Skip to content

g1t/.g1t/workflows/runner-release.yml

109 lines4,200 bytesCodeBlameRaw
1# Releases the self-hosted runner, g1t-runner (crates/runner): builds it for
2# Linux, macOS and Windows on x64 and arm64, signs the release, publishes it
3# to g1t.sh/downloads/runner/ (the g1t-downloads R2 bucket), and pushes its
4# container image. Runners already out there update themselves to it.
5#
6# A release is a tag `runner-v<version>`, where the version is the one in
7# crates/runner/Cargo.toml; or run it by hand. scripts/runner-release.mjs
8# does the work; docs/DEPLOYING.md, "The self-hosted runner", says how to
9# make the release key the first time.
10name: Runner release
11
12on:
13 push:
14 tags: ["runner-v*"]
15 workflow_dispatch:
16
17permissions:
18 contents: read
19
20concurrency:
21 group: runner-release
22 cancel-in-progress: false
23
24env:
25 CLOUDFLARE_ACCOUNT_ID: ${{ vars.CLOUDFLARE_ACCOUNT_ID }}
26 WRANGLER_SEND_METRICS: "false"
27
28jobs:
29 binaries:
30 name: Build, sign and publish
31 runs-on: ubuntu-latest
32 environment: production
33 timeout-minutes: 60
34 steps:
35 - uses: actions/checkout@v5
36 - name: The tag names this version
37 if: startsWith(github.ref, 'refs/tags/runner-v')
38 run: |
39 version="$(sed -n 's/^version = "\(.*\)"/\1/p' crates/runner/Cargo.toml | head -1)"
40 [ "runner-v$version" = "${GITHUB_REF_NAME}" ] || { echo "::error::The tag is ${GITHUB_REF_NAME}, but crates/runner is $version"; exit 1; }
41 - name: Install zig and cargo-zigbuild
42 run: |
43 pip install --user ziglang==0.13.0
44 echo "$HOME/.local/bin" >> "$GITHUB_PATH"
45 cargo install --locked cargo-zigbuild
46 - uses: actions/cache@v4
47 with:
48 path: |
49 ~/.cargo/registry
50 target
51 key: runner-release-${{ hashFiles('Cargo.lock') }}
52 - name: Build every platform
53 env:
54 G1T_RUNNER_RELEASE_KEY: ${{ vars.RUNNER_RELEASE_PUBLIC_KEY }}
55 RUNNER_AGENT_IMAGE: ${{ vars.RUNNER_AGENT_IMAGE }}
56 run: node scripts/runner-release.mjs build
57 - name: Sign
58 env:
59 RUNNER_RELEASE_KEY: ${{ secrets.RUNNER_RELEASE_KEY }}
60 G1T_RUNNER_RELEASE_KEY: ${{ vars.RUNNER_RELEASE_PUBLIC_KEY }}
61 run: |
62 node scripts/runner-release.mjs sign
63 node scripts/runner-release.mjs verify
64 - name: Install Wrangler
65 run: npm ci --workspaces=false --no-audit --no-fund
66 - name: Publish to g1t.sh/downloads/runner
67 env:
68 CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
69 run: node scripts/runner-release.mjs publish
70 - uses: actions/upload-artifact@v4
71 with:
72 name: linux-binaries
73 path: |
74 target/runner-release/*/g1t-runner-linux-x64
75 target/runner-release/*/g1t-runner-linux-arm64
76
77 image:
78 name: Container image
79 needs: binaries
80 # Builds for arm64 as well as amd64, which needs QEMU's emulators
81 # registered on the machine: a self-hosted runner's, for now.
82 runs-on: [self-hosted, docker]
83 environment: production
84 timeout-minutes: 30
85 # Its token pushes the image to g1t's registry.
86 permissions:
87 contents: read
88 packages: write
89 steps:
90 - uses: actions/checkout@v5
91 - uses: actions/download-artifact@v4
92 with:
93 name: linux-binaries
94 path: release
95 - name: Build and push for amd64 and arm64
96 # To g1t's own registry, where flagon-io keeps it public.
97 env:
98 IMAGE: g1t.sh/flagon-io/g1t-runner
99 run: |
100 version="$(sed -n 's/^version = "\(.*\)"/\1/p' crates/runner/Cargo.toml | head -1)"
101 echo "${{ secrets.G1T_TOKEN }}" | docker login g1t.sh -u g1t --password-stdin
102 for arch in amd64 arm64; do
103 mkdir -p "context-$arch"
104 cp deploy/runner/Dockerfile "context-$arch/"
105 name="g1t-runner-linux-$([ "$arch" = amd64 ] && echo x64 || echo arm64)"
106 cp release/*/"$name" "context-$arch/g1t-runner"
107 docker buildx build --platform "linux/$arch" -t "$IMAGE:$version-$arch" --push "context-$arch"
108 done
109 docker buildx imagetools create -t "$IMAGE:$version" -t "$IMAGE:latest" "$IMAGE:$version-amd64" "$IMAGE:$version-arm64"