diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index eadeac2..88cb296 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -4,81 +4,97 @@ name: Release on: push: tags: [ "*" ] + # Build, but don't publish, when this workflow changes or on demand, so the + # release build is exercised before a tag is pushed. + pull_request: + paths: [ ".github/workflows/release.yaml" ] + workflow_dispatch: + +permissions: + contents: read + +env: + GOTOOLCHAIN: local jobs: build: - name: Build + name: Build ${{ matrix.goos }}/${{ matrix.goarch }} + runs-on: ubuntu-latest strategy: matrix: - version: [1.24.x] - target: - - { os: 'darwin', platform: 'macos-latest', arch: 'amd64' } - - { os: 'darwin', platform: 'macos-latest', arch: 'arm64' } - - { os: 'linux', platform: 'ubuntu-latest', arch: 'amd64' } - - { os: 'linux', platform: 'ubuntu-latest', arch: 'arm64' } - - { os: 'windows', platform: 'windows-latest', arch: 'amd64' } - runs-on: ${{ matrix.target.platform }} + include: + - { goos: darwin, goarch: amd64 } + - { goos: darwin, goarch: arm64 } + - { goos: linux, goarch: amd64 } + - { goos: linux, goarch: arm64 } + - { goos: windows, goarch: amd64 } steps: - - name: Set up toolchain - uses: actions/setup-go@v2 - with: - go-version: ${{ matrix.version }} - id: go - name: Check out code - uses: actions/checkout@v2 - - name: Build binary - run: go build -o certstrap . - - name: Upload artifact - uses: actions/upload-artifact@v2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # ratchet:actions/checkout@v7.0.1 with: - name: certstrap-${{ matrix.target.os }}-${{ matrix.target.arch }} - path: certstrap + persist-credentials: false - release: - name: Create release - runs-on: ubuntu-latest - needs: [ build ] - outputs: - upload_url: ${{ steps.create_release.outputs.upload_url }} - steps: - - uses: actions/checkout@v2 - - name: Create release - id: create_release - uses: actions/create-release@v1 + - name: Set up Go + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # ratchet:actions/setup-go@v7.0.0 + with: + go-version-file: go.mod + cache: false + + - name: Build binary env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GOOS: ${{ matrix.goos }} + GOARCH: ${{ matrix.goarch }} + CGO_ENABLED: "0" + run: | + if [[ "$GITHUB_REF" == refs/tags/* ]]; then + version="${GITHUB_REF_NAME#v}" + else + version="dev-${GITHUB_SHA::7}" + fi + out="dist/certstrap-${GOOS}-${GOARCH}" + go build -trimpath -ldflags "-X main.release=${version}" -o "$out" . + + # Fail if the binary wasn't built for the requested platform. + go version -m "$out" | grep -Eq "^[[:space:]]+build[[:space:]]+GOOS=${GOOS}$" + go version -m "$out" | grep -Eq "^[[:space:]]+build[[:space:]]+GOARCH=${GOARCH}$" + if [[ "$GOOS" == linux && "$GOARCH" == amd64 ]]; then + "./$out" --version | grep -F "$version" + fi + + - name: Upload artifact + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # ratchet:actions/upload-artifact@v7.0.1 with: - tag_name: ${{ github.ref }} - release_name: "Release Build (Draft)" - body: "Release Build (from ${{ github.ref }}/${{ github.sha }})" - draft: true - prerelease: true + name: certstrap-${{ matrix.goos }}-${{ matrix.goarch }} + path: dist/certstrap-${{ matrix.goos }}-${{ matrix.goarch }} + if-no-files-found: error - add-assets: - name: Add assets + release: + name: Create draft release + if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/') + needs: build runs-on: ubuntu-latest - needs: [ build, release ] - strategy: - matrix: - target: - - { os: 'darwin', arch: 'amd64' } - - { os: 'darwin', arch: 'arm64' } - - { os: 'linux', arch: 'amd64' } - - { os: 'linux', arch: 'arm64' } - - { os: 'windows', arch: 'amd64' } + permissions: + contents: write steps: - - uses: actions/checkout@v2 - - name: Download artifact - uses: actions/download-artifact@v2 + - name: Download artifacts + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # ratchet:actions/download-artifact@v8.0.1 with: - name: certstrap-${{ matrix.target.os }}-${{ matrix.target.arch }} + pattern: certstrap-* path: dist - - name: Upload artifact to release - uses: actions/upload-release-asset@v1 + merge-multiple: true + + - name: Create draft release env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - upload_url: ${{ needs.release.outputs.upload_url }} - asset_path: ./dist/certstrap - asset_name: certstrap-${{ matrix.target.os }}-${{ matrix.target.arch }} - asset_content_type: application/octet-stream + GH_TOKEN: ${{ github.token }} + GH_REPO: ${{ github.repository }} + TAG: ${{ github.ref_name }} + run: | + cd dist + sha256sum certstrap-* > SHA256SUMS + flags=(--verify-tag --draft --generate-notes + --title "Version ${TAG#v}" + --notes "Release Build (from ${GITHUB_REF}/${GITHUB_SHA})") + if [[ "$TAG" == *-* ]]; then + flags+=(--prerelease) + fi + gh release create "$TAG" certstrap-* SHA256SUMS "${flags[@]}"