forked from Proximyst/proxy-protocol
-
Notifications
You must be signed in to change notification settings - Fork 1
107 lines (103 loc) · 3.85 KB
/
Copy pathrelease.yaml
File metadata and controls
107 lines (103 loc) · 3.85 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
name: Release
on:
push:
tags: ['v*']
workflow_dispatch:
inputs:
dry-run:
description: 'Run cargo publish with --dry-run (skips registry push and GH release)'
type: boolean
default: false
jobs:
verify-version:
if: ${{ startsWith(github.ref, 'refs/tags/v') }}
runs-on: ubuntu-latest
outputs:
version: ${{ steps.v.outputs.version }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- id: v
run: |
TAG_VERSION="${GITHUB_REF_NAME#v}"
CRATE_VERSION=$(grep -m1 '^version' Cargo.toml | sed -E 's/.*"([^"]+)".*/\1/')
if [ "$TAG_VERSION" != "$CRATE_VERSION" ]; then
echo "Tag version ($TAG_VERSION) does not match Cargo.toml version ($CRATE_VERSION)" >&2
exit 1
fi
echo "version=$TAG_VERSION" >> "$GITHUB_OUTPUT"
package-crate:
needs: [verify-version]
runs-on: ubuntu-latest
permissions:
contents: read
env:
CARGO_REGISTRIES_GEN0SEC_INDEX: sparse+https://crates-internal.g0s.dev/api/v1/crates/
CARGO_REGISTRIES_GEN0SEC_TOKEN: ${{ secrets.GEN0SEC_CARGO_TOKEN }}
CARGO_REGISTRIES_GEN0SEC_CREDENTIAL_PROVIDER: cargo:token
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
- name: cargo package
run: cargo package --registry gen0sec --locked
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: proxy-protocol-crate
path: target/package/proxy-protocol-${{ needs.verify-version.outputs.version }}.crate
if-no-files-found: error
retention-days: 7
publish:
needs: [verify-version, package-crate]
runs-on: ubuntu-latest
environment: release
permissions:
contents: read
env:
CARGO_REGISTRIES_GEN0SEC_INDEX: sparse+https://crates-internal.g0s.dev/api/v1/crates/
CARGO_REGISTRIES_GEN0SEC_TOKEN: ${{ secrets.GEN0SEC_CARGO_TOKEN }}
CARGO_REGISTRIES_GEN0SEC_CREDENTIAL_PROVIDER: cargo:token
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
- name: Cargo publish
env:
DRY_RUN: ${{ inputs.dry-run }}
CARGO_HTTP_TIMEOUT: '300'
CARGO_HTTP_LOW_SPEED_LIMIT: '1'
CARGO_NET_RETRY: '5'
run: |
ARGS="--registry gen0sec --locked"
if [ "$DRY_RUN" = "true" ]; then
ARGS="$ARGS --dry-run"
fi
for attempt in 1 2 3; do
if cargo publish $ARGS; then exit 0; fi
echo "Publish attempt $attempt failed, retrying in 15s..."
sleep 15
done
echo "Publish failed after 3 attempts" >&2
exit 1
gh-release:
needs: [verify-version, package-crate, publish]
if: ${{ startsWith(github.ref, 'refs/tags/v') && inputs.dry-run != true }}
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
name: proxy-protocol-crate
path: release-assets
- name: SHA256 checksums
run: |
set -euo pipefail
cd release-assets
for f in *; do [ -f "$f" ] && sha256sum "$f" > "${f}.sha256"; done
ls -la
- uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0
with:
draft: false
generate_release_notes: true
files: release-assets/*
make_latest: true