mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
Tagged releases need installable artifacts whose source and embedded revision are pinned to the pushed tag, without requiring operators to have Rust or Nix on the deployment host. Add a Linux pkgsStatic output and a v* ngit-ci workflow that verifies the tag against Cargo package metadata, builds the x86_64 MUSL binary, creates a reproducible licensed archive and SHA256SUMS, and uploads both as release assets. Derive the Nix package version from Cargo.toml so release validation has one authoritative version. The first artifact target assumes x86_64 Linux and the existing tag-trigger environment provided by ngit-ci. Multi-architecture archives, OCI publication, release tagging, and the separate v3 metadata promotion are deliberately excluded. Validated with a staged-tree nix build .#static, static PIE and embedded-revision inspection, an archive/checksum round trip, nix flake check --no-build --no-write-lock-file, cargo metadata, and git diff --check.
62 lines
2.2 KiB
YAML
62 lines
2.2 KiB
YAML
on:
|
|
push:
|
|
tags: ["v*"]
|
|
|
|
name: release assets
|
|
|
|
jobs:
|
|
linux-x86_64:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 60
|
|
steps:
|
|
- uses: actions/checkout@v5
|
|
- uses: cachix/install-nix-action@v31
|
|
with:
|
|
nix_path: nixpkgs=channel:nixos-unstable
|
|
- name: Restore Nix store cache
|
|
continue-on-error: true
|
|
uses: nix-community/cache-nix-action@v7
|
|
with:
|
|
primary-key: release-nix-${{ runner.os }}-${{ hashFiles('**/*.nix', 'flake.lock') }}
|
|
restore-prefixes-first-match: release-nix-${{ runner.os }}-
|
|
# cache-nix-action requires a token even with purge disabled;
|
|
# github.token is empty under ngit-ci, so any non-empty value works.
|
|
token: unused
|
|
- name: Build static binary
|
|
run: nix build .#static --out-link result-static
|
|
- name: Package release assets
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
version="${GITHUB_REF_NAME#v}"
|
|
if [[ -z "$version" || "$version" == *[!A-Za-z0-9._+-]* ]]; then
|
|
echo "unsupported release version from tag: $GITHUB_REF_NAME" >&2
|
|
exit 1
|
|
fi
|
|
package_version="$(nix eval --raw .#static.version)"
|
|
if [[ "$version" != "$package_version" ]]; then
|
|
echo "tag version $version does not match package version $package_version" >&2
|
|
exit 1
|
|
fi
|
|
|
|
target="x86_64-unknown-linux-musl"
|
|
archive="ngit-grasp-${version}-${target}"
|
|
source_date_epoch="$(git show -s --format=%ct "$GITHUB_SHA")"
|
|
|
|
install -Dm755 result-static/bin/ngit-grasp \
|
|
"release-stage/${archive}/ngit-grasp"
|
|
install -Dm644 LICENSE "release-stage/${archive}/LICENSE"
|
|
|
|
mkdir -p dist
|
|
tar --sort=name --mtime="@${source_date_epoch}" \
|
|
--owner=0 --group=0 --numeric-owner -C release-stage \
|
|
-czf "dist/${archive}.tar.gz" "$archive"
|
|
(cd dist && sha256sum ./*.tar.gz > SHA256SUMS)
|
|
- name: Upload release assets
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: ngit-grasp-release-assets
|
|
path: dist/*
|
|
if-no-files-found: error
|