g1t/.g1t/workflows/runner-release.yml

102 lines4,049 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Fast pages, required checks on the branch, self-hosted runners, honest incidents1# Releases the self-hosted runner, g1t-runner (crates/runner): builds it for
2# Linux, macOS and Windows on x64 and arm64, signs the release, publishes it
3# to g1t.sh/downloads/runner/ (the g1t-downloads R2 bucket), and pushes its
4# container image. Runners already out there update themselves to it.
5#
6# A release is a tag `runner-v<version>`, where the version is the one in
7# crates/runner/Cargo.toml; or run it by hand. scripts/runner-release.mjs
8# does the work; docs/DEPLOYING.md, "The self-hosted runner", says how to
9# make the release key the first time.
10name: Runner release
11
12on:
13 push:
14 tags: ["runner-v*"]
15 workflow_dispatch:
16
17concurrency:
18 group: runner-release
19 cancel-in-progress: false
20
21env:
22 CLOUDFLARE_ACCOUNT_ID: ${{ vars.CLOUDFLARE_ACCOUNT_ID }}
23 WRANGLER_SEND_METRICS: "false"
24
25jobs:
26 binaries:
27 name: Build, sign and publish
28 runs-on: ubuntu-latest
29 environment: production
30 timeout-minutes: 60
31 steps:
32 - uses: actions/checkout@v5
33 - name: The tag names this version
34 if: startsWith(github.ref, 'refs/tags/runner-v')
35 run: |
36 version="$(sed -n 's/^version = "\(.*\)"/\1/p' crates/runner/Cargo.toml | head -1)"
37 [ "runner-v$version" = "${GITHUB_REF_NAME}" ] || { echo "::error::The tag is ${GITHUB_REF_NAME}, but crates/runner is $version"; exit 1; }
38 - name: Install zig and cargo-zigbuild
39 run: |
40 pip install --user ziglang==0.13.0
41 echo "$HOME/.local/bin" >> "$GITHUB_PATH"
42 cargo install --locked cargo-zigbuild
43 - uses: actions/cache@v4
44 with:
45 path: |
46 ~/.cargo/registry
47 target
48 key: runner-release-${{ hashFiles('Cargo.lock') }}
49 - name: Build every platform
50 env:
g1t-runner 0.1.0 is released: signed binaries for five platforms at g1t.sh/downloads/runner; the Artifacts checks' results51 G1T_RUNNER_RELEASE_KEY: ${{ vars.RUNNER_RELEASE_PUBLIC_KEY }}
Fast pages, required checks on the branch, self-hosted runners, honest incidents52 RUNNER_AGENT_IMAGE: ${{ vars.RUNNER_AGENT_IMAGE }}
53 run: node scripts/runner-release.mjs build
54 - name: Sign
55 env:
56 RUNNER_RELEASE_KEY: ${{ secrets.RUNNER_RELEASE_KEY }}
g1t-runner 0.1.0 is released: signed binaries for five platforms at g1t.sh/downloads/runner; the Artifacts checks' results57 G1T_RUNNER_RELEASE_KEY: ${{ vars.RUNNER_RELEASE_PUBLIC_KEY }}
Fast pages, required checks on the branch, self-hosted runners, honest incidents58 run: |
59 node scripts/runner-release.mjs sign
60 node scripts/runner-release.mjs verify
61 - name: Install Wrangler
62 run: npm ci --workspaces=false --no-audit --no-fund
63 - name: Publish to g1t.sh/downloads/runner
64 env:
65 CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
66 run: node scripts/runner-release.mjs publish
67 - uses: actions/upload-artifact@v4
68 with:
69 name: linux-binaries
70 path: |
71 target/runner-release/*/g1t-runner-linux-x64
72 target/runner-release/*/g1t-runner-linux-arm64
73
74 image:
75 name: Container image
76 needs: binaries
77 # Needs Docker, which g1t's own sandboxes do not have.
78 runs-on: [self-hosted, docker]
79 environment: production
80 timeout-minutes: 30
81 steps:
82 - uses: actions/checkout@v5
83 - uses: actions/download-artifact@v4
84 with:
85 name: linux-binaries
86 path: release
87 - name: Build and push for amd64 and arm64
88 env:
89 REGISTRY_USER: ${{ vars.RUNNER_IMAGE_REGISTRY_USER }}
90 REGISTRY_TOKEN: ${{ secrets.RUNNER_IMAGE_REGISTRY_TOKEN }}
91 IMAGE: ${{ vars.RUNNER_IMAGE }}
92 run: |
93 version="$(sed -n 's/^version = "\(.*\)"/\1/p' crates/runner/Cargo.toml | head -1)"
94 echo "$REGISTRY_TOKEN" | docker login --username "$REGISTRY_USER" --password-stdin
95 for arch in amd64 arm64; do
96 mkdir -p "context-$arch"
97 cp deploy/runner/Dockerfile "context-$arch/"
98 name="g1t-runner-linux-$([ "$arch" = amd64 ] && echo x64 || echo arm64)"
99 cp release/*/"$name" "context-$arch/g1t-runner"
100 docker buildx build --platform "linux/$arch" -t "$IMAGE:$version-$arch" --push "context-$arch"
101 done
102 docker buildx imagetools create -t "$IMAGE:$version" -t "$IMAGE:latest" "$IMAGE:$version-amd64" "$IMAGE:$version-arm64"