Skip to content

Commit 0ee202c

Browse files
ci: publish GitHub release and GHCR package
1 parent 30e99de commit 0ee202c

1 file changed

Lines changed: 140 additions & 11 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 140 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,26 +1,155 @@
1-
name: Automated Release Engineering
1+
name: Release and Publish Package
22

33
on:
44
push:
55
branches:
66
- main
7+
workflow_dispatch:
8+
inputs:
9+
release_tag:
10+
description: "Semantic version tag to publish (for example v1.1.0)"
11+
required: false
12+
type: string
13+
14+
permissions:
15+
contents: write
16+
packages: write
17+
18+
concurrency:
19+
group: deepsequence-release-${{ github.ref }}
20+
cancel-in-progress: false
21+
22+
env:
23+
IMAGE_NAME: ghcr.io/coreyleath-code/deepsequence-recommender
724

825
jobs:
9-
tagging-engine:
10-
name: Construct Semantic Version Tags
26+
release:
27+
name: Validate, release, and publish GHCR package
28+
if: github.event_name == 'workflow_dispatch' || contains(github.event.head_commit.message, '[release]')
1129
runs-on: ubuntu-latest
12-
permissions:
13-
contents: write
30+
timeout-minutes: 30
1431

1532
steps:
16-
- name: ⬇️ Checkout Repository
33+
- name: Checkout repository
1734
uses: actions/checkout@v4
1835
with:
1936
fetch-depth: 0
2037

21-
- name: 🏷️ Calculate Release Version Alpha
22-
uses: anothrNick/github-tag-action@1.64.0
38+
- name: Set up Python
39+
uses: actions/setup-python@v5
40+
with:
41+
python-version: "3.11"
42+
cache: pip
43+
44+
- name: Resolve immutable release tag
45+
id: version
46+
shell: bash
47+
env:
48+
REQUESTED_TAG: ${{ inputs.release_tag }}
49+
run: |
50+
set -euo pipefail
51+
git fetch --tags --force
52+
53+
if [[ -n "${REQUESTED_TAG:-}" ]]; then
54+
TAG="$REQUESTED_TAG"
55+
else
56+
VERSION="$(python - <<'PY'
57+
import tomllib
58+
with open('pyproject.toml', 'rb') as handle:
59+
print(tomllib.load(handle)['project']['version'])
60+
PY
61+
)"
62+
TAG="v${VERSION}"
63+
fi
64+
65+
if [[ ! "$TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
66+
echo "Release tag must match vMAJOR.MINOR.PATCH; got: $TAG" >&2
67+
exit 1
68+
fi
69+
70+
if git rev-parse -q --verify "refs/tags/$TAG" >/dev/null; then
71+
echo "Using existing immutable tag $TAG for release/package recovery."
72+
else
73+
git config user.name "github-actions[bot]"
74+
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
75+
git tag -a "$TAG" "$GITHUB_SHA" -m "Release $TAG"
76+
git push origin "$TAG"
77+
fi
78+
79+
VERSION="${TAG#v}"
80+
echo "tag=$TAG" >> "$GITHUB_OUTPUT"
81+
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
82+
83+
- name: Check out tagged source
84+
run: git checkout --detach "${{ steps.version.outputs.tag }}"
85+
86+
- name: Install release test dependencies
87+
run: |
88+
python -m pip install --upgrade pip
89+
python -m pip install -r requirements.txt
90+
python -m pip install pytest pytest-cov
91+
92+
- name: Run release test gate
93+
run: pytest --cov=app --cov=src --cov-report=term-missing --cov-fail-under=85 tests/
94+
95+
- name: Build source release assets
96+
shell: bash
97+
run: |
98+
set -euo pipefail
99+
VERSION="${{ steps.version.outputs.version }}"
100+
ARCHIVE="deepsequence-recommender-${VERSION}.tar.gz"
101+
git archive --format=tar.gz --prefix="deepsequence-recommender-${VERSION}/" \
102+
-o "$ARCHIVE" "${{ steps.version.outputs.tag }}"
103+
sha256sum "$ARCHIVE" > SHA256SUMS
104+
105+
- name: Log in to GitHub Container Registry
106+
uses: docker/login-action@v3
107+
with:
108+
registry: ghcr.io
109+
username: ${{ github.actor }}
110+
password: ${{ secrets.GITHUB_TOKEN }}
111+
112+
- name: Set up Docker Buildx
113+
uses: docker/setup-buildx-action@v3
114+
115+
- name: Build and publish GHCR package
116+
id: push
117+
uses: docker/build-push-action@v6
118+
with:
119+
context: .
120+
push: true
121+
tags: |
122+
${{ env.IMAGE_NAME }}:${{ steps.version.outputs.tag }}
123+
${{ env.IMAGE_NAME }}:${{ steps.version.outputs.version }}
124+
${{ env.IMAGE_NAME }}:latest
125+
labels: |
126+
org.opencontainers.image.source=${{ github.server_url }}/${{ github.repository }}
127+
org.opencontainers.image.version=${{ steps.version.outputs.tag }}
128+
org.opencontainers.image.revision=${{ github.sha }}
129+
130+
- name: Create or repair GitHub Release
131+
shell: bash
23132
env:
24-
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
25-
WITH_V: true
26-
DEFAULT_BUMP: patch
133+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
134+
run: |
135+
set -euo pipefail
136+
TAG="${{ steps.version.outputs.tag }}"
137+
VERSION="${{ steps.version.outputs.version }}"
138+
ARCHIVE="deepsequence-recommender-${VERSION}.tar.gz"
139+
140+
if gh release view "$TAG" >/dev/null 2>&1; then
141+
gh release upload "$TAG" "$ARCHIVE" SHA256SUMS --clobber
142+
else
143+
gh release create "$TAG" "$ARCHIVE" SHA256SUMS \
144+
--title "DeepSequence Recommender $TAG" \
145+
--generate-notes \
146+
--verify-tag
147+
fi
148+
149+
- name: Publish release summary
150+
run: |
151+
echo "### DeepSequence Recommender ${{ steps.version.outputs.tag }}" >> "$GITHUB_STEP_SUMMARY"
152+
echo "- GitHub Release: published/repaired" >> "$GITHUB_STEP_SUMMARY"
153+
echo "- GHCR: \`${{ env.IMAGE_NAME }}:${{ steps.version.outputs.tag }}\`" >> "$GITHUB_STEP_SUMMARY"
154+
echo "- Image digest: \`${{ steps.push.outputs.digest }}\`" >> "$GITHUB_STEP_SUMMARY"
155+
echo "- Source archive and SHA256SUMS attached" >> "$GITHUB_STEP_SUMMARY"

0 commit comments

Comments
 (0)