Repository navigation
Merge branch 'Bnjoroge/lock-refactor' into gh-simulate/url-overrides #13
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: release-runner | ||
|
Check failure on line 1 in .github/workflows/release-runner.yml
|
||
| # Publishes standalone preloop-runner binaries for every supported host | ||
| # platform, a CycloneDX SBOM per binary, and a minimal container image at | ||
| # ghcr.io/preloopdev/preloop-runner. Linux bundles are also consumed by | ||
| # install.sh as the in-VM guest runner. | ||
| on: | ||
| release: | ||
| types: [published] | ||
| workflow_dispatch: | ||
| permissions: | ||
| contents: read | ||
| jobs: | ||
| build-runner: | ||
| name: Build runner ${{ matrix.triple }} | ||
| runs-on: ${{ matrix.os }} | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| include: | ||
| - triple: x86_64-unknown-linux-gnu | ||
| os: ubuntu-22.04 | ||
| zig: true | ||
| - triple: aarch64-unknown-linux-gnu | ||
| os: ubuntu-22.04 | ||
| zig: true | ||
| - triple: aarch64-apple-darwin | ||
| os: macos-14 | ||
| - triple: x86_64-apple-darwin | ||
| os: macos-15-intel | ||
| - triple: x86_64-pc-windows-msvc | ||
| os: windows-latest | ||
| ext: .exe | ||
| permissions: | ||
| contents: write | ||
| steps: | ||
| - name: Check out repository | ||
| uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 | ||
| with: | ||
| persist-credentials: false | ||
| - name: Set up Rust toolchain | ||
| - uses: dtolnay/rust-toolchain@89b12181fb390509a0842a86cc55eeb8eb928c1d # stable | ||
| with: | ||
| toolchain: "1.97" | ||
| targets: ${{ matrix.triple }} | ||
| - name: Set up Zig cross toolchain | ||
| if: matrix.zig | ||
| uses: goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406 # v2.2.1 | ||
| with: | ||
| version: 0.14.1 | ||
| - name: Install cargo-zigbuild | ||
| if: matrix.zig | ||
| uses: taiki-e/install-action@6c6fd71fe4fb72c3697d269963d0e15df8adedad # v2.85.10 | ||
| with: | ||
| tool: cargo-zigbuild@0.23.0 | ||
| - name: Build runner (Linux, zigbuild) | ||
| if: matrix.zig | ||
| env: | ||
| TRIPLE: ${{ matrix.triple }} | ||
| run: | | ||
| cargo zigbuild --release --target "$TRIPLE" -p preloop-runner | ||
| mkdir -p dist | ||
| cp "target/$TRIPLE/release/preloop-runner" "dist/preloop-runner-$TRIPLE" | ||
| sha256sum "dist/preloop-runner-$TRIPLE" > "dist/preloop-runner-$TRIPLE.sha256" | ||
| - name: Build runner (macOS) | ||
| if: runner.os == 'macOS' | ||
| env: | ||
| TRIPLE: ${{ matrix.triple }} | ||
| run: | | ||
| cargo build --release --target "$TRIPLE" -p preloop-runner | ||
| mkdir -p dist | ||
| cp "target/$TRIPLE/release/preloop-runner" "dist/preloop-runner-$TRIPLE" | ||
| shasum -a 256 "dist/preloop-runner-$TRIPLE" | awk '{print $1}' \ | ||
| > "dist/preloop-runner-$TRIPLE.sha256" | ||
| - name: Build runner (Windows) | ||
| if: runner.os == 'Windows' | ||
| env: | ||
| TRIPLE: ${{ matrix.triple }} | ||
| shell: bash | ||
| run: | | ||
| cargo build --release --target "$TRIPLE" -p preloop-runner | ||
| mkdir -p dist | ||
| cp "target/$TRIPLE/release/preloop-runner.exe" "dist/preloop-runner-$TRIPLE.exe" | ||
| sha256sum "dist/preloop-runner-$TRIPLE.exe" | awk '{print $1}' \ | ||
| > "dist/preloop-runner-$TRIPLE.exe.sha256" | ||
| - name: Generate SBOM (CycloneDX) | ||
| uses: taiki-e/install-action@6c6fd71fe4fb72c3697d269963d0e15df8adedad # v2.85.10 | ||
| with: | ||
| tool: cargo-cyclonedx | ||
| - name: Emit SBOM | ||
| env: | ||
| TRIPLE: ${{ matrix.triple }} | ||
| shell: bash | ||
| run: | | ||
| cargo cyclonedx \ | ||
| --manifest-path crates/preloop-runner/Cargo.toml \ | ||
| --format json --target "$TRIPLE" \ | ||
| --target-in-filename --override-filename preloop-runner | ||
| mv "crates/preloop-runner/preloop-runner_${TRIPLE}.cdx.json" dist/ | ||
| - name: Upload runner bundle to release | ||
| if: github.event_name == 'release' | ||
| env: | ||
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
| TAG_NAME: ${{ github.event.release.tag_name }} | ||
| shell: bash | ||
| run: gh release upload "$TAG_NAME" dist/* --clobber | ||
| - name: Retain runner bundle for non-release builds | ||
| if: github.event_name != 'release' | ||
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 | ||
| with: | ||
| name: preloop-runner-${{ matrix.triple }} | ||
| path: dist/ | ||
| if-no-files-found: error | ||
| runner-image: | ||
| name: Publish runner container image | ||
| runs-on: ubuntu-22.04 | ||
| needs: build-runner | ||
| permissions: | ||
| contents: read | ||
| packages: write | ||
| steps: | ||
| - name: Check out repository | ||
| uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 | ||
| with: | ||
| persist-credentials: false | ||
| - name: Set up Rust toolchain | ||
| - uses: dtolnay/rust-toolchain@89b12181fb390509a0842a86cc55eeb8eb928c1d # stable | ||
| with: | ||
| toolchain: "1.97" | ||
| targets: x86_64-unknown-linux-gnu,aarch64-unknown-linux-gnu | ||
| - name: Set up Zig cross toolchain | ||
| uses: goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406 # v2.2.1 | ||
| with: | ||
| version: 0.14.1 | ||
| - name: Install cargo-zigbuild | ||
| uses: taiki-e/install-action@6c6fd71fe4fb72c3697d269963d0e15df8adedad # v2.85.10 | ||
| with: | ||
| tool: cargo-zigbuild@0.23.0 | ||
| - name: Build Linux runner binaries | ||
| run: | | ||
| for TRIPLE in x86_64-unknown-linux-gnu aarch64-unknown-linux-gnu; do | ||
| cargo zigbuild --release --target "$TRIPLE" -p preloop-runner | ||
| mkdir -p "dist/$TRIPLE" | ||
| cp "target/$TRIPLE/release/preloop-runner" "dist/$TRIPLE/preloop-runner" | ||
| done | ||
| - name: Set up Docker Buildx | ||
| uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 | ||
| - name: Log in to ghcr.io | ||
| if: github.event_name == 'release' || github.event_name == 'workflow_dispatch' | ||
| uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 | ||
| with: | ||
| registry: ghcr.io | ||
| username: ${{ github.actor }} | ||
| password: ${{ secrets.GITHUB_TOKEN }} | ||
| - name: Read version pins | ||
| id: pins | ||
| run: | | ||
| # Same awk pattern release-golden.yml uses for versions.toml. | ||
| echo "docker=$(awk -F'\"' '/^runner_image_docker_version = / { print $2 }' versions.toml)" >> "$GITHUB_OUTPUT" | ||
| echo "buildx=$(awk -F'\"' '/^runner_image_buildx_version = / { print $2 }' versions.toml)" >> "$GITHUB_OUTPUT" | ||
| - name: Image tags | ||
| id: meta | ||
| env: | ||
| TAG_NAME: ${{ github.event.release.tag_name || github.sha }} | ||
| run: | | ||
| echo "tags=ghcr.io/preloopdev/preloop-runner:${TAG_NAME},ghcr.io/preloopdev/preloop-runner:latest" >> "$GITHUB_OUTPUT" | ||
| - name: Build (and push on release) runner image | ||
| uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 | ||
| with: | ||
| context: . | ||
| file: ./ci/runner.Dockerfile | ||
| platforms: linux/amd64,linux/arm64 | ||
| push: ${{ github.event_name == 'release' || github.event_name == 'workflow_dispatch' }} | ||
| tags: ${{ steps.meta.outputs.tags }} | ||
| build-args: | | ||
| DOCKER_VERSION=${{ steps.pins.outputs.docker }} | ||
| BUILDX_VERSION=${{ steps.pins.outputs.buildx }} | ||
| provenance: true | ||
| sbom: true | ||