| 1 | # Releases the self-hosted runner, g1t-runner (crates/runner): builds it for |
| 2 | # Linux, macOS and Windows on x64 and arm64, signs the release, publishes it |
| 3 | # to g1t.sh/downloads/runner/ (the g1t-downloads R2 bucket), and pushes its |
| 4 | # container image. Runners already out there update themselves to it. |
| 5 | # |
| 6 | # A release is a tag `runner-v<version>`, where the version is the one in |
| 7 | # crates/runner/Cargo.toml; or run it by hand. scripts/runner-release.mjs |
| 8 | # does the work; docs/DEPLOYING.md, "The self-hosted runner", says how to |
| 9 | # make the release key the first time. |
| 10 | name: Runner release |
| 11 | |
| 12 | on: |
| 13 | push: |
| 14 | tags: ["runner-v*"] |
| 15 | workflow_dispatch: |
| 16 | |
| 17 | concurrency: |
| 18 | group: runner-release |
| 19 | cancel-in-progress: false |
| 20 | |
| 21 | env: |
| 22 | CLOUDFLARE_ACCOUNT_ID: ${{ vars.CLOUDFLARE_ACCOUNT_ID }} |
| 23 | WRANGLER_SEND_METRICS: "false" |
| 24 | |
| 25 | jobs: |
| 26 | binaries: |
| 27 | name: Build, sign and publish |
| 28 | runs-on: ubuntu-latest |
| 29 | environment: production |
| 30 | timeout-minutes: 60 |
| 31 | steps: |
| 32 | - uses: actions/checkout@v5 |
| 33 | - name: The tag names this version |
| 34 | if: startsWith(github.ref, 'refs/tags/runner-v') |
| 35 | run: | |
| 36 | version="$(sed -n 's/^version = "\(.*\)"/\1/p' crates/runner/Cargo.toml | head -1)" |
| 37 | [ "runner-v$version" = "${GITHUB_REF_NAME}" ] || { echo "::error::The tag is ${GITHUB_REF_NAME}, but crates/runner is $version"; exit 1; } |
| 38 | - name: Install zig and cargo-zigbuild |
| 39 | run: | |
| 40 | pip install --user ziglang==0.13.0 |
| 41 | echo "$HOME/.local/bin" >> "$GITHUB_PATH" |
| 42 | cargo install --locked cargo-zigbuild |
| 43 | - uses: actions/cache@v4 |
| 44 | with: |
| 45 | path: | |
| 46 | ~/.cargo/registry |
| 47 | target |
| 48 | key: runner-release-${{ hashFiles('Cargo.lock') }} |
| 49 | - name: Build every platform |
| 50 | env: |
| 51 | G1T_RUNNER_RELEASE_KEY: ${{ vars.RUNNER_RELEASE_PUBLIC_KEY }} |
| 52 | RUNNER_AGENT_IMAGE: ${{ vars.RUNNER_AGENT_IMAGE }} |
| 53 | run: node scripts/runner-release.mjs build |
| 54 | - name: Sign |
| 55 | env: |
| 56 | RUNNER_RELEASE_KEY: ${{ secrets.RUNNER_RELEASE_KEY }} |
| 57 | G1T_RUNNER_RELEASE_KEY: ${{ vars.RUNNER_RELEASE_PUBLIC_KEY }} |
| 58 | run: | |
| 59 | node scripts/runner-release.mjs sign |
| 60 | node scripts/runner-release.mjs verify |
| 61 | - name: Install Wrangler |
| 62 | run: npm ci --workspaces=false --no-audit --no-fund |
| 63 | - name: Publish to g1t.sh/downloads/runner |
| 64 | env: |
| 65 | CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} |
| 66 | run: node scripts/runner-release.mjs publish |
| 67 | - uses: actions/upload-artifact@v4 |
| 68 | with: |
| 69 | name: linux-binaries |
| 70 | path: | |
| 71 | target/runner-release/*/g1t-runner-linux-x64 |
| 72 | target/runner-release/*/g1t-runner-linux-arm64 |
| 73 | |
| 74 | image: |
| 75 | name: Container image |
| 76 | needs: binaries |
| 77 | # Needs Docker, which g1t's own sandboxes do not have. |
| 78 | runs-on: [self-hosted, docker] |
| 79 | environment: production |
| 80 | timeout-minutes: 30 |
| 81 | steps: |
| 82 | - uses: actions/checkout@v5 |
| 83 | - uses: actions/download-artifact@v4 |
| 84 | with: |
| 85 | name: linux-binaries |
| 86 | path: release |
| 87 | - name: Build and push for amd64 and arm64 |
| 88 | env: |
| 89 | REGISTRY_USER: ${{ vars.RUNNER_IMAGE_REGISTRY_USER }} |
| 90 | REGISTRY_TOKEN: ${{ secrets.RUNNER_IMAGE_REGISTRY_TOKEN }} |
| 91 | IMAGE: ${{ vars.RUNNER_IMAGE }} |
| 92 | run: | |
| 93 | version="$(sed -n 's/^version = "\(.*\)"/\1/p' crates/runner/Cargo.toml | head -1)" |
| 94 | echo "$REGISTRY_TOKEN" | docker login --username "$REGISTRY_USER" --password-stdin |
| 95 | for arch in amd64 arm64; do |
| 96 | mkdir -p "context-$arch" |
| 97 | cp deploy/runner/Dockerfile "context-$arch/" |
| 98 | name="g1t-runner-linux-$([ "$arch" = amd64 ] && echo x64 || echo arm64)" |
| 99 | cp release/*/"$name" "context-$arch/g1t-runner" |
| 100 | docker buildx build --platform "linux/$arch" -t "$IMAGE:$version-$arch" --push "context-$arch" |
| 101 | done |
| 102 | docker buildx imagetools create -t "$IMAGE:$version" -t "$IMAGE:latest" "$IMAGE:$version-amd64" "$IMAGE:$version-arm64" |