Files
Bendik Aagaard LynghaugandClaude Opus 4.8 c1c337c2a2 ci: no toolchain installs on the bare aarch64 (klokka) runner; builtin:checkout
The aarch64 release leg runs on the klokka host. Gate the sccache /
cargo-binstall / cargo-leptos installs to the ephemeral x86_64 container; on
the bare runner check-and-fail instead (the sccache tarball was x86_64-only
anyway, so it was both a host mutation and a wrong-arch binary). Switch
checkout to v4 builtin:checkout (native Go, no Node/download) in all jobs.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 12:37:04 +02:00

206 lines
8.3 KiB
YAML

name: Release
on:
push:
tags:
- 'v*'
env:
CARGO_TERM_COLOR: always
jobs:
build:
strategy:
matrix:
include:
- arch: x86_64
runs-on: ubuntu-latest
sccache_dir: /sccache
- arch: aarch64
runs-on: aarch64
sccache_dir: /var/lib/gitea-runner/sccache
runs-on: ${{ matrix.runs-on }}
steps:
- uses: builtin:checkout
- name: Install Rust stable
uses: dtolnay/rust-toolchain@stable
with:
targets: wasm32-unknown-unknown
# Compiled-crate cache via sccache. x86_64 uses /sccache (a persistent
# host dir bind-mounted into the job container by the runner config);
# aarch64 runs on the klokka host and uses a runner-owned dir. Both
# persist across releases, unlike the (unreachable) Gitea cache service.
- name: Set up sccache
run: |
echo "RUSTC_WRAPPER=sccache" >> "$GITHUB_ENV"
echo "SCCACHE_DIR=${{ matrix.sccache_dir }}" >> "$GITHUB_ENV"
mkdir -p "${{ matrix.sccache_dir }}"
if command -v sccache >/dev/null 2>&1; then sccache --version; exit 0; fi
# Bare runners (aarch64 = klokka host) are pre-provisioned; CI must not
# install onto them (and this tarball is x86_64-only). Only the
# ephemeral x86_64 container installs; a bare host missing it fails loud.
if [ "${{ matrix.arch }}" != x86_64 ]; then
echo "::error::sccache missing on the bare ${{ matrix.arch }} runner — provision klokka; CI must not install on bare hosts"; exit 1
fi
V=0.8.2
curl -sSL "https://github.com/mozilla/sccache/releases/download/v${V}/sccache-v${V}-x86_64-unknown-linux-musl.tar.gz" | tar -xz
sudo install -m0755 "sccache-v${V}-x86_64-unknown-linux-musl/sccache" /usr/local/bin/sccache
sccache --version
- name: Install cargo-binstall
run: |
if command -v cargo-binstall >/dev/null 2>&1; then exit 0; fi
if [ "${{ matrix.arch }}" != x86_64 ]; then
echo "::error::cargo-binstall missing on the bare ${{ matrix.arch }} runner — provision klokka"; exit 1
fi
curl -L --proto '=https' --tlsv1.2 -sSf \
https://raw.githubusercontent.com/cargo-bins/cargo-binstall/main/install-from-binstall-release.sh \
| bash
- name: Install cargo-leptos
run: |
if command -v cargo-leptos >/dev/null 2>&1; then exit 0; fi
if [ "${{ matrix.arch }}" != x86_64 ]; then
echo "::error::cargo-leptos missing on the bare ${{ matrix.arch }} runner — provision klokka"; exit 1
fi
cargo binstall cargo-leptos --locked --no-confirm
- name: Build
run: cargo leptos build --release
- name: Package
run: |
TAG=${{ gitea.ref_name }}
TARBALL="cnats-${TAG}-${{ matrix.arch }}.tar.gz"
mkdir pkg
cp target/release/cnats pkg/
cp -r target/site pkg/site
cp packaging/cnats.service packaging/cnats.env pkg/
cp LICENSE README.md pkg/
tar -czf "${TARBALL}" -C pkg .
sha256sum "${TARBALL}" > "${TARBALL}.sha256"
echo "TARBALL=${TARBALL}" >> $GITHUB_ENV
- name: Create release
run: |
curl -sX POST \
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
-H "Content-Type: application/json" \
"${{ gitea.server_url }}/api/v1/repos/${{ gitea.repository }}/releases" \
-d "{\"tag_name\":\"${{ gitea.ref_name }}\",\"name\":\"${{ gitea.ref_name }}\"}" \
--fail-with-body || true
- name: Upload assets
run: |
RELEASE_ID=$(curl -s \
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
"${{ gitea.server_url }}/api/v1/repos/${{ gitea.repository }}/releases/tags/${{ gitea.ref_name }}" \
| jq -r '.id')
for FILE in "${{ env.TARBALL }}" "${{ env.TARBALL }}.sha256"; do
# Remove any existing asset with the same name so re-runs stay clean
EXISTING=$(curl -s \
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
"${{ gitea.server_url }}/api/v1/repos/${{ gitea.repository }}/releases/${RELEASE_ID}/assets" \
| jq -r ".[] | select(.name == \"${FILE}\") | .id")
for AID in $EXISTING; do
curl -sX DELETE \
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
"${{ gitea.server_url }}/api/v1/repos/${{ gitea.repository }}/releases/${RELEASE_ID}/assets/${AID}"
done
curl -sX POST \
-H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
-H "Content-Type: application/octet-stream" \
"${{ gitea.server_url }}/api/v1/repos/${{ gitea.repository }}/releases/${RELEASE_ID}/assets?name=${FILE}" \
--data-binary "@${FILE}" --fail-with-body
done
docker:
runs-on: ubuntu-latest
steps:
- uses: builtin:checkout
- name: Log in to Docker Hub
run: echo "${{ secrets.DOCKERHUB_TOKEN }}" | docker login -u bendik --password-stdin
- name: Build and push
run: |
TAG=${{ gitea.ref_name }}
docker build -t "bendik/cnats:${TAG#v}" -t bendik/cnats:latest .
docker push "bendik/cnats:${TAG#v}"
docker push bendik/cnats:latest
update-aur:
needs: build
runs-on: aarch64
steps:
- uses: builtin:checkout
- name: Compute checksums and update PKGBUILD
run: |
TAG=${{ gitea.ref_name }}
BASE="${{ gitea.server_url }}/${{ gitea.repository }}/releases/download/${TAG}"
SUM_X86=$(curl -sL "${BASE}/cnats-${TAG}-x86_64.tar.gz" | sha256sum | cut -d' ' -f1)
SUM_AARCH=$(curl -sL "${BASE}/cnats-${TAG}-aarch64.tar.gz" | sha256sum | cut -d' ' -f1)
sed -i "s/^pkgver=.*/pkgver=${TAG#v}/" aur/PKGBUILD
sed -i "s/sha256sums_x86_64=('.*')/sha256sums_x86_64=('${SUM_X86}')/" aur/PKGBUILD
sed -i "s/sha256sums_aarch64=('.*')/sha256sums_aarch64=('${SUM_AARCH}')/" aur/PKGBUILD
# Also publish the built packages to this instance's Arch registry
# (docs.gitea.com/usage/packages/arch). The PKGBUILD only repacks the
# release tarballs, so CARCH can produce both architectures from this
# one host. Consumers: see the infrastructure README.
# Best-effort mirror to the instance Arch registry. The ephemeral
# GITHUB_TOKEN is not accepted as a package-write credential, so this
# uses a dedicated REGISTRY_TOKEN secret (a write:package token for bl);
# if it is unset the step is skipped, and continue-on-error keeps a
# registry hiccup from failing the release or the AUR push.
- name: Publish to the Arch package registry
continue-on-error: true
run: |
set -euo pipefail
if [ -z "${{ secrets.REGISTRY_TOKEN }}" ]; then
echo "::warning::REGISTRY_TOKEN not set — skipping Arch registry publish"
exit 0
fi
cd aur
for carch in aarch64 x86_64; do
pkgfile=$(CARCH="$carch" makepkg --packagelist | tail -1)
CARCH="$carch" makepkg -f --nodeps --noconfirm --skipinteg
curl --fail-with-body --user "bl:${{ secrets.REGISTRY_TOKEN }}" \
--upload-file "$pkgfile" \
"${{ gitea.server_url }}/api/packages/${{ gitea.repository_owner }}/arch/uhhm"
done
- name: Push to AUR
env:
AUR_SSH_KEY: ${{ secrets.AUR_SSH_KEY }}
run: |
install -dm700 ~/.ssh
echo "$AUR_SSH_KEY" > ~/.ssh/aur
chmod 600 ~/.ssh/aur
echo "Host aur.archlinux.org" >> ~/.ssh/config
echo " IdentityFile ~/.ssh/aur" >> ~/.ssh/config
echo " User aur" >> ~/.ssh/config
ssh-keyscan aur.archlinux.org >> ~/.ssh/known_hosts 2>/dev/null
rm -rf /tmp/aur-cnats
git clone ssh://aur@aur.archlinux.org/cnats.git /tmp/aur-cnats
cp aur/PKGBUILD /tmp/aur-cnats/
cd /tmp/aur-cnats
makepkg --printsrcinfo > .SRCINFO
git config user.name "Bendik Aagaard Lynghaug"
git config user.email "bendik.lynghaug@gmail.com"
git add PKGBUILD .SRCINFO
git commit -m "Update to ${{ gitea.ref_name }}"
git push origin master