onionwire/.forgejo/workflows/release.yml

93 lines
3.6 KiB
YAML
Raw Normal View History

name: release
# Native aarch64 build on the Pi runner, published to the Forgejo release.
# x86_64 is NOT built here: there is no x86_64 runner on this instance — build
# it on an x86_64 host with scripts/build-release-local.sh (same release, same
# asset naming), or the release will carry aarch64 only.
on:
push:
tags:
- "v*.*.*"
workflow_dispatch:
inputs:
tag:
description: Existing tag to (re)build and publish
required: true
env:
CARGO_TERM_COLOR: never
TARGET: aarch64-unknown-linux-gnu
# Job steps run inside node:20-bullseye (the runner's docker label image) with
# the host docker socket mounted, so builds happen in a sibling rust container.
RUST_IMAGE: rust:1.87-bookworm
CARGO_REGISTRY_VOLUME: onionwire-cargo-registry
CARGO_TARGET_VOLUME: onionwire-target-aarch64
BUILD_CONTAINER: onionwire-release-build
jobs:
aarch64:
runs-on: docker
timeout-minutes: 120
steps:
- name: Checkout
uses: https://code.forgejo.org/actions/checkout@v4
with:
# A tag push builds that tag; a manual dispatch builds the tag the
# caller named (otherwise the binary version would not match the
# release it is attached to).
ref: ${{ github.event.inputs.tag || github.ref_name }}
- name: Build ${{ env.TARGET }} in a rust container
run: |
set -euo pipefail
docker volume create "$CARGO_REGISTRY_VOLUME" > /dev/null
docker volume create "$CARGO_TARGET_VOLUME" > /dev/null
docker rm -f "$BUILD_CONTAINER" > /dev/null 2>&1 || true
# The workspace lives in a per-task volume the host daemon cannot
# resolve, so pipe the source tree in over stdin (tar) and pull the
# binary back out with docker cp.
docker create --name "$BUILD_CONTAINER" -i \
-e CARGO_TARGET_DIR=/target \
-e CARGO_BUILD_JOBS=2 \
-e CARGO_TERM_COLOR=never \
-v "$CARGO_REGISTRY_VOLUME":/usr/local/cargo/registry \
-v "$CARGO_TARGET_VOLUME":/target \
-w /src \
"$RUST_IMAGE" \
sh -euxc 'mkdir -p /src && tar xzf - -C /src && cd /src \
&& apt-get update \
&& apt-get install -y --no-install-recommends pkg-config libssl-dev \
&& cargo build --release --locked \
&& strip /target/release/onionwire \
&& ls -l /target/release/onionwire'
tar czf - --exclude=./target --exclude=./.git --exclude=./.worktrees . \
| docker start -a -i "$BUILD_CONTAINER"
mkdir -p dist
docker cp "$BUILD_CONTAINER:/target/release/onionwire" "dist/onionwire-$TARGET"
docker rm -f "$BUILD_CONTAINER" > /dev/null
- name: Pack and checksum
run: |
set -euo pipefail
cd dist
file "onionwire-$TARGET"
sha256sum "onionwire-$TARGET" > "onionwire-$TARGET.sha256"
sha256sum -c "onionwire-$TARGET.sha256"
ls -l
- name: Publish to the Forgejo release
env:
FORGEJO_TOKEN: ${{ secrets.FORGEJO_TOKEN }}
TARGET_COMMITISH: ${{ github.sha }}
REPO_API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }}
REF: ${{ github.ref_name }}
INPUT_TAG: ${{ github.event.inputs.tag }}
run: |
set -euo pipefail
tag="${INPUT_TAG:-$REF}"
echo "publishing $tag from $REPO_API"
scripts/publish-release.sh \
"$tag" "OnionWire $tag" \
scripts/release-body.md \
"dist/onionwire-$TARGET" "dist/onionwire-$TARGET.sha256"