-
Notifications
You must be signed in to change notification settings - Fork 0
104 lines (92 loc) · 3.37 KB
/
Copy pathrelease.yml
File metadata and controls
104 lines (92 loc) · 3.37 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
name: Release Image
on:
push:
tags:
- "v*.*.*"
env:
REGISTRY: ghcr.io
IMAGE_NAME: acornops/execution-engine
# 30 minutes allows full CI completion under occasional queue delays.
CI_GATE_TIMEOUT_MS: 1800000
# 15 seconds balances API polling load with release responsiveness.
CI_GATE_POLL_MS: 15000
jobs:
ci-gate:
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
steps:
- name: Wait for CI workflow success
uses: actions/github-script@v7
with:
script: |
const workflowId = "ci.yml";
const sha = context.sha;
const timeoutMs = Number(process.env.CI_GATE_TIMEOUT_MS);
const pollMs = Number(process.env.CI_GATE_POLL_MS);
const start = Date.now();
while (Date.now() - start < timeoutMs) {
const { data } = await github.rest.actions.listWorkflowRuns({
owner: context.repo.owner,
repo: context.repo.repo,
workflow_id: workflowId,
event: "push",
head_sha: sha,
per_page: 20,
});
const matchingRun = data.workflow_runs
.filter((run) => run.name === "CI")
.sort((a, b) => new Date(b.created_at).getTime() - new Date(a.created_at).getTime())[0];
if (matchingRun) {
core.info(`Found CI run ${matchingRun.id} with status=${matchingRun.status} conclusion=${matchingRun.conclusion}`);
if (matchingRun.status === "completed") {
if (matchingRun.conclusion === "success") {
core.info("CI completed successfully for release commit.");
return;
}
core.setFailed(`Release blocked: CI conclusion is ${matchingRun.conclusion}.`);
return;
}
} else {
core.info("No CI run found yet for this commit.");
}
await new Promise((resolve) => setTimeout(resolve, pollMs));
}
core.setFailed("Release blocked: timed out waiting for CI workflow completion.");
release:
needs: ci-gate
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
- name: Resolve release version
id: version
run: |
VERSION="${GITHUB_REF_NAME#v}"
echo "version=${VERSION}" >> "$GITHUB_OUTPUT"
echo "image=${REGISTRY}/${IMAGE_NAME}:${VERSION}" >> "$GITHUB_OUTPUT"
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to GHCR
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push image
uses: docker/build-push-action@v6
with:
context: .
target: production
push: true
tags: ${{ steps.version.outputs.image }}
labels: |
org.opencontainers.image.source=${{ github.server_url }}/${{ github.repository }}
org.opencontainers.image.version=${{ steps.version.outputs.version }}
provenance: true
sbom: true
cache-from: type=gha
cache-to: type=gha,mode=max