Repository navigation
125 lines (125 loc) · 4.49 KB
/
Copy pathrelease.yaml
File metadata and controls
125 lines (125 loc) · 4.49 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
# Build and publish a source archive and Rust binaries for a tagged release.
# Unit, lint, and tooling tests run here; //tests:e2e_test runs in ci.yaml.
name: Release
on:
workflow_dispatch:
inputs:
tag_name:
description: Git tag being released
required: true
type: string
push:
tags:
- "v*.*.*"
permissions:
id-token: write
attestations: write
contents: write
jobs:
release:
uses: bazel-contrib/.github/.github/workflows/release_ruleset.yaml@v7.4.0
with:
release_files: archives/*.*
# Exclude the nested-Bazel E2E suite. The reusable workflow appends cache
# flags, so this command must not end with a `--` target terminator.
bazel_test_command: >-
bazel test //src/... //tools/... //:rust_clippy_check //:rust_format_check
--build_tests_only --test_output=errors
prerelease: false
draft: true
tag_name: ${{ inputs.tag_name || github.ref_name }}
permissions:
id-token: write # Needed to attest provenance
attestations: write # Needed to attest provenance
contents: write # Needed to upload release files
secrets: {}
publish:
needs: release
uses: ./.github/workflows/publish.yaml
with:
tag_name: ${{ inputs.tag_name || github.ref_name }}
secrets:
BCR_PUBLISH_TOKEN: ${{ secrets.BCR_PUBLISH_TOKEN }}
rust-binaries:
needs: release
runs-on: ${{ matrix.os }}
permissions:
contents: write
strategy:
fail-fast: false
matrix:
# Keep build flags in sync with `release-artifacts` in ci.yaml.
# Linux configs use musl; arm64 is cross-compiled on Ubuntu.
include:
- os: ubuntu-latest
asset: bazel-diff-rust-linux-amd64
release_config: release-linux
bazel_startup_flags: ""
bazel_extra_flags: ""
- os: ubuntu-latest
asset: bazel-diff-rust-linux-arm64
release_config: release-linux-arm64
bazel_startup_flags: ""
bazel_extra_flags: ""
- os: macos-latest
asset: bazel-diff-rust-macos-arm64
release_config: release
bazel_startup_flags: ""
bazel_extra_flags: ""
- os: windows-latest
asset: bazel-diff-rust-windows-amd64.exe
release_config: release
bazel_startup_flags: "--output_base=C:/b"
bazel_extra_flags: "--legacy_external_runfiles"
steps:
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ inputs.tag_name || github.ref_name }}
- name: Setup Go environment
uses: actions/setup-go@v5
with:
go-version: ^1.17
- name: Setup Bazelisk (Linux/macOS)
if: runner.os != 'Windows'
run: |
go install github.com/bazelbuild/bazelisk@latest
echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH"
- name: Setup Bazelisk (Windows)
if: runner.os == 'Windows'
shell: pwsh
run: |
go install github.com/bazelbuild/bazelisk@latest
echo "$(go env GOPATH)\bin" | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append
# .bazelrc defines release configs; //release:bazel-diff-rust names assets.
- name: Build Rust binary
shell: bash
env:
# Prevent Git Bash from rewriting Bazel target labels as Windows paths.
MSYS2_ARG_CONV_EXCL: '//'
run: bazelisk ${{ matrix.bazel_startup_flags }} build //release:bazel-diff-rust --config=${{ matrix.release_config }} ${{ matrix.bazel_extra_flags }}
- name: Check Linux static linking
if: runner.os == 'Linux'
run: .github/workflows/assert_static_binary.sh "bazel-bin/release/${{ matrix.asset }}"
- name: Run Linux release binary
if: matrix.asset == 'bazel-diff-rust-linux-amd64'
run: bazel-bin/release/${{ matrix.asset }} --version
- name: Upload release asset
shell: bash
env:
TAG: ${{ inputs.tag_name || github.ref_name }}
GH_TOKEN: ${{ github.token }}
run: |
gh release upload "$TAG" "bazel-bin/release/${{ matrix.asset }}" \
--clobber \
--repo "$GITHUB_REPOSITORY"
finalize:
needs: [publish, rust-binaries]
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- run: gh release edit "$TAG" --draft=false --repo "$GITHUB_REPOSITORY"
env:
TAG: ${{ inputs.tag_name || github.ref_name }}
GH_TOKEN: ${{ github.token }}