f7119e2361
golang:1.25 and the stale almalinux9-gobuilder pin are replaced by gobuilder:0.1.2-alma9 on every step that invokes the Go toolchain, with GOCACHEPROG wired to the baked-in go-cache-plugin against the shared S3 cache bucket. - pre-commit, test, release build/test: image -> gobuilder:0.1.2-alma9 - add GOCACHE_* env + AWS creds from org secrets, absolute cache-dir - lint step (test.yaml), buildx steps, release upload step untouched
102 lines
3.6 KiB
YAML
102 lines
3.6 KiB
YAML
when:
|
|
- event: tag
|
|
ref: refs/tags/v*
|
|
|
|
# Cuts a Gitea release with cross-compiled bootapi binaries attached. The
|
|
# container image is built+pushed separately by docker.yaml.
|
|
steps:
|
|
- name: test
|
|
image: "artifactapi.k8s.syd1.au.unkin.net/docker-internal/gobuilder:0.1.2-alma9"
|
|
environment:
|
|
GOCACHE_S3_BUCKET: gocache
|
|
GOCACHE_S3_REGION: us-east-1
|
|
GOCACHE_S3_ENDPOINT_URL: "https://s3.ceph.unkin.net"
|
|
GOCACHE_S3_PATH_STYLE: "true"
|
|
GOCACHE_KEY_PREFIX: ci-bootapi
|
|
GOCACHEPROG: "go-cache-plugin --cache-dir=/tmp/gocache"
|
|
AWS_ACCESS_KEY_ID:
|
|
from_secret: GOCACHE_AWS_ACCESS_KEY_ID
|
|
AWS_SECRET_ACCESS_KEY:
|
|
from_secret: GOCACHE_AWS_SECRET_ACCESS_KEY
|
|
commands:
|
|
- go test -race ./...
|
|
backend_options:
|
|
kubernetes:
|
|
serviceAccountName: default
|
|
resources:
|
|
requests:
|
|
memory: 512Mi
|
|
cpu: 1
|
|
limits:
|
|
memory: 2Gi
|
|
cpu: 2
|
|
|
|
- name: build
|
|
image: "artifactapi.k8s.syd1.au.unkin.net/docker-internal/gobuilder:0.1.2-alma9"
|
|
environment:
|
|
GOCACHE_S3_BUCKET: gocache
|
|
GOCACHE_S3_REGION: us-east-1
|
|
GOCACHE_S3_ENDPOINT_URL: "https://s3.ceph.unkin.net"
|
|
GOCACHE_S3_PATH_STYLE: "true"
|
|
GOCACHE_KEY_PREFIX: ci-bootapi
|
|
GOCACHEPROG: "go-cache-plugin --cache-dir=/tmp/gocache"
|
|
AWS_ACCESS_KEY_ID:
|
|
from_secret: GOCACHE_AWS_ACCESS_KEY_ID
|
|
AWS_SECRET_ACCESS_KEY:
|
|
from_secret: GOCACHE_AWS_SECRET_ACCESS_KEY
|
|
commands:
|
|
- make release-binaries VERSION=${CI_COMMIT_TAG}
|
|
depends_on: [test]
|
|
backend_options:
|
|
kubernetes:
|
|
serviceAccountName: default
|
|
resources:
|
|
requests:
|
|
memory: 512Mi
|
|
cpu: 1
|
|
limits:
|
|
memory: 2Gi
|
|
cpu: 2
|
|
|
|
- name: release
|
|
image: git.unkin.net/unkin/almalinux9-base:20260606
|
|
environment:
|
|
RELEASER_TOKEN:
|
|
from_secret: RELEASER_TOKEN
|
|
commands:
|
|
- |
|
|
curl --output /usr/local/bin/tea https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/gitea-dl/tea/0.12.0/tea-0.12.0-linux-amd64 && chmod +x /usr/local/bin/tea
|
|
tea logins add --name gitea --url https://git.unkin.net --token "$${RELEASER_TOKEN}" --no-version-check
|
|
# $$ escapes shell vars so Woodpecker doesn't substitute them at parse
|
|
# time; ${CI_COMMIT_TAG}/${CI_REPO} are real Woodpecker vars.
|
|
CUR_SHA=$$(git rev-list -n1 "${CI_COMMIT_TAG}")
|
|
PREV_TAG=""
|
|
for t in $$(git tag --sort=-v:refname); do
|
|
[ "$$t" = "${CI_COMMIT_TAG}" ] && continue
|
|
[ "$$(git rev-list -n1 "$$t")" = "$$CUR_SHA" ] && continue
|
|
if git merge-base --is-ancestor "$$t" "${CI_COMMIT_TAG}" 2>/dev/null; then
|
|
PREV_TAG="$$t"; break
|
|
fi
|
|
done
|
|
if [ -n "$$PREV_TAG" ]; then
|
|
NOTES=$$(git log "$${PREV_TAG}..${CI_COMMIT_TAG}" --pretty=format:"- %s")
|
|
else
|
|
NOTES=$$(git log --pretty=format:"- %s")
|
|
fi
|
|
tea releases create --tag "${CI_COMMIT_TAG}" --title "${CI_COMMIT_TAG}" --note "$${NOTES}" --login gitea --repo "${CI_REPO}"
|
|
ASSETS="dist/bootapi-linux-amd64 dist/bootapi-linux-arm64 dist/bootapi-darwin-amd64 dist/bootapi-darwin-arm64"
|
|
sha256sum $$ASSETS > dist/sha256sums.txt
|
|
tea releases assets create "${CI_COMMIT_TAG}" $$ASSETS dist/sha256sums.txt \
|
|
--login gitea --repo "${CI_REPO}"
|
|
depends_on: [build]
|
|
backend_options:
|
|
kubernetes:
|
|
serviceAccountName: default
|
|
resources:
|
|
requests:
|
|
memory: 128Mi
|
|
cpu: 100m
|
|
limits:
|
|
memory: 512Mi
|
|
cpu: 500m
|