-
Notifications
You must be signed in to change notification settings - Fork 0
128 lines (118 loc) · 4.08 KB
/
Copy pathrelease.yml
File metadata and controls
128 lines (118 loc) · 4.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
name: release
# Cut a release by pushing a semver tag (git tag v0.2.0 && git push --tags),
# or from the Actions UI (workflow_dispatch → version). Produces:
# - multi-arch image ghcr.io/<owner>/apd:<version> (+ x.y, latest, sha)
# - OCI Helm chart oci://ghcr.io/<owner>/charts/apd version <version>
# - a GitHub Release
on:
push:
tags: ["v*.*.*"]
workflow_dispatch:
inputs:
version:
description: "Release version, e.g. 0.2.0 (no leading v)"
required: true
permissions:
contents: write
packages: write
env:
REGISTRY: ghcr.io
jobs:
version:
runs-on: ubuntu-latest
outputs:
version: ${{ steps.v.outputs.version }}
steps:
- id: v
run: |
if [ "${{ github.event_name }}" = "workflow_dispatch" ]; then
V="${{ github.event.inputs.version }}"
else
V="${GITHUB_REF_NAME#v}"
fi
echo "version=$V" >> "$GITHUB_OUTPUT"
echo "Releasing version $V"
image:
needs: version
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: docker/setup-qemu-action@v3
- uses: docker/setup-buildx-action@v3
- uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ github.repository_owner }}/apd
tags: |
type=raw,value=${{ needs.version.outputs.version }}
type=semver,pattern={{major}}.{{minor}},value=${{ needs.version.outputs.version }}
type=raw,value=latest
type=sha,prefix=sha-
- uses: docker/build-push-action@v6
with:
context: .
platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
annotations: ${{ steps.meta.outputs.annotations }}
cache-from: type=gha
cache-to: type=gha,mode=max
provenance: mode=max
sbom: true
chart:
needs: version
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: azure/setup-helm@v4
with:
version: v3.16.2
- name: Package and push OCI chart
env:
V: ${{ needs.version.outputs.version }}
run: |
set -euo pipefail
OWNER=$(echo "${{ github.repository_owner }}" | tr '[:upper:]' '[:lower:]')
echo "${{ secrets.GITHUB_TOKEN }}" | helm registry login "$REGISTRY" \
--username "${{ github.actor }}" --password-stdin
helm package charts/apd --version "$V" --app-version "$V" -d dist
helm push "dist/apd-${V}.tgz" "oci://${REGISTRY}/${OWNER}/charts"
release:
needs: [version, image, chart]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Create GitHub Release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
V: ${{ needs.version.outputs.version }}
run: |
set -euo pipefail
OWNER=$(echo "${{ github.repository_owner }}" | tr '[:upper:]' '[:lower:]')
NOTES=$(cat <<EOF
apd v${V} — AAuth Agent Provider (demo mode; AAuth is an IETF draft).
### Container image (multi-arch: amd64, arm64)
\`\`\`
docker pull ghcr.io/${OWNER}/apd:${V}
\`\`\`
### Helm chart (OCI)
\`\`\`
helm install apd oci://ghcr.io/${OWNER}/charts/apd --version ${V} \\
--set issuer=https://ap.example.com --set keys.existingSecret=apd-keys
\`\`\`
See https://agentprovider.dev/docs/deployment.html
EOF
)
TAG="v${V}"
if ! git rev-parse "$TAG" >/dev/null 2>&1; then
gh release create "$TAG" --title "apd v${V}" --notes "$NOTES" --target "$GITHUB_SHA"
else
gh release create "$TAG" --title "apd v${V}" --notes "$NOTES" || \
gh release edit "$TAG" --notes "$NOTES"
fi