name: release on: push: tags: ["v*"] permissions: contents: write env: DL_DIR: /srv/breadway-dl jobs: build: runs-on: [self-hosted, hestia] steps: - uses: actions/checkout@v4 - name: build run: cargo build --release --locked -p bakery - name: test run: cargo test --locked --workspace - name: prepare artifacts run: | VERSION="${GITHUB_REF_NAME#v}" PKG_DIR="${DL_DIR}/bakery/${VERSION}" mkdir -p "${PKG_DIR}" cp target/release/bakery "${PKG_DIR}/bakery-x86_64" strip "${PKG_DIR}/bakery-x86_64" sha256sum "${PKG_DIR}/bakery-x86_64" | awk '{print $1}' \ > "${PKG_DIR}/bakery-x86_64.sha256" cp bakery.toml "${PKG_DIR}/bakery.toml" ln -sfn "${VERSION}" "${DL_DIR}/bakery/latest" # Signs the bakery binary itself with the same minisign key that signs # index.json (get.sh pins the matching public key). Dormant until the # BAKERY_MINISIGN_SEC_KEY secret is actually provisioned in this repo's # Actions settings — until then this step logs a warning and the # binary ships unsigned, exactly as it does today. - name: sign release binary env: MINISIGN_SEC_KEY_CONTENTS: ${{ secrets.BAKERY_MINISIGN_SEC_KEY }} run: | VERSION="${GITHUB_REF_NAME#v}" PKG_DIR="${DL_DIR}/bakery/${VERSION}" if [ -n "${MINISIGN_SEC_KEY_CONTENTS}" ]; then command -v minisign >/dev/null 2>&1 || { echo "::error::minisign not installed on runner"; exit 1; } KEY_FILE="$(mktemp)" trap 'shred -u "${KEY_FILE}" 2>/dev/null || rm -f "${KEY_FILE}"' EXIT printf '%s' "${MINISIGN_SEC_KEY_CONTENTS}" > "${KEY_FILE}" minisign -W -S -s "${KEY_FILE}" -m "${PKG_DIR}/bakery-x86_64" \ -x "${PKG_DIR}/bakery-x86_64.minisig" /dev/null || rm -f "${KEY_FILE}"' EXIT printf '%s' "${MINISIGN_SEC_KEY_CONTENTS}" > "${KEY_FILE}" MINISIGN_SEC_KEY="${KEY_FILE}" bash "${GITHUB_WORKSPACE}/scripts/gen-index.sh" else bash "${GITHUB_WORKSPACE}/scripts/gen-index.sh" fi - name: upload to GitHub Release env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | VERSION="${GITHUB_REF_NAME#v}" PKG_DIR="${DL_DIR}/bakery/${VERSION}" gh release create "${GITHUB_REF_NAME}" \ --title "bakery v${VERSION}" --generate-notes 2>/dev/null || true ASSETS="${PKG_DIR}/bakery-x86_64 ${PKG_DIR}/bakery-x86_64.sha256" [ -f "${PKG_DIR}/bakery-x86_64.minisig" ] && ASSETS="${ASSETS} ${PKG_DIR}/bakery-x86_64.minisig" gh release upload "${GITHUB_REF_NAME}" ${ASSETS} --clobber