Skip to content

Align with commercial build support - #1537

Merged
artembilan merged 3 commits into
spring-projects:mainfrom
sobychacko:align-commercial-build-support
Aug 6, 2026
Merged

artembilan merged 3 commits into
spring-projects:mainfrom
sobychacko:align-commercial-build-support

Conversation

@sobychacko

Copy link
Copy Markdown
Collaborator

Align spring-pulsar's Gradle and CI setup with spring-pulsar-commercial so
the same workflow files and build scripts can run, largely unmodified, in
both repositories.

  • Add an isCI Gradle variable in a buildscript block and conditionally
    apply a new commercial-settings.gradle when the COMMERCIAL environment
    variable is set (i.e. only in the commercial repository). Inert in OSS.
  • commercial-settings.gradle resolves artifacts from the enterprise
    Artifactory repositories in CI, falling back to the spring-commercial
    remote for local development.
  • Recognize *.x-internal maintenance branches alongside main and *.x
    in the CI-triggering workflows (ci.yml, ci-pr.yml).
  • Relax the repository guard from github.repository == spring-projects/ spring-pulsar to github.repository_owner == spring-projects so CI also
    runs in the commercial repository.
  • Introduce a vars.COMMERCIAL repository variable as the single source of
    truth for repo-specific behavior: it selects the Artifactory URL/repository
    for snapshot deployment and, together with COMMERCIAL_ARTIFACTORY_*
    secret fallbacks, the deploy credentials.
  • Gate the OSS-only deploy_docs_antora and Maven Central perform_release
    jobs on !vars.COMMERCIAL; commercial docs and releases are handled by the
    release-train workflows.
  • Add release-train automation workflows (release-train-build/join/leave/
    ready/retry/test) and their composite actions, plus a post-release.yml
    gated on vars.COMMERCIAL, and the .github/workflow-generator.yml config.

Signed-off-by: Soby Chacko soby.chacko@broadcom.com

Align spring-pulsar's Gradle and CI setup with spring-pulsar-commercial so
the same workflow files and build scripts can run, largely unmodified, in
both repositories.

- Add an `isCI` Gradle variable in a buildscript block and conditionally
  apply a new `commercial-settings.gradle` when the `COMMERCIAL` environment
  variable is set (i.e. only in the commercial repository). Inert in OSS.
- `commercial-settings.gradle` resolves artifacts from the enterprise
  Artifactory repositories in CI, falling back to the spring-commercial
  remote for local development.
- Recognize `*.x-internal` maintenance branches alongside `main` and `*.x`
  in the CI-triggering workflows (ci.yml, ci-pr.yml).
- Relax the repository guard from `github.repository == spring-projects/
  spring-pulsar` to `github.repository_owner == spring-projects` so CI also
  runs in the commercial repository.
- Introduce a `vars.COMMERCIAL` repository variable as the single source of
  truth for repo-specific behavior: it selects the Artifactory URL/repository
  for snapshot deployment and, together with `COMMERCIAL_ARTIFACTORY_*`
  secret fallbacks, the deploy credentials.
- Gate the OSS-only `deploy_docs_antora` and Maven Central `perform_release`
  jobs on `!vars.COMMERCIAL`; commercial docs and releases are handled by the
  release-train workflows.
- Add release-train automation workflows (release-train-build/join/leave/
  ready/retry/test) and their composite actions, plus a `post-release.yml`
  gated on `vars.COMMERCIAL`, and the `.github/workflow-generator.yml` config.

Signed-off-by: Soby Chacko <soby.chacko@broadcom.com>
@sobychacko
sobychacko requested a review from artembilan August 4, 2026 19:30

@artembilan artembilan left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for doing this, Soby!

But as we have discussed many times: it is not that easy since the project diverges from our experience in other projects.

Let's hope we can nail it anyway!

Comment thread .github/workflows/post-release.yml Outdated

jobs:
release:
# Commercial-only: in OSS, post-release automation runs inside ci.yml's perform_release job.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is correct.
The ci.yml is not use for release anymore.
The tag is going to be pushed to repository by the Orchestrator.
Therefore, on: push: tags: is still valid, and this condition is wrong.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

maybe we should eventually drop the perfom_release from ci.yml.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think that should be a separate task.
For now we need to assume that release-related code in the ci.yml is dead because we are not going to release manually anymore.

contents: write
issues: write

uses: spring-io/spring-github-workflows/.github/workflows/spring-post-release.yml@main

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We need to double check if the logic in that spring-post-release.yml is valid for this project: https://github.com/spring-io/spring-github-workflows/blob/main/.github/workflows/spring-post-release.yml

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me from what i can see.

uses: "actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95" # v5.6.0
with:
distribution: "liberica"
java-version: "17"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the copy/paste artifact.
According to the generator has to be Java 25.
I see the same problem in SA, SK & SI.
Will fix there shortly.

Thank you for doing this, so we spot problems on review! 😄

Comment thread build.gradle Outdated
// Commercial build support: applied only when the COMMERCIAL repository variable is
// propagated into the environment (i.e. in the spring-pulsar-commercial repository).
// Inert in OSS builds where COMMERCIAL is unset.
if (System.getenv('COMMERCIAL')) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah... This feels a bit fragile.
I my understand why you cannot rely on the ARTIFACTORY_USERNAME like we do in other projects but then this COMMERCIAL has to be propagated in more places to the ENV.
SNAPSHOT build, PR build, release train build and test.

Or... the logic in those workflows has to be revisited to not use ARTIFACTORY_USERNAME...

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I tried to rework it so that it is now gated on the ARTIFACTORY_USERNAME condition.

Align with the sibling Spring projects (spring-kafka, spring-amqp,
spring-integration) instead of the bespoke COMMERCIAL env-var mechanism.

- Gate commercial-settings.gradle on ARTIFACTORY_USERNAME, apply it via
  ${rootProject.projectDir}, and add the isDependabotPr guard. Presence of
  the commercial credential is now the single trigger, so the release-train
  build/test workflows (which already export it) need no further changes.
- Source ARTIFACTORY_USERNAME/PASSWORD from the COMMERCIAL_* secrets in
  ci.yml and ci-pr.yml (empty in OSS, so the settings stay inert there),
  keeping the OSS snapshot-deploy gate via a step-scoped fallback. Drop the
  now-unused COMMERCIAL env var; vars.COMMERCIAL still drives the
  workflow-level switches.
- Drop the vars.COMMERCIAL gate from post-release.yml so it runs on v* tag
  push in both repositories.
- Fix the release-train Java version (17 -> 25) in release-train-test.yml.

Signed-off-by: Soby Chacko <soby.chacko@broadcom.com>
Only the read-only artifactory secrets are available to PR builds, so
source ARTIFACTORY_USERNAME/PASSWORD from those in ci-pr.yml. Aligns with
the sibling projects.

Signed-off-by: Soby Chacko <soby.chacko@broadcom.com>
@artembilan artembilan added this to the 2.0.7 milestone Aug 6, 2026
@artembilan artembilan added the theme: build An issue relating to our own build label Aug 6, 2026
@artembilan
artembilan merged commit 293bad6 into spring-projects:main Aug 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

theme: build An issue relating to our own build

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants