Repository navigation
Historical Artifact Migration: Script Plan #407
Closed
SeanTAllen
started this conversation in
Cloudsmith Migration
Replies: 1 comment
|
Completed. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Plan for the one-off script that moves existing release-channel artifacts from Cloudsmith to GitHub releases. Scoped to workstream 2 of the migration overview in #405 — just the historical binary move. No ponyup code changes, no CI changes, no cutover work.
Principles at play
Goal
For each of the four tool repos, walk Cloudsmith release-channel packages that already have a matching GitHub release tag, and upload the archive plus a generated
.sha512sibling as release assets. Skip anything without a matching GitHub release. Additive only — Cloudsmith is untouched.Per-tool loop
For each of
ponylang/ponyc,ponylang/corral,ponylang/ponyup,ponylang/changelog-tool:gh api /repos/<owner>/<repo>/releases --paginate --jq '.[].tag_name'. Defaultgh release list --limit 30would silently miss tags; ponyc has 100+.packages/ponylang/releases/?query=<tool>%20status:completed— server-side tool-name filter. Loop untilpage > x-pagination-pagetotal(from the response header) or a page returns[]. Page size 100.filenamestarts with<tool>-. Guards against a substring-match surprise. Skip with log if not.skipped (no tag).gh api /repos/<owner>/<repo>/releases/tags/<tag> --jq '.assets[].name'. Per-file check:<archive>.sha512present → skip, logalready present (not verified).cdn_urlwith Cloudsmith auth.checksum_sha512. Mismatch → skip, logfailed (checksum mismatch on download). No upload.<filename>.sha512containing Cloudsmith'schecksum_sha512— raw hex, no re-compute.gh release upload <tag> <archive> <archive>.sha512on the tool's repo.Credentials
public_repo, expiration 1 week. Exported asGH_TOKENfor the invocation only — does not touch the localgh authlogin. Assumption: migration completes inside the PAT's validity window; if a later re-run is needed, mint a new one.CLOUDSMITH_API_KEY. Passed to each download as-H "X-Api-Key: $CLOUDSMITH_API_KEY". Anonymous reads return 402 (bandwidth cap), confirmed empirically, so auth is mandatory.gh api user --jq .login) so the run-results comment can confirmuploaded as ponylang-main.Mechanics
curl+jq+gh.STAGING=$(mktemp -d)— respects$TMPDIR.trap 'rm -rf "$STAGING"' EXIT. Delete each archive right after its upload step so disk usage at any moment is bounded.--dry-runprints the full action list (per package: resolved tag, planned action) without downloading or uploading.--dry-runagainst the smallest population (changelog-tool) first. Eyeball the output. Then real run on that tool. Verify the uploaded assets on its GitHub release. Then repeat for corral, ponyup, ponyc in that order — increasing size.uploaded,uploaded (sibling only),skipped (no tag),skipped (prefix mismatch),already present (not verified),failed (checksum mismatch on download),failed (upload). Counts per tool at the end.Artifacts produced on this discussion
Three comments, posted in this order:
Assumptions to validate at dry-run time
checksum_sha512.versionmatches a GitHubtagNameexactly for the intersection we expect to migrate. All four repos use barex.y.ztoday, and Cloudsmith matches.X-Api-Keyheader works oncdn_urldownloads (Cloudsmith's documented auth method). Probe one archive before the real run.All reactions