Commit Graph
5 Commits
Author SHA1 Message Date
max-voitcov 381c928342 Give the SDK job the pulumi CLI it has always needed
build / build (push) Successful in 14m12s
The v0.2.0 plugin binaries published, then the SDK job died in tfgen:

    panic: fatal: error An assertion has failed: bulk converting examples
    failed. convertViaPulumiCLI: pulumi executable not in PATH

tfgen converts the upstream provider's documentation examples into each
language by shelling out to `pulumi convert`, and asserts rather than degrades
when the binary is missing. The build workflow installs the CLI; this job never
did. It went unnoticed through v0.1.0 because tfgen had no docs to convert
until UpstreamRepoPath pointed it at the upstream checkout.

So half a release is published and the other half is not, and re-pushing the
tag would rerun a 45 minute build against artifacts that are already uploaded.
Let a dispatch republish just the SDKs instead: it takes the tag to publish,
skips the plugin job, and checks the tree out at that tag while the workflow
file itself comes from the branch it was dispatched on.
2026-08-26 02:52:02 +03:00
max-voitcov 5e9b1ea663 Let a stranded release be re-run without moving the tag
build / build (push) Successful in 13m48s
release / plugin (push) Successful in 45m40s
release / sdks (push) Failing after 7m2s
The v0.2.0 release died twice on the runner -- once OOM-killed by six parallel
builds, once with the host going away mid-compile -- and each time the only way
back was to delete the tag and push it again. That is destructive, it rewrites
published history for a version that may already be half-published, and it is
easy to get wrong under pressure.

Add a workflow_dispatch trigger so the same release can simply be re-run.
goreleaser refuses to release from an untagged commit, so a dispatch can only
ever republish a real tag.

The sdks job derived VERSION from the ref name, which is the tag on a push but
the branch on a dispatch. It now asks git which tag the checked-out commit
carries, with --exact-match so an untagged commit fails loudly instead of
publishing under the previous version. That needs the tags, hence fetch-depth.
2026-08-26 01:52:53 +03:00
max-voitcov 5b106b406d Build the release one target at a time so it fits in memory
build / build (push) Has been cancelled
release / sdks (push) Has been cancelled
release / plugin (push) Has been cancelled
The v0.2.0 plugin release ran for 31 minutes and then died:

    build failed: exit status 1:
      github.com/pulumi/pulumi/sdk/v3/go/pulumi:
      compile: signal: killed
    target=darwin_amd64_v1

`signal: killed` is the OOM killer. A bridged provider links the entire
Terraform provider and the Pulumi SDK into a single ~100MB binary, and
goreleaser defaults its parallelism to the CPU count, so several of those
compiles were resident at once on a runner that could not hold them.

Serialise the builds and lower the compiler's GC target. Slower in wall-clock,
but it is the difference between a release that finishes and one that does
not.
2026-08-26 01:44:19 +03:00
usr_unknown ad3e908c98 Fix the upstream checkout and skip the dead cache server
build / build (push) Failing after 49s
Two separate CI failures:

- The cross-repo checkout of terraform-provider-dokploy asked the API
  for the default branch and got "not found", failing the build. An
  explicit ref: main skips the lookup entirely.
- setup-go caches by default, and this runner's cache server is
  unreachable from job containers, so restore and save each block until
  they time out. The same change cut the upstream provider's build from
  15m46s to 2m37s.
2026-08-09 14:00:20 +03:00
usr_unknown a44ebd4432 Resolve the plugin and SDKs from Gitea
build / build (push) Has been cancelled
release / plugin (push) Failing after 3m46s
release / sdks (push) Has been skipped
PluginDownloadURL moves off github:// to a templated Gitea release URL.
Pulumi interpolates ${VERSION}, then appends
pulumi-resource-dokploy-v<version>-<os>-<arch>.tar.gz -- which is what
the GoReleaser archive template already produces. Schema, bridge
metadata and all four SDKs regenerated to carry it.

Releases publish to this instance's npm, PyPI, NuGet and Go registries
using the GITEA_TOKEN that Gitea injects, so no secrets need
configuring.

The Go SDK keeps its github.com module path, which is exactly why it
goes to Gitea's Go registry: pointing GOPROXY there is what makes that
path resolve at all. Verified locally by serving the module zip from a
file proxy and building a consumer against it -- note zip -D, without
which go get rejects the archive's directory entries.
2026-08-09 12:37:19 +03:00