# Fenris release workflow — dormant (no runner registered yet). # When a runner is provisioned, this replicates `make release` automatically. # Spec: §5, issue #52 name: Release on: push: tags: - 'v*' workflow_dispatch: # Built-in Gitea token needs write access for release assets and package registry. permissions: contents: read releases: write packages: write jobs: release: runs-on: [self-hosted] steps: - uses: actions/checkout@v4 - name: Set up Python uses: actions/setup-python@v5 with: python-version: '3.12' - name: Install build dependencies run: | sudo apt-get update sudo apt-get install -y rpm python3-venv python3 -m venv /tmp/fenris-ci /tmp/fenris-ci/bin/pip install --quiet build echo "/tmp/fenris-ci/bin" >> "$GITHUB_PATH" NFPM_VERSION=2.47.0 curl --fail --silent --show-error --location \ "https://github.com/goreleaser/nfpm/releases/download/v${NFPM_VERSION}/nfpm_${NFPM_VERSION}_Linux_x86_64.tar.gz" \ -o /tmp/nfpm.tar.gz sudo tar -xzf /tmp/nfpm.tar.gz -C /usr/local/bin nfpm nfpm --version - name: Build packages run: make package - name: Sign RPM payload env: GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} run: | echo "$GPG_PRIVATE_KEY" | gpg --batch --import make sign-rpm - name: Generate and clearsign SHA256SUMS run: make clearsign - name: Determine version id: version run: echo "version=$(sed -n 's/^version = "\(.*\)"/\1/p' pyproject.toml)" >> "$GITHUB_OUTPUT" - name: Upload deb packages to registry env: GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} run: | VERSION=${{ steps.version.outputs.version }} DEB="fenris_${VERSION}_amd64.deb" for CODENAME in bookworm jammy noble; do curl --fail -X PUT \ -u "xavierk:${GITEA_TOKEN}" \ -T "dist/${DEB}" \ "https://git.bongbetic.com/api/packages/xavierk/debian/pool/${CODENAME}/main/upload" done - name: Upload RPM to registry env: GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} run: | VERSION=${{ steps.version.outputs.version }} RPM="fenris-${VERSION}-1.x86_64.rpm" curl --fail -X PUT \ -u "xavierk:${GITEA_TOKEN}" \ -T "dist/${RPM}" \ "https://git.bongbetic.com/api/packages/xavierk/rpm/fenris/upload" - name: Create Gitea release env: GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} run: | VERSION=${{ steps.version.outputs.version }} # Check if release already exists (idempotent re-runs) EXISTING=$(curl -s -o /dev/null -w '%{http_code}' \ -u "xavierk:${GITEA_TOKEN}" \ "https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases/tags/v${VERSION}") if [ "$EXISTING" = "200" ]; then echo "Release v${VERSION} already exists, skipping creation" else curl --fail -X POST \ -u "xavierk:${GITEA_TOKEN}" \ -H "Content-Type: application/json" \ -d "{\"tag_name\":\"v${VERSION}\",\"name\":\"v${VERSION}\"}" \ "https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases" fi - name: Attach artifacts to release env: GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} run: | VERSION=${{ steps.version.outputs.version }} # Get release ID for this tag RELEASE_ID=$(curl -s \ -u "xavierk:${GITEA_TOKEN}" \ "https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases/tags/v${VERSION}" \ | python3 -c "import sys,json; print(json.load(sys.stdin)['id'])") # Attach deb, rpm, and clearsigned checksums for FILE in "dist/fenris_${VERSION}_amd64.deb" \ "dist/fenris-${VERSION}-1.x86_64.rpm" \ "dist/SHA256SUMS.asc"; do curl --fail -X POST \ -u "xavierk:${GITEA_TOKEN}" \ -F "attachment=@${FILE}" \ "https://git.bongbetic.com/api/v1/repos/xavierk/Fenris/releases/${RELEASE_ID}/assets" done - name: Upload build artifacts uses: actions/upload-artifact@v4 with: name: fenris-packages path: dist/