# Tag a Crucible release: re-tag the already-built immutable image and attach # per-platform binary bundles. Tag-gated; never PR-triggered (deploy/release is # not a PR concern, D7). The : image from build-image is the source of truth. name: release on: push: tags: - "v*" env: REGISTRY: registry.westgate.pw IMAGE: sow/crucible jobs: release: runs-on: nix-docker steps: - uses: actions/checkout@v4 with: { fetch-depth: 0 } - name: Build release binaries run: | nix develop --command bash -c ' set -euo pipefail GOOS=linux GOARCH=amd64 scripts/build-binaries.sh mkdir -p dist tar -C bin -czf "dist/crucible-linux-amd64-${GITHUB_REF_NAME}.tar.gz" . ' - name: Upload release artifacts uses: actions/upload-artifact@v4 with: name: crucible-${{ github.ref_name }} path: dist/* # TODO(phase-6): re-tag registry.westgate.pw/sow/crucible: as : # and pin it from sow-platform releases/*.yml once the registry is live.