From a420394821c464a0285de00ad66d06c6daca3799 Mon Sep 17 00:00:00 2001 From: Stuart Date: Fri, 2 Oct 2026 15:09:10 +0200 Subject: [PATCH] ci: build and release through Start9's reusable workflows build.yml and release.yml already called the reusable workflows in Start9Labs/start-technologies, but as this repo's own variants: Build also ran on every push to master and passed DEV_KEY to pull-request builds, and Release switched the registry step off. A release needed a hand-pushed tag, and listing it on the registry was a separate manual step. Replace both with the package template's three callers, unchanged: - Build: on pull requests, one runner per arch, without the signing key - Tag and Release: on a push to master, tag the commit and release it when the registry named by REFERENCE_REGISTRY does not list the version - Release: the same build, GitHub release and registry add for a tag pushed by hand The registry is set through two repository variables, REFERENCE_REGISTRY and RELEASE_REGISTRY. FREE_DISK_SPACE goes with the old files. It had been on since the repo's first run, so no build of this package has yet run without it. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/build.yml | 24 +++++++++--------------- .github/workflows/release.yml | 9 ++------- .github/workflows/tagAndRelease.yml | 24 ++++++++++++++++++++++++ 3 files changed, 35 insertions(+), 22 deletions(-) create mode 100644 .github/workflows/tagAndRelease.yml diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 9a9e1cf..256a408 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -2,27 +2,21 @@ name: Build on: workflow_dispatch: - push: - paths-ignore: ['*.md'] - branches: ['master'] pull_request: - paths-ignore: ['*.md'] + types: [opened, synchronize, reopened, ready_for_review] branches: ['master'] + paths-ignore: ['*.md'] + +permissions: {} concurrency: - group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} + group: package-build-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true jobs: build: - if: github.event.pull_request.draft == false + if: github.event_name != 'pull_request' || github.event.pull_request.draft == false + permissions: + contents: read uses: Start9Labs/start-technologies/.github/workflows/build.yml@master - with: - # Ten upstream images per arch, and the packed s9pk runs to hundreds of - # megabytes — a stock runner gets tight once the images are unpacked. - FREE_DISK_SPACE: true - secrets: - # Optional for a build — without it the reusable workflow falls back to - # `start-cli init-key` and signs with a throwaway identity. Passing the - # real key keeps CI artifacts signed the same as local builds. - DEV_KEY: ${{ secrets.DEV_KEY }} + # No DEV_KEY — a PR build doesn't publish, so it doesn't need the signing key. diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 36de2de..6dcef4a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -9,13 +9,8 @@ jobs: release: uses: Start9Labs/start-technologies/.github/workflows/release.yml@master with: - FREE_DISK_SPACE: true - # Deliberately left unset: this package publishes to GitHub Releases only, - # not to a Start9 registry. Every registry and S3 step in the reusable - # workflow is guarded on these, so empty values skip them and the - # "Create GitHub Release" step (which is unguarded) still runs. - RELEASE_REGISTRY: '' - S3_S9PKS_BASE_URL: '' + RELEASE_REGISTRY: ${{ vars.RELEASE_REGISTRY }} + S3_S9PKS_BASE_URL: ${{ vars.S3_S9PKS_BASE_URL }} secrets: DEV_KEY: ${{ secrets.DEV_KEY }} S3_ACCESS_KEY: ${{ secrets.S3_ACCESS_KEY }} diff --git a/.github/workflows/tagAndRelease.yml b/.github/workflows/tagAndRelease.yml new file mode 100644 index 0000000..f000851 --- /dev/null +++ b/.github/workflows/tagAndRelease.yml @@ -0,0 +1,24 @@ +name: Tag and Release + +on: + push: + branches: ['master'] + paths-ignore: ['*.md'] + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +jobs: + tag: + uses: Start9Labs/start-technologies/.github/workflows/tagAndRelease.yml@master + with: + REFERENCE_REGISTRY: ${{ vars.REFERENCE_REGISTRY }} + RELEASE_REGISTRY: ${{ vars.RELEASE_REGISTRY }} + S3_S9PKS_BASE_URL: ${{ vars.S3_S9PKS_BASE_URL }} + secrets: + DEV_KEY: ${{ secrets.DEV_KEY }} + S3_ACCESS_KEY: ${{ secrets.S3_ACCESS_KEY }} + S3_SECRET_KEY: ${{ secrets.S3_SECRET_KEY }} + permissions: + contents: write