Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3dc5ebbbb9 | ||
|
|
a0acdd1c82 | ||
|
|
9a2d4675cf | ||
|
|
398dc2cfb4 | ||
|
|
9c3b595b7e | ||
|
|
4638686939 | ||
|
|
cc01a956ad | ||
|
|
381c928342 |
@@ -3,12 +3,17 @@ name: release
|
|||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
tags: ["v*.*.*"]
|
tags: ["v*.*.*"]
|
||||||
# A release that dies halfway -- the runner OOMs, the host reboots -- leaves
|
# A release that dies halfway -- the runner OOMs, the host reboots, a job is
|
||||||
# the tag pushed and nothing published, and re-pushing a tag to retry it is
|
# missing a tool -- leaves the tag pushed and only part of the release
|
||||||
# both awkward and destructive. Dispatch re-runs the same release instead.
|
# published, and re-pushing a tag to retry it is both awkward and
|
||||||
# goreleaser refuses to run unless the checked-out commit is itself tagged,
|
# destructive. Dispatch republishes the SDKs for a tag that already has its
|
||||||
# so this can only ever republish a real tag, never main-in-progress.
|
# plugin binaries, which is the half that fails: the plugin job is a 45
|
||||||
workflow_dispatch: {}
|
# minute build that either produced its artifacts or did not.
|
||||||
|
workflow_dispatch:
|
||||||
|
inputs:
|
||||||
|
tag:
|
||||||
|
description: Tag to publish the SDKs for, e.g. v0.2.0
|
||||||
|
required: true
|
||||||
|
|
||||||
env:
|
env:
|
||||||
GO_VERSION: "1.25.x"
|
GO_VERSION: "1.25.x"
|
||||||
@@ -17,16 +22,28 @@ env:
|
|||||||
DOTNET_VERSION: "8.0.x"
|
DOTNET_VERSION: "8.0.x"
|
||||||
UPSTREAM_REPO: usr_unknown/terraform-provider-dokploy
|
UPSTREAM_REPO: usr_unknown/terraform-provider-dokploy
|
||||||
UPSTREAM_DIR: dokploy-teraform
|
UPSTREAM_DIR: dokploy-teraform
|
||||||
# Everything below authenticates with the token Gitea injects into every
|
# Cloning and the release itself authenticate with the token Gitea injects
|
||||||
# run, so releasing needs no configured secrets at all.
|
# into every run. Publishing packages does not -- see PACKAGES_TOKEN below.
|
||||||
GITEA_HOST: gitea.coolify.vojtkov.dev
|
GITEA_HOST: gitea.coolify.vojtkov.dev
|
||||||
GITEA_OWNER: usr_unknown
|
GITEA_OWNER: usr_unknown
|
||||||
|
|
||||||
|
# Publishing to the package registries needs its own token. The one Actions
|
||||||
|
# injects authenticates fine -- it reads the registry and the API as the repo
|
||||||
|
# owner -- but every write comes back 401, under Bearer and Basic alike, and
|
||||||
|
# `permissions: packages: write` does not change that. So PACKAGES_TOKEN is a
|
||||||
|
# repository secret holding an access token with the `write:package` scope.
|
||||||
|
# Everything else here still uses the injected token.
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
# The plugin binaries. Pulumi resolves them from this release via the
|
# The plugin binaries. Pulumi resolves them from this release via the
|
||||||
# PluginDownloadURL baked into the schema, so this has to land before anyone
|
# PluginDownloadURL baked into the schema, so this has to land before anyone
|
||||||
# installs an SDK.
|
# installs an SDK.
|
||||||
plugin:
|
plugin:
|
||||||
|
# Only on a tag push. A dispatch is for republishing SDKs against a tag
|
||||||
|
# whose binaries are already uploaded, and goreleaser would collide with
|
||||||
|
# them. To rebuild the binaries themselves, delete the release and
|
||||||
|
# re-push the tag.
|
||||||
|
if: github.event_name == 'push'
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
@@ -62,16 +79,24 @@ jobs:
|
|||||||
args: release --clean --parallelism 1
|
args: release --clean --parallelism 1
|
||||||
workdir: pulumi-dokploy
|
workdir: pulumi-dokploy
|
||||||
env:
|
env:
|
||||||
|
# goreleaser creates the release and uploads binaries: repository
|
||||||
|
# write, which the injected token already has. Not a package write.
|
||||||
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||||
GOGC: "50"
|
GOGC: "50"
|
||||||
|
|
||||||
sdks:
|
sdks:
|
||||||
needs: plugin
|
needs: plugin
|
||||||
|
# `always()` so a dispatch, where plugin is skipped rather than run, still
|
||||||
|
# gets here -- but not past a plugin job that actually failed.
|
||||||
|
if: always() && needs.plugin.result != 'failure' && needs.plugin.result != 'cancelled'
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
path: pulumi-dokploy
|
path: pulumi-dokploy
|
||||||
|
# The workflow file comes from the dispatched branch; the tree to
|
||||||
|
# publish comes from the tag. On a push the two are the same thing.
|
||||||
|
ref: ${{ inputs.tag || github.ref }}
|
||||||
# Needed for the tag lookup below.
|
# Needed for the tag lookup below.
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
|
|
||||||
@@ -100,6 +125,13 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
dotnet-version: ${{ env.DOTNET_VERSION }}
|
dotnet-version: ${{ env.DOTNET_VERSION }}
|
||||||
|
|
||||||
|
# tfgen converts the upstream provider's documentation examples into
|
||||||
|
# each language by shelling out to `pulumi convert`, and asserts rather
|
||||||
|
# than degrades when the binary is absent: "pulumi executable not in
|
||||||
|
# PATH". It only started mattering once UpstreamRepoPath gave tfgen
|
||||||
|
# docs to find, which is why v0.1.0 published without this.
|
||||||
|
- uses: pulumi/actions@v6
|
||||||
|
|
||||||
# On a tag push the ref name is the tag; on a dispatch it is the branch,
|
# On a tag push the ref name is the tag; on a dispatch it is the branch,
|
||||||
# so ask git what tag this commit carries. --exact-match keeps a dispatch
|
# so ask git what tag this commit carries. --exact-match keeps a dispatch
|
||||||
# from quietly publishing an untagged commit under the previous version.
|
# from quietly publishing an untagged commit under the previous version.
|
||||||
@@ -116,32 +148,56 @@ jobs:
|
|||||||
- name: Publish to the Gitea npm registry
|
- name: Publish to the Gitea npm registry
|
||||||
working-directory: pulumi-dokploy/sdk/nodejs/bin
|
working-directory: pulumi-dokploy/sdk/nodejs/bin
|
||||||
env:
|
env:
|
||||||
TOKEN: ${{ secrets.GITEA_TOKEN }}
|
TOKEN: ${{ secrets.PACKAGES_TOKEN }}
|
||||||
run: |
|
run: |
|
||||||
cat > .npmrc <<EOF
|
cat > .npmrc <<EOF
|
||||||
@maxvojtkov:registry=https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/
|
@maxvojtkov:registry=https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/
|
||||||
//${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/:_authToken=${TOKEN}
|
//${GITEA_HOST}/api/packages/${GITEA_OWNER}/npm/:_authToken=${TOKEN}
|
||||||
EOF
|
EOF
|
||||||
npm publish
|
# A re-run of a half-finished release must get past the registries
|
||||||
|
# that already have this version -- Gitea answers a repeat publish
|
||||||
|
# with 409 and npm treats that as fatal.
|
||||||
|
if npm view "@maxvojtkov/pulumi-dokploy@${VERSION}" version >/dev/null 2>&1; then
|
||||||
|
echo "@maxvojtkov/pulumi-dokploy@${VERSION} is already published"
|
||||||
|
else
|
||||||
|
npm publish
|
||||||
|
fi
|
||||||
|
|
||||||
- name: Publish to the Gitea PyPI registry
|
- name: Publish to the Gitea PyPI registry
|
||||||
working-directory: pulumi-dokploy/sdk/python
|
working-directory: pulumi-dokploy/sdk/python
|
||||||
env:
|
env:
|
||||||
TWINE_USERNAME: ${{ env.GITEA_OWNER }}
|
TWINE_USERNAME: ${{ env.GITEA_OWNER }}
|
||||||
TWINE_PASSWORD: ${{ secrets.GITEA_TOKEN }}
|
TWINE_PASSWORD: ${{ secrets.PACKAGES_TOKEN }}
|
||||||
run: |
|
run: |
|
||||||
python -m pip install --upgrade build twine
|
python -m pip install --upgrade build twine
|
||||||
python -m build
|
python -m build
|
||||||
python -m twine upload \
|
# twine's --skip-existing is refused outright here: it asks the
|
||||||
--repository-url "https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/pypi" \
|
# repository whether it supports the feature and Gitea's PyPI
|
||||||
dist/*
|
# registry does not advertise it ("UnsupportedConfiguration"). Ask
|
||||||
|
# the simple index instead, the same check-then-publish shape the
|
||||||
|
# npm step uses.
|
||||||
|
INDEX="https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/pypi/simple/pulumi-dokploy/"
|
||||||
|
if curl -sf --user "${GITEA_OWNER}:${TWINE_PASSWORD}" "$INDEX" \
|
||||||
|
| grep -qE "pulumi_dokploy-${VERSION}[-.]"; then
|
||||||
|
echo "pulumi-dokploy ${VERSION} is already published"
|
||||||
|
else
|
||||||
|
python -m twine upload \
|
||||||
|
--repository-url "https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/pypi" \
|
||||||
|
dist/*
|
||||||
|
fi
|
||||||
|
|
||||||
- name: Publish to the Gitea NuGet registry
|
- name: Publish to the Gitea NuGet registry
|
||||||
working-directory: pulumi-dokploy/sdk/dotnet
|
working-directory: pulumi-dokploy/sdk/dotnet
|
||||||
env:
|
env:
|
||||||
TOKEN: ${{ secrets.GITEA_TOKEN }}
|
TOKEN: ${{ secrets.PACKAGES_TOKEN }}
|
||||||
run: |
|
run: |
|
||||||
dotnet pack --configuration Release --output ./nupkg
|
# The generated csproj sets GeneratePackageOnBuild, and `dotnet pack`
|
||||||
|
# on such a project skips compiling -- it assumes the build already
|
||||||
|
# packed -- then fails with NU5026 because the assembly it wants to
|
||||||
|
# pack was never produced. Turn the property off for this invocation
|
||||||
|
# and pack builds the project itself, as it normally would.
|
||||||
|
dotnet pack --configuration Release --output ./nupkg \
|
||||||
|
-p:GeneratePackageOnBuild=false
|
||||||
dotnet nuget push ./nupkg/*.nupkg \
|
dotnet nuget push ./nupkg/*.nupkg \
|
||||||
--source "https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/nuget/index.json" \
|
--source "https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/nuget/index.json" \
|
||||||
--api-key "$TOKEN" --skip-duplicate
|
--api-key "$TOKEN" --skip-duplicate
|
||||||
@@ -156,7 +212,7 @@ jobs:
|
|||||||
- name: Publish the Go SDK to the Gitea Go registry
|
- name: Publish the Go SDK to the Gitea Go registry
|
||||||
working-directory: pulumi-dokploy
|
working-directory: pulumi-dokploy
|
||||||
env:
|
env:
|
||||||
TOKEN: ${{ secrets.GITEA_TOKEN }}
|
TOKEN: ${{ secrets.PACKAGES_TOKEN }}
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
MODULE=github.com/maxvojtkov/pulumi-dokploy/sdk
|
MODULE=github.com/maxvojtkov/pulumi-dokploy/sdk
|
||||||
@@ -166,8 +222,14 @@ jobs:
|
|||||||
cp sdk/go.mod sdk/go.sum "$DEST/"
|
cp sdk/go.mod sdk/go.sum "$DEST/"
|
||||||
cp -R sdk/go "$DEST/"
|
cp -R sdk/go "$DEST/"
|
||||||
(cd "$STAGE" && zip -qrD "$STAGE/sdk.zip" . -x 'sdk.zip')
|
(cd "$STAGE" && zip -qrD "$STAGE/sdk.zip" . -x 'sdk.zip')
|
||||||
curl -fsSL -X PUT \
|
# 409 means this version is already in the registry, which is the
|
||||||
|
# expected answer when a partly finished release is re-run.
|
||||||
|
CODE="$(curl -sS -o /dev/null -w '%{http_code}' -X PUT \
|
||||||
--user "${GITEA_OWNER}:${TOKEN}" \
|
--user "${GITEA_OWNER}:${TOKEN}" \
|
||||||
--upload-file "$STAGE/sdk.zip" \
|
--upload-file "$STAGE/sdk.zip" \
|
||||||
"https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/go/upload"
|
"https://${GITEA_HOST}/api/packages/${GITEA_OWNER}/go/upload")"
|
||||||
echo "Published $MODULE@v${VERSION}"
|
case "$CODE" in
|
||||||
|
201) echo "Published $MODULE@v${VERSION}" ;;
|
||||||
|
409) echo "$MODULE@v${VERSION} is already published" ;;
|
||||||
|
*) echo "Go registry upload failed with HTTP $CODE"; exit 1 ;;
|
||||||
|
esac
|
||||||
|
|||||||
Reference in New Issue
Block a user