Repository navigation
feat: harden AWS integration security and deployment evidence #22
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| on: | |
| push: | |
| tags: | |
| - "v*.*.*" | |
| pull_request: | |
| paths: | |
| - ".github/workflows/release.yml" | |
| - "pyproject.toml" | |
| - "CHANGELOG.md" | |
| - "RELEASE_NOTES_*.md" | |
| workflow_dispatch: | |
| inputs: | |
| tag: | |
| description: "Existing semantic-version tag to validate" | |
| required: true | |
| type: string | |
| permissions: | |
| contents: read | |
| jobs: | |
| verify: | |
| name: Verify release candidate | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| ref: ${{ github.event_name == 'workflow_dispatch' && format('refs/tags/{0}', inputs.tag) || github.ref }} | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| cache: pip | |
| cache-dependency-path: | | |
| requirements.txt | |
| requirements-dev.txt | |
| pyproject.toml | |
| - name: Validate version and release notes | |
| if: startsWith(github.ref, 'refs/tags/') || github.event_name == 'workflow_dispatch' | |
| shell: bash | |
| run: | | |
| tag="${{ github.event_name == 'workflow_dispatch' && inputs.tag || github.ref_name }}" | |
| [[ "$tag" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]] | |
| version="${tag#v}" | |
| RELEASE_VERSION="$version" python - <<'PY' | |
| import os | |
| from pathlib import Path | |
| import tomllib | |
| version = os.environ["RELEASE_VERSION"] | |
| project = tomllib.loads(Path("pyproject.toml").read_text(encoding="utf-8")) | |
| assert project["project"]["version"] == version | |
| assert Path(f"RELEASE_NOTES_{version}.md").is_file() | |
| assert f"## [{version}]" in Path("CHANGELOG.md").read_text(encoding="utf-8") | |
| PY | |
| - name: Install release dependencies | |
| run: | | |
| python -m pip install --upgrade pip | |
| python -m pip install -r requirements.txt -r requirements-dev.txt build | |
| - name: Run quality gates | |
| run: | | |
| black --diff --check . --line-length=100 | |
| ruff check . | |
| mypy models.py utils.py event_bus.py location_store.py matching_engine.py pricing_engine.py consumer.py --ignore-missing-imports | |
| pytest | |
| python benchmarks/ride_sharing_benchmarks.py --iterations 250 --driver-count 100 --output benchmark-results.json | |
| python -m json.tool benchmark-results.json > /dev/null | |
| - name: Build Python distributions | |
| run: python -m build | |
| - name: Build application image | |
| run: docker build --tag ride-sharing-platform:${{ github.sha }} . | |
| - name: Create release checksums | |
| run: sha256sum dist/* > SHA256SUMS.txt | |
| - name: Generate SPDX SBOM | |
| uses: anchore/sbom-action@v0 | |
| with: | |
| path: . | |
| format: spdx-json | |
| output-file: sbom.spdx.json | |
| - uses: actions/upload-artifact@v4 | |
| with: | |
| name: release-assets | |
| path: | | |
| dist/* | |
| SHA256SUMS.txt | |
| sbom.spdx.json | |
| publish-release: | |
| name: Publish GitHub Release | |
| if: startsWith(github.ref, 'refs/tags/v') | |
| needs: verify | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/download-artifact@v4 | |
| with: | |
| name: release-assets | |
| path: release-assets | |
| - id: notes | |
| shell: bash | |
| run: echo "path=RELEASE_NOTES_${GITHUB_REF_NAME#v}.md" >> "$GITHUB_OUTPUT" | |
| - name: Create GitHub Release | |
| uses: softprops/action-gh-release@v2 | |
| with: | |
| body_path: ${{ steps.notes.outputs.path }} | |
| generate_release_notes: false | |
| files: release-assets/* | |
| publish-container: | |
| name: Publish release container to GHCR | |
| if: startsWith(github.ref, 'refs/tags/v') | |
| needs: verify | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| packages: write | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - id: metadata | |
| uses: docker/metadata-action@v5 | |
| with: | |
| images: ghcr.io/coreyleath-code/ride-sharing-platform | |
| tags: | | |
| type=semver,pattern={{version}} | |
| type=semver,pattern={{major}}.{{minor}} | |
| type=raw,value=latest | |
| - uses: docker/build-push-action@v6 | |
| with: | |
| context: . | |
| push: true | |
| tags: ${{ steps.metadata.outputs.tags }} | |
| labels: ${{ steps.metadata.outputs.labels }} |