release: one-command build, sign, publish, and attach — plus dormant workflow (#52)
Implements the full release flow: a single script builds both deb and rpm packages, signs the RPM payload, generates and clearsigns SHA256SUMS, uploads to the Gitea package registry (deb to bookworm/jammy/noble pools, rpm to the fenris group), creates a Gitea release entry with notes, and attaches all artifacts. Key changes: - scripts/release.sh: new release script with --dry-run and --publish modes - tests/test_release.py: 32 structural tests (dry-run output, filenames, revision bumping, bare tag prevention, CI workflow, Makefile targets) - Makefile: added release-run and release-dry-run targets - .gitea/workflows/release.yml: extended dormant workflow with signing, upload, release creation, and artifact attachment (idempotent re-runs) - docs/install/signing-key-ceremony.md: added one-time live probe section documenting throwaway package publish, apt/dnf verification, and cleanup Acceptance criteria met: - One release command performs build, sign, publish, and attach - Dry-run mode prints every command; tests assert output without network - Revision bumping on 409 (same-version rebuilds increment release number) - Dormant CI workflow replicates the flow (queues harmlessly without runner) - Live probe documented with throwaway package end-to-end - No bare tags: release API creates tag atomically with release entry Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
co-authored by
CommandCodeBot
parent
d8fa6df072
commit
120d80b28c
@@ -132,3 +132,99 @@ verification is manual for downloaded assets:
|
||||
gpg --verify SHA256SUMS.asc SHA256SUMS
|
||||
sha256sum -c SHA256SUMS
|
||||
```
|
||||
|
||||
## One-time live probe
|
||||
|
||||
Before the first real release, verify the full registry path end-to-end with a
|
||||
throwaway package. This confirms apt/dnf metadata generation, signature
|
||||
verification, and consumer setup work as a real consumer would experience them.
|
||||
|
||||
### Setup
|
||||
|
||||
```bash
|
||||
# Create a throwaway package name to avoid polluting fenris metadata
|
||||
PROBE_NAME="fenris-regtest"
|
||||
PROBE_VERSION="0.0.1"
|
||||
```
|
||||
|
||||
### Publish
|
||||
|
||||
```bash
|
||||
# Build a throwaway deb and rpm (use the existing nfpm config with a dummy name)
|
||||
# Or use a pre-built package — the probe tests the registry path, not the build
|
||||
|
||||
# Upload deb to all codename pools
|
||||
for CODENAME in bookworm jammy noble; do
|
||||
curl --fail -X PUT \
|
||||
-u "xavierk:${GITEA_TOKEN}" \
|
||||
-T "dist/${PROBE_NAME}_${PROBE_VERSION}_amd64.deb" \
|
||||
"https://git.bongbetic.com/api/packages/xavierk/debian/pool/${CODENAME}/main/upload"
|
||||
done
|
||||
|
||||
# Upload rpm
|
||||
curl --fail -X PUT \
|
||||
-u "xavierk:${GITEA_TOKEN}" \
|
||||
-T "dist/${PROBE_NAME}-${PROBE_VERSION}-1.x86_64.rpm" \
|
||||
"https://git.bongbetic.com/api/packages/xavierk/rpm/fenris/upload"
|
||||
```
|
||||
|
||||
### Verify apt metadata (Debian/Ubuntu consumer perspective)
|
||||
|
||||
```bash
|
||||
# On a Debian/Ubuntu machine:
|
||||
sudo mkdir -p /etc/apt/keyrings
|
||||
sudo curl -fsSL https://git.bongbetic.com/api/packages/xavierk/debian/repository.key \
|
||||
| sudo gpg --dearmor -o /etc/apt/keyrings/gitea-xavierk.asc
|
||||
|
||||
echo "deb [signed-by=/etc/apt/keyrings/gitea-xavierk.asc] https://git.bongbetic.com/api/packages/xavierk/debian bookworm main" \
|
||||
| sudo tee /etc/apt/sources.list.d/fenris.list
|
||||
|
||||
sudo apt update
|
||||
apt show ${PROBE_NAME} # metadata present, correct version
|
||||
apt install --dry-run ${PROBE_NAME} # dependency resolution works
|
||||
|
||||
# Verify InRelease signature
|
||||
apt-key list 2>/dev/null || gpg --no-default-keyring --keyring /etc/apt/keyrings/gitea-xavierk.asc --list-keys
|
||||
```
|
||||
|
||||
### Verify dnf metadata (Fedora consumer perspective)
|
||||
|
||||
```bash
|
||||
# On a Fedora machine:
|
||||
sudo dnf config-manager --add-repo https://git.bongbetic.com/xavierk/Fenris/raw/branch/main/packaging/fenris.repo
|
||||
# Or use Gitea's auto-generated repo for the probe:
|
||||
sudo dnf config-manager --add-repo https://git.bongbetic.com/api/packages/xavierk/rpm/fenris.repo
|
||||
|
||||
dnf info ${PROBE_NAME} # metadata present, correct version
|
||||
dnf install --assumeno ${PROBE_NAME} # dependency resolution works
|
||||
|
||||
# Verify rpm signature
|
||||
rpm -q --scripts ${PROBE_NAME} # no scripts (throwaway)
|
||||
```
|
||||
|
||||
### Verify checksums and clearsign
|
||||
|
||||
```bash
|
||||
# Download from release assets or local build
|
||||
gpg --verify SHA256SUMS.asc SHA256SUMS
|
||||
sha256sum -c SHA256SUMS
|
||||
```
|
||||
|
||||
### Cleanup
|
||||
|
||||
```bash
|
||||
# Delete the throwaway packages from the registry
|
||||
for CODENAME in bookworm jammy noble; do
|
||||
curl --fail -X DELETE \
|
||||
-u "xavierk:${GITEA_TOKEN}" \
|
||||
"https://git.bongbetic.com/api/packages/xavierk/debian/pool/${CODENAME}/main/${PROBE_NAME}/${PROBE_VERSION}/amd64"
|
||||
done
|
||||
|
||||
curl --fail -X DELETE \
|
||||
-u "xavierk:${GITEA_TOKEN}" \
|
||||
"https://git.bongbetic.com/api/packages/xavierk/rpm/fenris/${PROBE_NAME}/${PROBE_VERSION}/x86_64"
|
||||
|
||||
# Remove test source list on consumer machines
|
||||
sudo rm /etc/apt/sources.list.d/fenris.list
|
||||
sudo apt update
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user