-
Notifications
You must be signed in to change notification settings - Fork 1
97 lines (91 loc) · 3.81 KB
/
Copy pathpublish-python.yml
File metadata and controls
97 lines (91 loc) · 3.81 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
# The Python SDK's release lane (§2.4 "`slates` on PyPI"; docs/publish.md). On a pushed tag
# `v<version>`: build the cp39-abi3 wheel of crates/sdk-python (one wheel per platform serves every
# CPython >= 3.9) for manylinux and musllinux (x86_64, aarch64), macOS (x86_64, arm64) and Windows
# (x64), plus the sdist, check every artifact's metadata, and publish to PyPI through TRUSTED
# PUBLISHING — OIDC from the `pypi` environment's id-token; no API token anywhere. PyPI registers a
# *pending* trusted publisher for a project that does not exist yet, so no maintainer upload ever
# happens (the one-time registration is in docs/publish.md). workflow_dispatch is a build-only dry run.
#
# The version is the workspace's: maturin reads it from the crate manifest (`dynamic = ["version"]`
# in pyproject.toml), and the shared guard refuses a tag that does not name it.
name: Publish Python SDK
on:
push:
tags: ["v*"]
workflow_dispatch:
env:
CARGO_TERM_COLOR: always
jobs:
guard:
uses: ./.github/workflows/version-guard.yml
wheels:
name: wheel ${{ matrix.name }}
needs: guard
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
include:
- { name: linux-x86_64, os: ubuntu-latest, target: x86_64, manylinux: auto }
# Native builds on the arm64 runners: an explicit target makes maturin demand a cross
# linker the manylinux/musllinux images lack (vorpal's finding, publish-python.yml).
- { name: linux-aarch64, os: ubuntu-24.04-arm, manylinux: auto }
- { name: musllinux-x86_64, os: ubuntu-latest, target: x86_64, manylinux: musllinux_1_2 }
- { name: musllinux-aarch64, os: ubuntu-24.04-arm, manylinux: musllinux_1_2 }
- { name: macos-x86_64, os: macos-latest, target: x86_64-apple-darwin }
- { name: macos-aarch64, os: macos-latest, target: aarch64-apple-darwin }
- { name: windows-x64, os: windows-latest, target: x64 }
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.11"
- uses: PyO3/maturin-action@v1
with:
rust-toolchain: 1.98.0 # keep in sync with rust-toolchain.toml
target: ${{ matrix.target || '' }}
manylinux: ${{ matrix.manylinux || 'auto' }}
args: --release --out dist -m crates/sdk-python/Cargo.toml
- uses: actions/upload-artifact@v4
with:
name: wheel-${{ matrix.name }}
path: dist
if-no-files-found: error
sdist:
name: sdist
needs: guard
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: PyO3/maturin-action@v1
with:
rust-toolchain: 1.98.0 # keep in sync with rust-toolchain.toml
command: sdist
args: --out dist -m crates/sdk-python/Cargo.toml
- uses: actions/upload-artifact@v4
with:
name: wheel-sdist
path: dist
if-no-files-found: error
publish:
name: Publish slates to PyPI (trusted publishing)
if: startsWith(github.ref, 'refs/tags/')
needs: [wheels, sdist]
runs-on: ubuntu-latest
environment: pypi
permissions:
id-token: write # OIDC: PyPI trusted publishing — no token
contents: read
steps:
- uses: actions/download-artifact@v4
with:
path: dist
merge-multiple: true
# The check PyPI applies to metadata and the README rendering, run before anything is uploaded
# so a refused artifact fails here with its reason, not halfway through an upload.
- name: Check every artifact's metadata
run: pipx run twine check --strict dist/*
- uses: pypa/gh-action-pypi-publish@release/v1
with:
packages-dir: dist
skip-existing: true # a re-run after a moved tag must not 400 on duplicates