Files
routstrd/.github/workflows/release.yml
T
redshift f5c257674f feat(release): add install.sh for standalone binaries
Standalone installs previously required downloading a release tarball,
checking SHA256SUMS, extracting and installing by hand. Add a POSIX shell
installer, published as a release asset so `releases/latest/download/`
always serves the current one:

    curl -fsSL https://github.com/Routstr/routstrd/releases/latest/download/install.sh | sh

The installer detects platform and architecture, resolves the latest
version from the GitHub API (or takes --version), verifies the archive
against the release SHA256SUMS, and only replaces the installed executable
after the checksum matches. It needs only sh, tar, curl/wget and a SHA256
tool -- no Bun, Node.js or npm.

The release job now checks out the repo, smoke tests install.sh against the
artifacts it just built by serving them locally, and attaches install.sh to
the GitHub Release.

Tests cover asset-name parity with releaseArchiveName, version/platform
validation, and end-to-end installs against a fake release server including
checksum mismatch, missing asset and missing SHA256SUMS failure paths.
2026-09-10 17:04:02 +02:00

133 lines
4.0 KiB
YAML

name: Release
on:
pull_request:
workflow_dispatch:
push:
tags:
- "v*"
permissions:
contents: read
jobs:
validate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- uses: oven-sh/setup-bun@v2
with:
bun-version: 1.4.0
- run: bun install --frozen-lockfile
- name: Verify tag version
if: startsWith(github.ref, 'refs/tags/v')
run: |
package_version="$(bun -p "require('./package.json').version")"
test "${GITHUB_REF_NAME}" = "v${package_version}"
- run: bun run lint
- run: bun test
build:
needs: validate
strategy:
fail-fast: false
matrix:
include:
- runner: ubuntu-24.04
target: bun-linux-x64
platform: linux
arch: x64
- runner: ubuntu-24.04-arm
target: bun-linux-arm64
platform: linux
arch: arm64
- runner: macos-15-intel
target: bun-darwin-x64
platform: darwin
arch: x64
- runner: macos-15
target: bun-darwin-arm64
platform: darwin
arch: arm64
runs-on: ${{ matrix.runner }}
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- uses: oven-sh/setup-bun@v2
with:
bun-version: 1.4.0
- run: bun install --frozen-lockfile
- name: Build standalone executable
run: >-
bun build --compile
--target=${{ matrix.target }}
--no-compile-autoload-dotenv
--no-compile-autoload-bunfig
src/index.ts
--outfile=build/routstrd
- name: Smoke test executable
run: |
package_version="$(bun -p "require('./package.json').version")"
test "$(build/routstrd --version)" = "${package_version}"
build/routstrd --help >/dev/null
- name: Package executable
run: |
package_version="$(bun -p "require('./package.json').version")"
tar -C build -czf \
"routstrd-v${package_version}-${{ matrix.platform }}-${{ matrix.arch }}.tar.gz" \
routstrd
- uses: actions/upload-artifact@v4
with:
name: routstrd-${{ matrix.platform }}-${{ matrix.arch }}
path: routstrd-*.tar.gz
if-no-files-found: error
release:
if: startsWith(github.ref, 'refs/tags/v')
needs: build
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- uses: actions/download-artifact@v4
with:
pattern: routstrd-*
merge-multiple: true
- name: Create checksums
run: shasum -a 256 routstrd-*.tar.gz > SHA256SUMS
- name: Serve artifacts for installer smoke test
run: |
version="${GITHUB_REF_NAME#v}"
mkdir -p "serve/v${version}"
cp "routstrd-v${version}-linux-x64.tar.gz" SHA256SUMS "serve/v${version}/"
- name: Smoke test install.sh against the built artifacts
run: |
version="${GITHUB_REF_NAME#v}"
python3 -m http.server 8137 --bind 127.0.0.1 --directory serve &
server_pid=$!
trap 'kill "${server_pid}"' EXIT
sleep 1
sh install.sh \
--version "${version}" \
--platform linux \
--arch x64 \
--dir /tmp/routstrd-install-smoke \
--download-base-url http://127.0.0.1:8137
test "$(/tmp/routstrd-install-smoke/routstrd --version)" = "${version}"
- name: Publish GitHub Release
env:
GH_TOKEN: ${{ github.token }}
run: >-
gh release create "${GITHUB_REF_NAME}"
routstrd-*.tar.gz SHA256SUMS install.sh
--repo "${GITHUB_REPOSITORY}"
--verify-tag
--generate-notes
--title "${GITHUB_REF_NAME}"