-
Notifications
You must be signed in to change notification settings - Fork 1
247 lines (226 loc) · 9.42 KB
/
Copy pathrelease.yml
File metadata and controls
247 lines (226 loc) · 9.42 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
name: Release
# Builds the `autter` binary for every supported platform, publishes them as a
# GitHub Release, and attaches version-pinned install.sh/install.ps1 copies
# (placeholders filled in with the real repo, version, and SHA256 checksums).
# Afterwards publishes the npm bootstrapper package (npm/) stamped with the
# same version, which downloads these release binaries on install.
#
# Trigger:
# - pushing a tag matching `v*` (e.g. v1.5.9) publishes a release
# - merging a version bump to main (see tag-release.yml) creates the tag
# automatically from Cargo.toml's `version`
# - a manual run on a branch builds binaries for validation without publishing
# - a manual run targeting a v* tag publishes that tagged release
#
# Asset names match what install.sh / install.ps1 expect: autter-<os>-<arch>
# macos/arm64 -> autter-macos-arm64 macos/x64 -> autter-macos-x64
# linux/x64 -> autter-linux-x64 linux/arm64 -> autter-linux-arm64
# windows/x64 -> autter-windows-x64.exe
# windows/arm64 -> autter-windows-arm64.exe
on:
push:
tags:
# Match CLI version tags like v1.6.4 only. The leading digit class is
# important so this does NOT also fire on the extension's `vscode-v*`
# tags (which start with "v" too and would otherwise match "v*").
- "v[0-9]*"
workflow_dispatch:
permissions:
contents: write
jobs:
build:
name: Build ${{ matrix.asset }}
runs-on: ${{ matrix.os }}
# PostHog project public ("client") key + host, baked into release binaries
# at compile time via option_env!. Public keys are safe to embed (they ship
# in browser bundles too); telemetry only sends after the user opts in during
# `autter onboard`. To rotate, change these values (or move them to repo
# variables and reference ${{ vars.POSTHOG_API_KEY }}).
env:
POSTHOG_API_KEY: phc_aWveMd1bPhuEYtFnCS1G2IHgln3iGQqjfIdkfnuolxI
POSTHOG_HOST: https://us.i.posthog.com
strategy:
fail-fast: false
matrix:
include:
- asset: autter-macos-arm64
os: blacksmith-6vcpu-macos-15
target: aarch64-apple-darwin
tool: cargo
- asset: autter-macos-x64
# Cross-compile x86_64 on an Apple Silicon runner: the macOS SDK is
# universal, and the scarce/deprecated macos-13 Intel runners can
# leave this job queued for hours before it is cancelled.
os: blacksmith-6vcpu-macos-15
target: x86_64-apple-darwin
tool: cargo
- asset: autter-linux-x64
# 22.04 keeps the glibc requirement low (2.35) for broader portability
os: blacksmith-4vcpu-ubuntu-2204
target: x86_64-unknown-linux-gnu
tool: cargo
- asset: autter-linux-arm64
os: blacksmith-4vcpu-ubuntu-2204
target: aarch64-unknown-linux-gnu
tool: cross
- asset: autter-windows-x64.exe
# No OpenSSL needed on Windows: TLS goes through native-tls/SChannel,
# and the only C build is the bundled SQLite (handled by cc + MSVC).
os: blacksmith-4vcpu-windows-2025
target: x86_64-pc-windows-msvc
tool: cargo
- asset: autter-windows-arm64.exe
# Cross-compile ARM64 on an x64 runner. Stay on GitHub-hosted
# windows-2022: Blacksmith's windows-2025 image exports x64 LIB/
# INCLUDE by default, so link.exe pulls um\x64\*.lib and fails with
# LNK4272 / LNK1120 unless the amd64_arm64 MSVC env is set first.
# windows-2022 is the last known-good host for this target (v1.7.2).
os: windows-2022
target: aarch64-pc-windows-msvc
tool: cargo
msvc_arch: amd64_arm64
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@stable
with:
targets: ${{ matrix.target }}
- name: Cache cargo
uses: Swatinem/rust-cache@v2
with:
key: ${{ matrix.target }}
- name: Install cross
if: matrix.tool == 'cross'
uses: taiki-e/install-action@v2
with:
tool: cross
# Point LIB/INCLUDE/PATH at the ARM64 Windows SDK + MSVC libs when
# cross-compiling aarch64-pc-windows-msvc from an x64 host. Without this,
# runners that pre-export an x64 MSVC environment (notably Blacksmith
# windows-2025) link the wrong machine-type libraries.
- name: Configure MSVC for target arch
if: ${{ matrix.msvc_arch }}
uses: ilammy/msvc-dev-cmd@v1
with:
arch: ${{ matrix.msvc_arch }}
- name: Build (cargo)
if: matrix.tool == 'cargo'
run: cargo build --release --locked --target ${{ matrix.target }} --bin autter
- name: Build (cross)
if: matrix.tool == 'cross'
# cross runs the build inside a Docker image that bundles the aarch64
# cross toolchain, which is what makes the vendored openssl + bundled
# sqlite C builds work for the non-native target.
run: cross build --release --locked --target ${{ matrix.target }} --bin autter
- name: Stage binary
shell: bash
run: |
mkdir -p dist
src="target/${{ matrix.target }}/release/autter"
if [[ "${{ matrix.target }}" == *-windows-* ]]; then
src="${src}.exe"
fi
cp "${src}" "dist/${{ matrix.asset }}"
- name: Upload artifact
uses: actions/upload-artifact@v4
with:
name: ${{ matrix.asset }}
path: dist/${{ matrix.asset }}
if-no-files-found: error
release:
name: Publish release
needs: build
runs-on: blacksmith-4vcpu-ubuntu-2404
# Publish only when the workflow is running against a version tag. A manual
# branch dispatch therefore remains build-only, while tag-release.yml can
# explicitly dispatch this workflow for its GITHUB_TOKEN-created tag.
if: startsWith(github.ref, 'refs/tags/v')
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Download all binaries
uses: actions/download-artifact@v4
with:
path: artifacts
- name: Assemble release assets
id: assemble
shell: bash
run: |
set -euo pipefail
mkdir -p dist
assets="autter-macos-arm64 autter-macos-x64 autter-linux-x64 autter-linux-arm64 autter-windows-x64.exe autter-windows-arm64.exe"
# download-artifact nests each artifact under its own directory
for asset in ${assets}; do
cp "artifacts/${asset}/${asset}" "dist/${asset}"
chmod +x "dist/${asset}"
done
# Build the checksums file and the pipe-separated string the install
# scripts embed.
: > dist/checksums.txt
CHECKSUMS=""
for asset in ${assets}; do
line="$(cd dist && sha256sum "${asset}")"
echo "${line}" >> dist/checksums.txt
CHECKSUMS="${CHECKSUMS:+${CHECKSUMS}|}${line}"
done
echo "Checksums:"
cat dist/checksums.txt
# Fill the install script placeholders for the version-pinned release
# copies (bash and PowerShell).
python3 scripts/fill-install-template.py install.sh dist/install.sh \
--repo "${GITHUB_REPOSITORY}" \
--version "${GITHUB_REF_NAME}" \
--checksums "${CHECKSUMS}"
chmod +x dist/install.sh
python3 scripts/fill-install-template.py install.ps1 dist/install.ps1 \
--repo "${GITHUB_REPOSITORY}" \
--version "${GITHUB_REF_NAME}" \
--checksums "${CHECKSUMS}"
- name: Create GitHub Release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
gh release create "${GITHUB_REF_NAME}" \
--repo "${GITHUB_REPOSITORY}" \
--title "${GITHUB_REF_NAME}" \
--generate-notes \
dist/autter-macos-arm64 \
dist/autter-macos-x64 \
dist/autter-linux-x64 \
dist/autter-linux-arm64 \
dist/autter-windows-x64.exe \
dist/autter-windows-arm64.exe \
dist/install.sh \
dist/install.ps1 \
dist/checksums.txt
publish-npm:
name: Publish npm package
needs: release
runs-on: blacksmith-4vcpu-ubuntu-2404
if: startsWith(github.ref, 'refs/tags/v')
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: 20
registry-url: "https://registry.npmjs.org"
# The npm package is a thin bootstrapper that downloads the binaries
# published by the release job above, so it must publish AFTER the
# GitHub Release exists. Stamps the package with the tag's version so
# `npm i -g @autter/cli@X.Y.Z` maps 1:1 onto release vX.Y.Z. Skips (rather
# than fails) when the NPM_TOKEN secret is not configured, so a release
# never blocks on npm.
- name: Publish to npm
working-directory: npm
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
run: |
if [ -z "${NODE_AUTH_TOKEN}" ]; then
echo "NPM_TOKEN secret not set; skipping npm publish."
exit 0
fi
npm version "${GITHUB_REF_NAME#v}" --no-git-tag-version --allow-same-version
npm publish --access public