# Cross-platform Crucible release binaries: a v* tag builds all targets, # then uploads them, SHA256SUMS, and the canonical wrappers to its Gitea release. # Crucible is pure Go (CGO_ENABLED=0), so cross-compiling is a fast loop. name: build-binaries on: push: tags: ['v*'] permissions: code: read releases: write jobs: build-binaries: runs-on: nix-docker timeout-minutes: 30 steps: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: { fetch-depth: 0 } - name: Cross-build all targets run: | nix develop --command bash -c ' set -euo pipefail sha="$(git rev-parse --short=12 HEAD)" ldflags="-s -w -X git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/buildinfo.Version=${sha}" rm -rf dist && mkdir -p dist export CGO_ENABLED=0 for target in linux/amd64 linux/arm64 darwin/amd64 darwin/arm64 windows/amd64 windows/arm64; do os="${target%/*}"; arch="${target#*/}" ext=""; [ "$os" = windows ] && ext=".exe" echo "building crucible-${os}-${arch}${ext}" GOOS="$os" GOARCH="$arch" go build -trimpath -ldflags "$ldflags" \ -o "dist/crucible-${os}-${arch}${ext}" ./cmd/crucible done # Ship the canonical wrappers as release assets too: consumer # drift-check fetches them from the latest release to compare. cp wrappers/crucible.sh wrappers/crucible.ps1 dist/ ( cd dist && sha256sum crucible-* > SHA256SUMS ) cat dist/SHA256SUMS ' - name: Upload to Gitea release env: TOKEN: ${{ secrets.GITEA_TOKEN }} TAG: ${{ github.ref_name }} REPO: ${{ github.repository }} SERVER: ${{ github.server_url }} run: | nix develop --command bash -c ' set -euo pipefail api="${SERVER}/api/v1/repos/${REPO}" auth="Authorization: token ${TOKEN}" # Create the release (ignore "already exists"), then read its id. curl -fsS -X POST -H "$auth" -H "Content-Type: application/json" \ "${api}/releases" \ -d "{\"tag_name\":\"${TAG}\",\"name\":\"${TAG}\"}" || true id="$(curl -fsS -H "$auth" "${api}/releases/tags/${TAG}" \ | grep -o "\"id\":[0-9]*" | head -1 | cut -d: -f2)" for f in dist/*; do echo "uploading $(basename "$f")" curl -fsS -X POST -H "$auth" \ -F "attachment=@${f}" \ "${api}/releases/${id}/assets?name=$(basename "$f")" done '