diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 9a9e1cf..256a408 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -2,27 +2,21 @@ name: Build on: workflow_dispatch: - push: - paths-ignore: ['*.md'] - branches: ['master'] pull_request: - paths-ignore: ['*.md'] + types: [opened, synchronize, reopened, ready_for_review] branches: ['master'] + paths-ignore: ['*.md'] + +permissions: {} concurrency: - group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} + group: package-build-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true jobs: build: - if: github.event.pull_request.draft == false + if: github.event_name != 'pull_request' || github.event.pull_request.draft == false + permissions: + contents: read uses: Start9Labs/start-technologies/.github/workflows/build.yml@master - with: - # Ten upstream images per arch, and the packed s9pk runs to hundreds of - # megabytes — a stock runner gets tight once the images are unpacked. - FREE_DISK_SPACE: true - secrets: - # Optional for a build — without it the reusable workflow falls back to - # `start-cli init-key` and signs with a throwaway identity. Passing the - # real key keeps CI artifacts signed the same as local builds. - DEV_KEY: ${{ secrets.DEV_KEY }} + # No DEV_KEY — a PR build doesn't publish, so it doesn't need the signing key. diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 36de2de..6dcef4a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -9,13 +9,8 @@ jobs: release: uses: Start9Labs/start-technologies/.github/workflows/release.yml@master with: - FREE_DISK_SPACE: true - # Deliberately left unset: this package publishes to GitHub Releases only, - # not to a Start9 registry. Every registry and S3 step in the reusable - # workflow is guarded on these, so empty values skip them and the - # "Create GitHub Release" step (which is unguarded) still runs. - RELEASE_REGISTRY: '' - S3_S9PKS_BASE_URL: '' + RELEASE_REGISTRY: ${{ vars.RELEASE_REGISTRY }} + S3_S9PKS_BASE_URL: ${{ vars.S3_S9PKS_BASE_URL }} secrets: DEV_KEY: ${{ secrets.DEV_KEY }} S3_ACCESS_KEY: ${{ secrets.S3_ACCESS_KEY }} diff --git a/.github/workflows/tagAndRelease.yml b/.github/workflows/tagAndRelease.yml new file mode 100644 index 0000000..f000851 --- /dev/null +++ b/.github/workflows/tagAndRelease.yml @@ -0,0 +1,24 @@ +name: Tag and Release + +on: + push: + branches: ['master'] + paths-ignore: ['*.md'] + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +jobs: + tag: + uses: Start9Labs/start-technologies/.github/workflows/tagAndRelease.yml@master + with: + REFERENCE_REGISTRY: ${{ vars.REFERENCE_REGISTRY }} + RELEASE_REGISTRY: ${{ vars.RELEASE_REGISTRY }} + S3_S9PKS_BASE_URL: ${{ vars.S3_S9PKS_BASE_URL }} + secrets: + DEV_KEY: ${{ secrets.DEV_KEY }} + S3_ACCESS_KEY: ${{ secrets.S3_ACCESS_KEY }} + S3_SECRET_KEY: ${{ secrets.S3_SECRET_KEY }} + permissions: + contents: write