main
|
||||||
- v[0-9]+
|
- v[0-9]+
|
||||||
tags:
|
tags:
|
||||||
|
- devel
|
||||||
- v*
|
- v*
|
||||||
|
|
||||||
concurrency:
|
concurrency:
|
||||||
@@ -100,48 +101,68 @@ jobs:
|
|||||||
if-no-files-found: error
|
if-no-files-found: error
|
||||||
|
|
||||||
|
|
||||||
prepare:
|
tag:
|
||||||
name: Release / Prepare
|
name: Release / Tag
|
||||||
if: |
|
if: |
|
||||||
startsWith(github.ref, 'refs/tags/v') &&
|
startsWith(github.ref, 'refs/heads/') &&
|
||||||
(success() || needs.arm.result == 'skipped')
|
needs.docs.result == 'success' &&
|
||||||
|
needs.test.result == 'success' &&
|
||||||
|
needs.build.result == 'success' &&
|
||||||
|
(needs.arm.result == 'skipped' || success())
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
runs-on: ubuntu-22.04
|
runs-on: ubuntu-22.04
|
||||||
needs:
|
needs:
|
||||||
- docs
|
- docs
|
||||||
- test
|
- test
|
||||||
- build
|
- build
|
||||||
- arm
|
- arm
|
||||||
outputs:
|
|
||||||
version: ${{ steps.Identify-Version.outputs.version }}
|
|
||||||
isprerelease: ${{ steps.Identify-Version.outputs.isprerelease }}
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # v4.1.4
|
- uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # v4.1.4
|
||||||
- id: Identify-Version
|
with:
|
||||||
name: Identify the version to be released
|
ssh-key: ${{ secrets.POSTGREST_SSH_KEY }}
|
||||||
|
- name: Tag latest commit
|
||||||
run: |
|
run: |
|
||||||
tag_version="${GITHUB_REF##*/}"
|
|
||||||
cabal_version="$(grep -oP '^version:\s*\K.*' postgrest.cabal)"
|
cabal_version="$(grep -oP '^version:\s*\K.*' postgrest.cabal)"
|
||||||
|
|
||||||
if [ "$tag_version" != "v$cabal_version" ]; then
|
if [[ "$cabal_version" == *.*.* ]]; then
|
||||||
echo "Tagged version ($tag_version) does not match the one in postgrest.cabal (v$cabal_version). Aborting release..."
|
if [ -z "$(git tag --list "v$cabal_version")" ]; then
|
||||||
exit 1
|
git tag "v$cabal_version"
|
||||||
|
git push origin "v$cabal_version"
|
||||||
|
fi
|
||||||
else
|
else
|
||||||
echo "Version to be released is $cabal_version"
|
git tag -f "devel"
|
||||||
echo "version=$cabal_version" >> "$GITHUB_OUTPUT"
|
git push -f origin "devel"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ "$cabal_version" != *.*.*.* ]]; then
|
|
||||||
echo "Version is for a full release (version does not have four components)"
|
prepare:
|
||||||
else
|
name: Release / Prepare
|
||||||
echo "Version is for a pre-release (version has four components, e.g., 1.1.1.1)"
|
if: |
|
||||||
echo "isprerelease=1" >> "$GITHUB_OUTPUT"
|
startsWith(github.ref, 'refs/tags/') &&
|
||||||
|
needs.docs.result == 'success' &&
|
||||||
|
needs.test.result == 'success' &&
|
||||||
|
needs.build.result == 'success' &&
|
||||||
|
(needs.arm.result == 'skipped' || success())
|
||||||
|
runs-on: ubuntu-22.04
|
||||||
|
needs:
|
||||||
|
- docs
|
||||||
|
- test
|
||||||
|
- build
|
||||||
|
- arm
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
|
||||||
|
- name: Check the version to be released
|
||||||
|
run: |
|
||||||
|
cabal_version="$(grep -oP '^version:\s*\K.*' postgrest.cabal)"
|
||||||
|
|
||||||
|
if [ "${GITHUB_REF_NAME}" != "devel" ] && [ "${GITHUB_REF_NAME}" != "v$cabal_version" ]; then
|
||||||
|
echo "Tagged version ($GITHUB_REF_NAME) does not match the one in postgrest.cabal (v$cabal_version). Aborting release..."
|
||||||
|
exit 1
|
||||||
fi
|
fi
|
||||||
- name: Identify changes from CHANGELOG.md
|
- name: Identify changes from CHANGELOG.md
|
||||||
run: |
|
run: |
|
||||||
version="${{ steps.Identify-Version.outputs.version }}"
|
if [ "${GITHUB_REF_NAME}" == "devel" ]; then
|
||||||
isprerelease="${{ steps.Identify-Version.outputs.isprerelease }}"
|
|
||||||
|
|
||||||
if [ -n "$isprerelease" ]; then
|
|
||||||
echo "Getting unreleased changes..."
|
echo "Getting unreleased changes..."
|
||||||
sed -n "1,/## Unreleased/d;/## \[/q;p" CHANGELOG.md > CHANGES.md
|
sed -n "1,/## Unreleased/d;/## \[/q;p" CHANGELOG.md > CHANGES.md
|
||||||
else
|
else
|
||||||
@@ -164,9 +185,9 @@ jobs:
|
|||||||
permissions:
|
permissions:
|
||||||
contents: write
|
contents: write
|
||||||
runs-on: ubuntu-22.04
|
runs-on: ubuntu-22.04
|
||||||
needs: prepare
|
needs:
|
||||||
env:
|
- prepare
|
||||||
VERSION: ${{ needs.prepare.outputs.version }}
|
if: success() || needs.prepare.result == 'success'
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # v4.1.4
|
- uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # v4.1.4
|
||||||
- name: Download all artifacts
|
- name: Download all artifacts
|
||||||
@@ -179,19 +200,19 @@ jobs:
|
|||||||
|
|
||||||
mkdir -p release-bundle
|
mkdir -p release-bundle
|
||||||
|
|
||||||
tar cJvf "release-bundle/postgrest-v$VERSION-linux-static-x64.tar.xz" \
|
tar cJvf "release-bundle/postgrest-${GITHUB_REF_NAME}-linux-static-x64.tar.xz" \
|
||||||
-C artifacts/postgrest-linux-static-x64 postgrest
|
-C artifacts/postgrest-linux-static-x64 postgrest
|
||||||
|
|
||||||
tar cJvf "release-bundle/postgrest-v$VERSION-macos-x64.tar.xz" \
|
tar cJvf "release-bundle/postgrest-${GITHUB_REF_NAME}-macos-x64.tar.xz" \
|
||||||
-C artifacts/postgrest-macos-x64 postgrest
|
-C artifacts/postgrest-macos-x64 postgrest
|
||||||
|
|
||||||
tar cJvf "release-bundle/postgrest-v$VERSION-freebsd-x64.tar.xz" \
|
tar cJvf "release-bundle/postgrest-${GITHUB_REF_NAME}-freebsd-x64.tar.xz" \
|
||||||
-C artifacts/postgrest-freebsd-x64 postgrest
|
-C artifacts/postgrest-freebsd-x64 postgrest
|
||||||
|
|
||||||
tar cJvf "release-bundle/postgrest-v$VERSION-ubuntu-aarch64.tar.xz" \
|
tar cJvf "release-bundle/postgrest-${GITHUB_REF_NAME}-ubuntu-aarch64.tar.xz" \
|
||||||
-C artifacts/postgrest-ubuntu-aarch64 postgrest
|
-C artifacts/postgrest-ubuntu-aarch64 postgrest
|
||||||
|
|
||||||
zip "release-bundle/postgrest-v$VERSION-windows-x64.zip" \
|
zip "release-bundle/postgrest-${GITHUB_REF_NAME}-windows-x64.zip" \
|
||||||
artifacts/postgrest-windows-x64/postgrest.exe
|
artifacts/postgrest-windows-x64/postgrest.exe
|
||||||
|
|
||||||
- name: Save release bundle
|
- name: Save release bundle
|
||||||
@@ -205,11 +226,14 @@ jobs:
|
|||||||
env:
|
env:
|
||||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
run: |
|
run: |
|
||||||
isprerelease="${{ needs.prepare.outputs.isprerelease }}"
|
echo "Releasing version ${GITHUB_REF_NAME} on GitHub..."
|
||||||
echo "Releasing version v$VERSION on GitHub (isprerelease=$isprerelease)..."
|
|
||||||
|
|
||||||
gh release delete "v$VERSION" || true
|
if [ "${GITHUB_REF_NAME}" == "devel" ]; then
|
||||||
gh release create "v$VERSION" \
|
isprerelease=1
|
||||||
|
fi
|
||||||
|
|
||||||
|
gh release delete "${GITHUB_REF_NAME}" || true
|
||||||
|
gh release create "${GITHUB_REF_NAME}" \
|
||||||
-F artifacts/release-changes/CHANGES.md \
|
-F artifacts/release-changes/CHANGES.md \
|
||||||
${isprerelease:+"--prerelease"} \
|
${isprerelease:+"--prerelease"} \
|
||||||
release-bundle/*
|
release-bundle/*
|
||||||
@@ -220,13 +244,13 @@ jobs:
|
|||||||
runs-on: ubuntu-22.04
|
runs-on: ubuntu-22.04
|
||||||
needs:
|
needs:
|
||||||
- prepare
|
- prepare
|
||||||
|
if: |
|
||||||
|
vars.DOCKER_USER &&
|
||||||
|
(success() || needs.prepare.result == 'success')
|
||||||
env:
|
env:
|
||||||
GITHUB_COMMIT: ${{ github.sha }}
|
|
||||||
DOCKER_REPO: postgrest
|
DOCKER_REPO: postgrest
|
||||||
DOCKER_USER: stevechavez
|
DOCKER_USER: stevechavez
|
||||||
DOCKER_PASS: ${{ secrets.DOCKER_PASS }}
|
DOCKER_PASS: ${{ secrets.DOCKER_PASS }}
|
||||||
VERSION: ${{ needs.prepare.outputs.version }}
|
|
||||||
ISPRERELEASE: ${{ needs.prepare.outputs.isprerelease }}
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # v4.1.4
|
- uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # v4.1.4
|
||||||
- name: Setup Nix Environment
|
- name: Setup Nix Environment
|
||||||
@@ -243,16 +267,16 @@ jobs:
|
|||||||
docker login -u "$DOCKER_USER" -p "$DOCKER_PASS"
|
docker login -u "$DOCKER_USER" -p "$DOCKER_PASS"
|
||||||
docker load -i postgrest-docker.tar.gz
|
docker load -i postgrest-docker.tar.gz
|
||||||
|
|
||||||
docker tag postgrest:latest "$DOCKER_REPO/postgrest:v$VERSION"
|
docker tag postgrest:latest "$DOCKER_REPO/postgrest:${GITHUB_REF_NAME}"
|
||||||
docker push "$DOCKER_REPO/postgrest:v$VERSION"
|
docker push "$DOCKER_REPO/postgrest:${GITHUB_REF_NAME}"
|
||||||
|
|
||||||
# Only tag 'latest' for full releases
|
# Only tag 'latest' for full releases
|
||||||
if [[ -z "$ISPRERELEASE" ]]; then
|
if [ "${GITHUB_REF_NAME}" != "devel" ]; then
|
||||||
echo "Pushing to 'latest' tag for full release of v$VERSION ..."
|
echo "Pushing to 'latest' tag for full release of ${GITHUB_REF_NAME} ..."
|
||||||
docker tag postgrest:latest "$DOCKER_REPO"/postgrest:latest
|
docker tag postgrest:latest "$DOCKER_REPO"/postgrest:latest
|
||||||
docker push "$DOCKER_REPO"/postgrest:latest
|
docker push "$DOCKER_REPO"/postgrest:latest
|
||||||
else
|
else
|
||||||
echo "Skipping pushing to 'latest' tag for v$VERSION pre-release..."
|
echo "Skipping push to 'latest' tag for pre-release..."
|
||||||
fi
|
fi
|
||||||
# TODO: Enable dockerhub description update again, once a solution for the permission problem is found:
|
# TODO: Enable dockerhub description update again, once a solution for the permission problem is found:
|
||||||
# https://github.com/docker/hub-feedback/issues/1927
|
# https://github.com/docker/hub-feedback/issues/1927
|
||||||
@@ -273,15 +297,12 @@ jobs:
|
|||||||
runs-on: ubuntu-22.04
|
runs-on: ubuntu-22.04
|
||||||
needs:
|
needs:
|
||||||
- arm
|
- arm
|
||||||
- prepare
|
|
||||||
- docker
|
- docker
|
||||||
env:
|
env:
|
||||||
GITHUB_COMMIT: ${{ github.sha }}
|
GITHUB_COMMIT: ${{ github.sha }}
|
||||||
DOCKER_REPO: postgrest
|
DOCKER_REPO: postgrest
|
||||||
DOCKER_USER: stevechavez
|
DOCKER_USER: stevechavez
|
||||||
DOCKER_PASS: ${{ secrets.DOCKER_PASS }}
|
DOCKER_PASS: ${{ secrets.DOCKER_PASS }}
|
||||||
VERSION: ${{ needs.prepare.outputs.version }}
|
|
||||||
ISPRERELEASE: ${{ needs.prepare.outputs.isprerelease }}
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # v4.1.4
|
- uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b # v4.1.4
|
||||||
- name: Publish images for ARM builds on Docker Hub
|
- name: Publish images for ARM builds on Docker Hub
|
||||||
@@ -294,8 +315,8 @@ jobs:
|
|||||||
key: ${{ secrets.SSH_ARM_PRIVATE_KEY }}
|
key: ${{ secrets.SSH_ARM_PRIVATE_KEY }}
|
||||||
fingerprint: ${{ secrets.SSH_ARM_FINGERPRINT }}
|
fingerprint: ${{ secrets.SSH_ARM_FINGERPRINT }}
|
||||||
script_stop: true
|
script_stop: true
|
||||||
envs: GITHUB_COMMIT,DOCKER_REPO,DOCKER_USER,DOCKER_PASS,REMOTE_DIR,VERSION,ISPRERELEASE
|
envs: GITHUB_COMMIT,DOCKER_REPO,DOCKER_USER,DOCKER_PASS,REMOTE_DIR,GITHUB_REF_NAME
|
||||||
script: bash ~/$REMOTE_DIR/docker-publish.sh "$GITHUB_COMMIT" "$DOCKER_REPO" "$DOCKER_USER" "$DOCKER_PASS" "$REMOTE_DIR" "$VERSION" "$ISPRERELEASE"
|
script: bash ~/$REMOTE_DIR/docker-publish.sh "$GITHUB_COMMIT" "$DOCKER_REPO" "$DOCKER_USER" "$DOCKER_PASS" "$REMOTE_DIR" "$GITHUB_REF_NAME"
|
||||||
|
|
||||||
|
|
||||||
clean-arm:
|
clean-arm:
|
||||||
|
|||||||
Reference in New Issue
Block a user