Skip to content

Commit 32ec355

Browse files
ci: replace auto-tagging with validated tagged releases
1 parent 7e9b55f commit 32ec355

1 file changed

Lines changed: 114 additions & 14 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 114 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -1,26 +1,126 @@
1-
name: Automated Release Engineering
1+
name: SentinelAI Release
22

33
on:
44
push:
5-
branches:
6-
- main
5+
tags:
6+
- "v*.*.*"
7+
pull_request:
8+
paths:
9+
- ".github/workflows/release.yml"
10+
- "CHANGELOG.md"
11+
- "RELEASE_NOTES_v0.1.0.md"
12+
13+
permissions:
14+
contents: read
15+
16+
concurrency:
17+
group: sentinelai-release-${{ github.ref }}
18+
cancel-in-progress: false
719

820
jobs:
9-
tagging-engine:
10-
name: Construct Semantic Version Tags
21+
validate:
22+
name: Validate release candidate
23+
runs-on: ubuntu-latest
24+
steps:
25+
- uses: actions/checkout@v4
26+
with:
27+
fetch-depth: 0
28+
29+
- name: Verify semantic-version tag and changelog
30+
if: startsWith(github.ref, 'refs/tags/')
31+
shell: bash
32+
run: |
33+
tag="${{ github.ref_name }}"
34+
if [[ ! "$tag" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
35+
echo "Invalid semantic-version tag: $tag" >&2
36+
exit 1
37+
fi
38+
version="${tag#v}"
39+
grep -Fq "## [$version]" CHANGELOG.md
40+
41+
- uses: actions/setup-python@v5
42+
with:
43+
python-version: "3.11"
44+
cache: pip
45+
46+
- name: Install Python test dependencies
47+
run: |
48+
python -m pip install --upgrade pip
49+
pip install -r requirements-dev.txt
50+
51+
- name: Run Python test suite
52+
env:
53+
PYTHONPATH: .
54+
run: pytest tests/ -q
55+
56+
- uses: actions/setup-go@v5
57+
with:
58+
go-version: "1.21.x"
59+
cache-dependency-path: ingestion-service/go.sum
60+
61+
- name: Run Go ingestion tests
62+
working-directory: ingestion-service
63+
run: go test ./...
64+
65+
- name: Build ingestion container
66+
run: docker build -t sentinelai-ingestion:release ./ingestion-service
67+
68+
release:
69+
name: Publish GitHub Release
70+
if: startsWith(github.ref, 'refs/tags/')
71+
needs: validate
1172
runs-on: ubuntu-latest
1273
permissions:
1374
contents: write
14-
1575
steps:
16-
- name: ⬇️ Checkout Repository
17-
uses: actions/checkout@v4
76+
- uses: actions/checkout@v4
1877
with:
1978
fetch-depth: 0
2079

21-
- name: 🏷️ Calculate Release Version Alpha
22-
uses: anothrNick/github-tag-action@1.64.0
23-
env:
24-
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
25-
WITH_V: true
26-
DEFAULT_BUMP: patch
80+
- name: Build deterministic source archive and checksum
81+
run: |
82+
mkdir -p dist
83+
git archive --format=tar --prefix="sentinelai-${{ github.ref_name }}/" "${{ github.sha }}" | gzip -n > "dist/sentinelai-${{ github.ref_name }}.tar.gz"
84+
sha256sum "dist/sentinelai-${{ github.ref_name }}.tar.gz" > "dist/sentinelai-${{ github.ref_name }}.tar.gz.sha256"
85+
86+
- name: Publish release
87+
uses: softprops/action-gh-release@v2
88+
with:
89+
body_path: RELEASE_NOTES_v0.1.0.md
90+
generate_release_notes: false
91+
files: |
92+
dist/sentinelai-${{ github.ref_name }}.tar.gz
93+
dist/sentinelai-${{ github.ref_name }}.tar.gz.sha256
94+
95+
publish-container:
96+
name: Publish GHCR ingestion image
97+
if: startsWith(github.ref, 'refs/tags/')
98+
needs: release
99+
runs-on: ubuntu-latest
100+
permissions:
101+
contents: read
102+
packages: write
103+
steps:
104+
- uses: actions/checkout@v4
105+
106+
- uses: docker/login-action@v3
107+
with:
108+
registry: ghcr.io
109+
username: ${{ github.actor }}
110+
password: ${{ secrets.GITHUB_TOKEN }}
111+
112+
- uses: docker/metadata-action@v5
113+
id: meta
114+
with:
115+
images: ghcr.io/coreyleath-code/sentinelai-ingestion
116+
tags: |
117+
type=semver,pattern={{version}}
118+
type=semver,pattern={{major}}.{{minor}}
119+
type=raw,value=latest
120+
121+
- uses: docker/build-push-action@v6
122+
with:
123+
context: ./ingestion-service
124+
push: true
125+
tags: ${{ steps.meta.outputs.tags }}
126+
labels: ${{ steps.meta.outputs.labels }}

0 commit comments

Comments
 (0)