Rehome to project.uhhm.no: PKGBUILD URLs, ephemeral CI token, Arch registry publishing
- PKGBUILD url/source now point at this instance's releases. - Release uploads use the run's own ephemeral token instead of the GITEA_TOKEN secret. - The publish job also builds both architectures' packages (repack PKGBUILD, CARCH override) and uploads them to the instance Arch package registry (repository name: uhhm). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GLUwWE2KmFPzhKaf67tWbx
This commit is contained in:
co-authored by
Claude Fable 5
parent
1f47337c40
commit
903b8ccbb9
@@ -65,7 +65,7 @@ jobs:
|
||||
- name: Create release
|
||||
run: |
|
||||
curl -sX POST \
|
||||
-H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \
|
||||
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
|
||||
-H "Content-Type: application/json" \
|
||||
"${{ gitea.server_url }}/api/v1/repos/${{ gitea.repository }}/releases" \
|
||||
-d "{\"tag_name\":\"${{ gitea.ref_name }}\",\"name\":\"${{ gitea.ref_name }}\"}" \
|
||||
@@ -74,24 +74,24 @@ jobs:
|
||||
- name: Upload assets
|
||||
run: |
|
||||
RELEASE_ID=$(curl -s \
|
||||
-H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \
|
||||
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
|
||||
"${{ gitea.server_url }}/api/v1/repos/${{ gitea.repository }}/releases/tags/${{ gitea.ref_name }}" \
|
||||
| jq -r '.id')
|
||||
|
||||
for FILE in "${{ env.TARBALL }}" "${{ env.TARBALL }}.sha256"; do
|
||||
# Remove any existing asset with the same name so re-runs stay clean
|
||||
EXISTING=$(curl -s \
|
||||
-H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \
|
||||
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
|
||||
"${{ gitea.server_url }}/api/v1/repos/${{ gitea.repository }}/releases/${RELEASE_ID}/assets" \
|
||||
| jq -r ".[] | select(.name == \"${FILE}\") | .id")
|
||||
for AID in $EXISTING; do
|
||||
curl -sX DELETE \
|
||||
-H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \
|
||||
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
|
||||
"${{ gitea.server_url }}/api/v1/repos/${{ gitea.repository }}/releases/${RELEASE_ID}/assets/${AID}"
|
||||
done
|
||||
|
||||
curl -sX POST \
|
||||
-H "Authorization: token ${{ secrets.GITEA_TOKEN }}" \
|
||||
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
|
||||
-H "Content-Type: application/octet-stream" \
|
||||
"${{ gitea.server_url }}/api/v1/repos/${{ gitea.repository }}/releases/${RELEASE_ID}/assets?name=${FILE}" \
|
||||
--data-binary "@${FILE}" --fail-with-body
|
||||
@@ -132,6 +132,21 @@ jobs:
|
||||
sed -i "s/sha256sums_x86_64=('.*')/sha256sums_x86_64=('${SUM_X86}')/" aur/PKGBUILD
|
||||
sed -i "s/sha256sums_aarch64=('.*')/sha256sums_aarch64=('${SUM_AARCH}')/" aur/PKGBUILD
|
||||
|
||||
# Also publish the built packages to this instance's Arch registry
|
||||
# (docs.gitea.com/usage/packages/arch). The PKGBUILD only repacks the
|
||||
# release tarballs, so CARCH can produce both architectures from this
|
||||
# one host. Consumers: see the infrastructure README.
|
||||
- name: Publish to the Arch package registry
|
||||
run: |
|
||||
cd aur
|
||||
for carch in aarch64 x86_64; do
|
||||
rm -f ./*.pkg.tar.zst
|
||||
CARCH=$carch makepkg -f --nodeps
|
||||
curl --fail --user "${{ gitea.actor }}:${{ secrets.GITHUB_TOKEN }}" \
|
||||
--upload-file ./*-$carch.pkg.tar.zst \
|
||||
"${{ gitea.server_url }}/api/packages/${{ gitea.repository_owner }}/arch/uhhm"
|
||||
done
|
||||
|
||||
- name: Push to AUR
|
||||
env:
|
||||
AUR_SSH_KEY: ${{ secrets.AUR_SSH_KEY }}
|
||||
|
||||
Reference in New Issue
Block a user