Files
antisocial/.gitea/workflows/publish.yml
T
thatguygriffandClaude Opus 5 b94c43a10c Open the version bump as a pull request
The bump job has never once worked. Its first step died in two seconds on
`set: Illegal option -o pipefail` -- it is the only job here that runs in a
container, and a container job is handed `sh -e {0}` rather than the bash the
runner gives its own jobs. Dash has no `pipefail`, and no `10#` either, so the
arithmetic on the line after would have gone the same way. It now asks for
bash, which node:22 carries.

That would have got the job as far as its last step, which pushed straight to
main. Nothing had ever exercised that, and it needs the token to be allowed
past whatever protects the branch -- hence the second token, VERSION_BUMP_TOKEN,
standing by for where it is not. unsupervised-scheduler has been bumping its
version on every release for a while by pushing a branch and opening a pull
request with the ordinary task token, so that is what this does now. The second
token is no longer needed, and neither is `[skip ci]`: main is never pushed, so
there is no build of the just-published image to suppress. The pull request
puts the changed package.json through a build before it lands.

scheduler builds the request body with jq because its CI image carries jq. This
one is node:22, where node is the thing that certainly is there.

Co-Authored-By: Claude Opus 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01XBT25ZDzm453A8XViSRqRB
2026-08-27 20:35:33 -03:00

277 lines
11 KiB
YAML

name: Publish
# Builds the application image and pushes it to a container registry.
#
# push to main -> :main and :sha-<short>
# tag 1.2.3 -> :1.2.3, :1.2, :1 and :latest
# pull request -> builds without pushing, so a broken Dockerfile is
# caught before it can move a published tag
#
# Configure with repository variables and secrets:
#
# vars.REGISTRY required, e.g. registry.example.com
# vars.IMAGE_NAME optional, defaults to this repository's owner/name
# vars.REGISTRY_USER optional, defaults to the actor running the workflow
# secrets.REGISTRY_TOKEN required to push
#
# Point REGISTRY at a host the runner reaches directly, without an intermediate
# proxy that caps request bodies: a browser image has layers well over 100MB,
# and such a proxy rejects them mid-push with `413 Payload Too Large`.
#
# If that host serves plain HTTP, the builder's Docker daemon also needs it in
# `insecure-registries` — that is daemon configuration, not something a
# workflow can set.
on:
push:
branches:
- main
tags:
# Glob, not regex: `[0-9]` is one digit and `*` is the rest, so these
# match 1.2.3 and 1.2.3-rc1 while ignoring tags that are not versions.
# A `+` here would be read as a literal plus.
- '[0-9]*.[0-9]*.[0-9]*'
- 'v[0-9]*.[0-9]*.[0-9]*'
pull_request:
paths:
- 'Dockerfile'
- 'package.json'
- 'package-lock.json'
- '.gitea/workflows/publish.yml'
workflow_dispatch:
jobs:
build:
name: Build and push
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Check the runner can build images
run: |
if ! docker info >/dev/null 2>&1; then
echo "No usable Docker daemon in the job container." >&2
exit 1
fi
docker version --format 'client {{.Client.Version}} / server {{.Server.Version}} / arch {{.Server.Arch}}'
# Images are built natively, so each carries the architecture of the
# runner that built it. A runner of a different architecture joining the
# pool would overwrite these tags with its own arch, at which point this
# needs buildx and a manifest list.
- name: Work out the tags
id: meta
env:
REGISTRY: ${{ vars.REGISTRY }}
IMAGE_NAME: ${{ vars.IMAGE_NAME }}
run: |
set -euo pipefail
if [ -z "${REGISTRY}" ]; then
echo "The REGISTRY repository variable is not set." >&2
echo "Set it to the registry host to publish to, e.g. registry.example.com" >&2
exit 1
fi
image="${REGISTRY}/$(echo "${IMAGE_NAME:-${{ github.repository }}}" | tr '[:upper:]' '[:lower:]')"
tags=""
if [ "${{ github.ref_type }}" = "tag" ]; then
version="${{ github.ref_name }}"
version="${version#v}"
tags="${version}"
# Only a final release moves the rolling aliases; a prerelease is
# published under its own exact version and nothing else.
case "${version}" in
*-*) ;;
*)
major="${version%%.*}"
minor="${version%.*}"
tags="${tags} ${minor} ${major} latest"
;;
esac
else
tags="main sha-$(git rev-parse --short HEAD)"
fi
args=""
for tag in ${tags}; do args="${args} --tag ${image}:${tag}"; done
{
echo "image=${image}"
echo "tags=${tags}"
echo "args=${args}"
} >> "$GITHUB_OUTPUT"
echo "Publishing ${image} as:${tags// /, :}"
# The Actions task token is rejected by some registries, so pushing uses
# a token that belongs to a real user.
- name: Log in to the container registry
if: github.event_name != 'pull_request'
run: |
if [ -z "${{ secrets.REGISTRY_TOKEN }}" ]; then
echo "REGISTRY_TOKEN is not set." >&2
exit 1
fi
if ! echo "${{ secrets.REGISTRY_TOKEN }}" \
| docker login "${{ vars.REGISTRY }}" -u "${{ vars.REGISTRY_USER || github.actor }}" --password-stdin
then
echo >&2
echo "If that failed with 'server gave HTTP response to HTTPS client', the" >&2
echo "registry is plain HTTP and the builder's Docker daemon has to be told" >&2
echo "to allow it: add ${{ vars.REGISTRY }} to insecure-registries in the" >&2
echo "daemon config on the runner. The workflow cannot configure that." >&2
exit 1
fi
- name: Build
run: docker build --pull ${{ steps.meta.outputs.args }} --file Dockerfile .
- name: Push
if: github.event_name != 'pull_request'
run: |
set -euo pipefail
for tag in ${{ steps.meta.outputs.tags }}; do
docker push "${{ steps.meta.outputs.image }}:${tag}"
done
echo "Published ${{ steps.meta.outputs.image }} as: ${{ steps.meta.outputs.tags }}"
- name: Log out
if: always() && github.event_name != 'pull_request'
run: docker logout "${{ vars.REGISTRY }}" || true
# Once a release is out, the version in package.json has already shipped.
# Moving it on to the next patch means the working tree is never sitting on
# a number that is published and immutable, and that a build from main is
# always identifiable as "after 1.2.0" rather than "1.2.0, but not really".
#
# `needs: build` is the point of putting this here rather than in a workflow
# of its own: a version that failed to publish has not been released, and
# bumping past it would say it had.
bump:
name: Move the working version on
needs: build
# Tags only, and only final ones. A prerelease has not shipped the version
# it is a candidate for, so there is nothing yet to move past.
if: github.ref_type == 'tag' && !contains(github.ref_name, '-')
runs-on: ubuntu-latest
# npm does the bump, so this one job wants node. A job in a container is
# given `sh -e {0}` as its shell rather than the bash the runner's own jobs
# get, and dash has neither `pipefail` nor the `10#` below — which failed
# the first line of the first step the one time this ran. node:22 is Debian
# and carries bash, so asking for it keeps these scripts the same as the
# ones in the job above.
container:
image: node:22
defaults:
run:
shell: bash
steps:
# The tag names a commit in main's history, but the bump belongs on the
# branch, so this checks out main rather than the tag. The full history
# because a shallow clone cannot reliably push a branch back.
- uses: actions/checkout@v4
with:
ref: main
fetch-depth: 0
token: ${{ secrets.GITHUB_TOKEN }}
- name: Work out the next patch version
id: next
run: |
set -euo pipefail
version="${{ github.ref_name }}"
version="${version#v}"
major="${version%%.*}"
rest="${version#*.}"
minor="${rest%%.*}"
patch="${rest##*.}"
# `10#` forces base ten: a patch number written 08 would otherwise be
# read as octal and fail to parse.
next="${major}.${minor}.$((10#${patch} + 1))"
echo "next=${next}" >> "$GITHUB_OUTPUT"
echo "Released ${version}; the working version becomes ${next}"
- name: Bump package.json
id: bump
env:
NEXT: ${{ steps.next.outputs.next }}
run: |
set -euo pipefail
current="$(node -p "require('./package.json').version")"
if [ "${current}" = "${NEXT}" ]; then
echo "package.json is already ${NEXT}; nothing to do."
echo "changed=false" >> "$GITHUB_OUTPUT"
exit 0
fi
# npm rather than editing the file: the version is in the lockfile
# too, in more than one place, and they have to agree.
npm version "${NEXT}" --no-git-tag-version --allow-same-version >/dev/null
echo "changed=true" >> "$GITHUB_OUTPUT"
echo "package.json ${current} -> ${NEXT}"
# The bump arrives as a pull request rather than as a commit straight to
# main. Pushing a branch asks nothing of the task token beyond ordinary
# write access, so nothing here depends on being allowed past whatever
# protects main; and the pull request puts the changed package.json
# through the build before it lands. Since main is never pushed, the
# `[skip ci]` that would otherwise be needed to stop this rebuilding the
# image just published is not.
- name: Open a pull request for it
if: steps.bump.outputs.changed == 'true'
env:
NEXT: ${{ steps.next.outputs.next }}
RELEASED: ${{ github.ref_name }}
TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
set -euo pipefail
branch="release/bump-${NEXT}"
# A name that is not a person, and a reserved address that can never
# resolve to one. Nothing here names the instance it runs on.
git config user.name 'Release bot'
git config user.email '[email protected]'
git checkout -b "${branch}"
git add package.json package-lock.json
git commit -m "Set the working version to ${NEXT}"
git push origin "${branch}"
# node rather than jq to build the request body: jq is not in this
# image, and node is the one thing that certainly is.
payload="$(BRANCH="${branch}" node -e 'process.stdout.write(JSON.stringify({
head: process.env.BRANCH,
base: "main",
title: `Set the working version to ${process.env.NEXT}`,
body: `${process.env.RELEASED} has shipped, so the tree was left on a version that is published and immutable. This moves it on to ${process.env.NEXT}, which is deliberately not a version that exists.`,
}))')"
api="${GITHUB_SERVER_URL}/api/v1/repos/${GITHUB_REPOSITORY}"
response="$(mktemp)"
code="$(curl -sS -o "${response}" -w '%{http_code}' \
-X POST "${api}/pulls" \
-H "Authorization: token ${TOKEN}" \
-H 'Content-Type: application/json' \
-d "${payload}")"
case "${code}" in
201) echo "Opened ${branch} against main." ;;
# A release re-run that got this far: the branch and its pull
# request are already there, which is the state we wanted anyway.
409) echo "A pull request for ${branch} is already open." ;;
*)
echo "Could not open the pull request (HTTP ${code}):" >&2
cat "${response}" >&2
exit 1
;;
esac