-
Notifications
You must be signed in to change notification settings - Fork 67
137 lines (125 loc) · 5.29 KB
/
Copy pathrelease.yml
File metadata and controls
137 lines (125 loc) · 5.29 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
name: release
on:
push:
tags:
- "v*"
workflow_dispatch:
permissions:
contents: write
jobs:
release:
name: release
runs-on: ubuntu-latest
concurrency: release-${{ github.ref }}
# belt and braces over quill's own notary bound, which is already firm:
# notary.PollStatus wraps the poll loop in context.WithTimeout, and
# status.timeout-seconds defaults to 900s. this only keeps a hang elsewhere
# in the job (build, upload, tap pr) from holding the concurrency lock for
# the default 6h and blocking a retry.
#
# quill's 900s notary timeout has a hard ceiling above it: quill mints one
# app store connect jwt up front with exp = timeout + 2m and never refreshes
# it (quill/notarize.go WithStatusConfig -> notary.NewSignedToken), and apple
# rejects notary tokens with a lifetime over 20 minutes. so anything above
# 1080s (18m) is a guaranteed 401 -- the 2400s that looks reasonable for a
# slow first submission cannot work. if apple does exceed the timeout,
# re-run the workflow; quill has no resume, so it re-signs and resubmits
# from scratch (and each signing run embeds a fresh apple timestamp, so the
# bytes and the hash differ every time).
timeout-minutes: 45
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
ref: ${{ github.ref }} # build the tagged commit
- name: Generate homebrew tap token
id: app-token
uses: actions/create-github-app-token@v1
with:
app-id: ${{ secrets.RELEASE_APP_ID }}
private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }}
owner: runpod
repositories: homebrew-runpodctl
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version: "1.26.6"
# the release tarball is pinned by version *and* sha256, and installed
# without piping anything to a shell. this job receives the developer id
# p12 and the notary key, so an unverified installer running as root here
# is a direct exfiltration path for the signing identity. the checksum
# also makes an upstream regression a loud install failure rather than a
# quietly different signature.
# bump both values together, from quill_<version>_checksums.txt.
# names are deliberately not QUILL_*: quill itself reads QUILL_<section>_<key>
# from the environment, so keeping install vars out of that prefix stops a
# future rename from silently reconfiguring the signer.
- name: Install quill
env:
PIN_QUILL_VERSION: 0.7.1
PIN_QUILL_SHA256: e58c6f86378a22507c1123e24412afd4ee2d3bb32ebd94d6059827dc0c1b3fbf
run: |
set -euo pipefail
# a scratch dir, not the workspace: goreleaser's non-snapshot run fails
# on a dirty git tree, so a leftover download would break the release
# with an unrelated error message.
workdir="$(mktemp -d)"
tarball="${workdir}/quill_${PIN_QUILL_VERSION}_linux_amd64.tar.gz"
curl -sSfL --retry 3 -o "$tarball" \
"https://github.com/anchore/quill/releases/download/v${PIN_QUILL_VERSION}/quill_${PIN_QUILL_VERSION}_linux_amd64.tar.gz"
echo "${PIN_QUILL_SHA256} ${tarball}" | sha256sum --check --strict -
tar -xzf "$tarball" -C "$workdir" quill
sudo install -m 0755 "${workdir}/quill" /usr/local/bin/quill
rm -rf "$workdir"
quill version
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@v6
with:
# pinned now that goreleaser drives signing: with `latest`, an upstream
# release can change the signing chain (hook ordering, universal binary
# handling) between two tags of ours with no change on our side.
version: v2.17.1
args: release --clean
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
HOMEBREW_TAP_TOKEN: ${{ steps.app-token.outputs.token }}
QUILL_SIGN_P12: ${{ secrets.QUILL_SIGN_P12 }}
QUILL_SIGN_PASSWORD: ${{ secrets.QUILL_SIGN_PASSWORD }}
QUILL_NOTARY_KEY: ${{ secrets.QUILL_NOTARY_KEY }}
QUILL_NOTARY_KEY_ID: ${{ secrets.QUILL_NOTARY_KEY_ID }}
QUILL_NOTARY_ISSUER: ${{ secrets.QUILL_NOTARY_ISSUER }}
# Linear release tracking. Only runs for tag pushes, not manual dispatch.
linear-sync:
name: Linear Release Sync
needs: release
if: startsWith(github.ref, 'refs/tags/')
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: linear/linear-release-action@v0
with:
access_key: ${{ secrets.LINEAR_RELEASE_ACCESS_KEY }}
command: sync
version: ${{ github.ref_name }}
name: runpodctl ${{ github.ref_name }}
linear-complete:
name: Linear Release Complete
needs: [release, linear-sync]
if: startsWith(github.ref, 'refs/tags/')
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: linear/linear-release-action@v0
with:
access_key: ${{ secrets.LINEAR_RELEASE_ACCESS_KEY }}
command: complete
version: ${{ github.ref_name }}