From 1f25aa318fe20103cc28429a1e50dd5b787dee58 Mon Sep 17 00:00:00 2001 From: vickydotbat Date: Tue, 16 Jun 2026 08:36:19 +0200 Subject: [PATCH] ci: cross-platform binaries + tag-gated Gitea release --- .gitea/workflows/build-binaries.yml | 66 +++++++++++++++++++++++++++++ .gitea/workflows/release.yml | 38 ----------------- 2 files changed, 66 insertions(+), 38 deletions(-) create mode 100644 .gitea/workflows/build-binaries.yml delete mode 100644 .gitea/workflows/release.yml diff --git a/.gitea/workflows/build-binaries.yml b/.gitea/workflows/build-binaries.yml new file mode 100644 index 0000000..f4f5770 --- /dev/null +++ b/.gitea/workflows/build-binaries.yml @@ -0,0 +1,66 @@ +# Cross-platform Crucible binaries (D7 trigger standard): +# PR / push main -> cross-build ALL targets to prove they compile (no publish) +# tag v* -> build all targets + SHA256SUMS, upload to the Gitea release +# Crucible is pure Go (CGO_ENABLED=0), so cross-compiling is a fast loop. +name: build-binaries + +on: + pull_request: + push: + branches: [main] + tags: ['v*'] + +jobs: + build-binaries: + runs-on: nix-docker + steps: + - uses: actions/checkout@v4 + with: { fetch-depth: 0 } + + - name: Cross-build all targets + run: | + nix develop --command bash -c ' + set -euo pipefail + sha="$(git rev-parse --short=12 HEAD)" + ldflags="-s -w -X git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/buildinfo.Version=${sha}" + rm -rf dist && mkdir -p dist + export CGO_ENABLED=0 + for target in linux/amd64 linux/arm64 darwin/amd64 darwin/arm64 windows/amd64 windows/arm64; do + os="${target%/*}"; arch="${target#*/}" + ext=""; [ "$os" = windows ] && ext=".exe" + echo "building crucible-${os}-${arch}${ext}" + GOOS="$os" GOARCH="$arch" go build -trimpath -ldflags "$ldflags" \ + -o "dist/crucible-${os}-${arch}${ext}" ./cmd/crucible + done + # Ship the canonical wrappers as release assets too: consumer + # drift-check fetches them from the latest release to compare. + cp wrappers/crucible.sh wrappers/crucible.ps1 dist/ + ( cd dist && sha256sum crucible-* > SHA256SUMS ) + cat dist/SHA256SUMS + ' + + - name: Upload to Gitea release + if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') + env: + TOKEN: ${{ secrets.GITHUB_TOKEN }} + TAG: ${{ github.ref_name }} + REPO: ${{ github.repository }} + SERVER: ${{ github.server_url }} + run: | + nix develop --command bash -c ' + set -euo pipefail + api="${SERVER}/api/v1/repos/${REPO}" + auth="Authorization: token ${TOKEN}" + # Create the release (ignore "already exists"), then read its id. + curl -fsS -X POST -H "$auth" -H "Content-Type: application/json" \ + "${api}/releases" \ + -d "{\"tag_name\":\"${TAG}\",\"name\":\"${TAG}\"}" || true + id="$(curl -fsS -H "$auth" "${api}/releases/tags/${TAG}" \ + | grep -o "\"id\":[0-9]*" | head -1 | cut -d: -f2)" + for f in dist/*; do + echo "uploading $(basename "$f")" + curl -fsS -X POST -H "$auth" \ + -F "attachment=@${f}" \ + "${api}/releases/${id}/assets?name=$(basename "$f")" + done + ' diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml deleted file mode 100644 index e7caf19..0000000 --- a/.gitea/workflows/release.yml +++ /dev/null @@ -1,38 +0,0 @@ -# Tag a Crucible release: re-tag the already-built immutable image and attach -# per-platform binary bundles. Tag-gated; never PR-triggered (deploy/release is -# not a PR concern, D7). The : image from build-image is the source of truth. -name: release - -on: - push: - tags: - - "v*" - -env: - REGISTRY: registry.westgate.pw - IMAGE: deployment/crucible - -jobs: - release: - runs-on: nix-docker - steps: - - uses: actions/checkout@v4 - with: { fetch-depth: 0 } - - - name: Build release binaries - run: | - nix develop --command bash -c ' - set -euo pipefail - GOOS=linux GOARCH=amd64 bash scripts/build-binaries.sh - mkdir -p dist - tar -C bin -czf "dist/crucible-linux-amd64-${GITHUB_REF_NAME}.tar.gz" . - ' - - - name: Upload release artifacts - uses: actions/upload-artifact@v4 - with: - name: crucible-${{ github.ref_name }} - path: dist/* - - # TODO(phase-6): re-tag registry.westgate.pw/deployment/crucible: as : - # and pin it from sow-platform releases/*.yml once the registry is live.