ci: release the platform and the Java SDK together from a vX.Y.Z release - #152
Merged
Merged
Conversation
Every module now takes `version` from the root gradle.properties (1.0.0-SNAPSHOT), replacing the apps' hard-coded 0.0.1-SNAPSHOT and the SDK's own apiModelVersion/javaSdkVersion. The console's About dialog now shows the real version. The Dockerfile no longer names the jar by version, and the Pulsar filter's NAR keeps its unversioned name, since brokers load it by path. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: jgjesdal <jostein@intellistream.ai>
A vX.Y.Z GitHub Release on release/vX.Y attaches the five service jars and the Pulsar filter to the release, with SHA256SUMS and a provenance attestation, and publishes the locally signed SDK to Maven Central. The systemd install now downloads the release jars. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: jgjesdal <jostein@intellistream.ai>
This was referenced Oct 1, 2026
olavgg
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
A platform release delivered nothing. #145 set up release branches (
release/vX.Y), but no workflow reacted to a release. No artifacts were built or attached, and every app was hard-coded at0.0.1-SNAPSHOT, so the console's About dialog, which is also its AGPL source offer, could not say which release was running. Operators install from source (git clone+./scripts/up.sh --build), or for production followsystemd/README.md, which builds the jars with./gradlew bootJarand installs one per service.The SDK had a release pipeline of its own (#148), on its own version and also on
vX.Y.Ztags. Two release lines on the same tags would collide: a platform release would start an SDK publish.The decision is to couple them for now: one version, one tag, one release for the platform and the Java SDK, like the Rust SDK already follows the platform's version line. Splitting later means giving the SDK its own version property and tag prefix again.
This supersedes #151, which separated the two.
What changes
One version (
4c611bcd)version=1.0.0-SNAPSHOTin the rootgradle.properties, which Gradle applies to every module.-Pversion=X.Y.Zoverrides it.version = '0.0.1-SNAPSHOT'and the SDK'sapiModelVersion/javaSdkVersion.centralBundlenames its zip from it.deploy/app/Dockerfilecopied${MODULE}-0.0.1-SNAPSHOT.jarby name. It now copies each module's boot jar (skipping-plain) to a fixed name in the build stage, so the runtime stage need not know the version. Tested by building thedatahub-cleanupimage with podman.datahub-pulsar-filter.nar, because its README and broker setups load it by path. The release copy carries the version.datahub-e2e/README.mdglobs the jar instead of naming the version.The release workflow (
878b5bec).github/workflows/java-sdk-release.ymlbecomesrelease.yml. AvX.Y.ZGitHub Release runs:versionsvX.Y.Z, equalsversion, and its commit is onrelease/vX.Ybuild./gradlew build(build.ymldoes not run on releases)platformsystemd/runs), plusdatahub-pulsar-filter-X.Y.Z.narand aSHA256SUMSsdkpublish-sdkreleaseenvironment, after approval: uploads the verified bundle to Maven Centralattach-platformactions/attest, as the Rust repo does for its wheels) and attaches the jars, NAR andSHA256SUMSto the releaseThe platform jars are attached last, so a release shows its jars only once all of it went out. If Central fails, re-running the failed jobs finishes the release.
systemd/README.mdnow installs the jars from the release, checked againstSHA256SUMS, with building from a checkout of the tag as the alternative.On a pull request that touches a build file, the version or the release machinery, the workflow rehearses everything except the upload and the attaching.
To release
X.Y.Z(also inAGENTS.md):# on release/vX.Y, with version=X.Y.Z in gradle.properties ./gradlew centralBundle -PsigningUseGpgCommand=true gh release create vX.Y.Z --target release/vX.Y build/central/datahub-central-X.Y.Z.zipDecisions to confirm
gradle.propertiesif you prefer otherwise.SHA256SUMSand a GitHub build-provenance attestation (gh attestation verify <file> --repo IntelliStream-DataHub/datahub-platform), which ties each file to this workflow and the tagged commit without anyone holding a key. Signing them locally like the SDK is possible, but adds a step to every release.Needed in the GitHub settings
The
releaseenvironment is set up for #151'ssdk-v*tags. For this scheme:v*.publish-sdkwould upload with no approval.CENTRAL_TOKEN_PASSWORDafter testing.Also recommended: a branch ruleset on
release/*(still open from #145), and a tag ruleset restricting who may createv*tags.Docs
docs/administration/installing.mdxshould say a production install takes the jars from the release matching the version, assystemd/README.mdnow does. Pinning the evaluation stack to a tag (git clone --branch vX.Y.Z) would also make releases meaningful there.ai.intellistream:datahub-sdk:1.0.0.Verification
./gradlew buildis green, and every module reportsversion: 1.0.0-SNAPSHOT.platformjob's script was run locally as written: it produced the five jars, the versioned NAR andSHA256SUMS.sdkjob's rehearsal was simulated locally from the YAML, and the verifier passes.versionscheck was run in a scratch repository:v1.0.0onrelease/v1.0passes, while a tag that disagrees withversion, ansdk-vtag, and a commit not on the release branch are refused.datahub-cleanupimage.🤖 Generated with Claude Code