mirror of
https://gitea.com/gitea/act_runner.git
synced 2026-07-27 18:00:40 +00:00
Mirrors every release artifact into Cloudflare R2 alongside the existing AWS S3 upload, so both buckets carry the same objects during a parallel period. S3 is untouched and stays authoritative for now; once R2 is confirmed complete it can be dropped by deleting the `blobs:` block and pointing this at R2 alone. ### Why `publishers:` and not a second `blobs:` entry goreleaser's blob pipe authenticates from the global `AWS_*` environment and has no per-entry credential fields, so two different credential sets (AWS S3 and Cloudflare R2) cannot coexist in `blobs:`. Custom publishers do support per-entry `env:`, which is the supported way to isolate the two. ### Why `curl --aws-sigv4` and not `aws`/`rclone` The CI image `docker.gitea.com/runner-images:ubuntu-latest` ships none of `aws`, `rclone`, `s3cmd` or `mc`, but does ship curl 8.5 with `--aws-sigv4`. This keeps the change zero-install. Credentials are fed to curl through a config file on stdin rather than argv, so they never appear in the process list. ### Behaviour - Object layout is identical to S3 (`gitea-runner/<version>/<artifact>`), so migrating consumers later means changing only the host, not the path. - Nightly gets R2 too, matching the existing nightly-to-S3 behaviour. - Missing R2 configuration fails the build. Because custom publishers run as the very last step of the publish pipeline, a preflight `--check-config` step runs right after checkout so the failure happens before anything is built or published rather than after the release already exists. - Verified against a local MinIO instance (site region `auto`, matching R2): successful upload byte-compared after download, plus the missing-variable, wrong-credentials, missing-file and bad-argument paths. ### Required repository secrets These must be configured before the next release run, otherwise the new preflight step will fail the workflow: - `R2_ENDPOINT` (full base URL, e.g. `https://<account>.r2.cloudflarestorage.com`) - `R2_BUCKET` - `R2_ACCESS_KEY_ID` - `R2_SECRET_ACCESS_KEY` ### Known, deliberate wart The publisher runs 109 times for 73 distinct object keys: goreleaser's release pipe already registers `release.extra_files` as `UploadableFile` artifacts, and `internal/exec` appends the publisher's own `extra_files` on top with no de-duplication. It cannot be globbed away because `gobwas/glob` has no substring-exclusion matcher, so `./**.sha256` cannot be narrowed to exclude `*.xz.sha256`. It is harmless since PUT is idempotent, and the redundant `./**.xz` glob is kept on purpose so the publisher declares its own complete file set instead of implicitly depending on the `release:` block's globs. This is documented in a comment above the block. Reviewed-on: https://gitea.com/gitea/runner/pulls/1114 Reviewed-by: Zettat123 <39446+zettat123@noreply.gitea.com>
113 lines
3.6 KiB
YAML
113 lines
3.6 KiB
YAML
---
|
|
name: release-nightly
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
push:
|
|
branches:
|
|
- 'main'
|
|
tags:
|
|
- '*'
|
|
|
|
env:
|
|
DOCKER_ORG: gitea
|
|
DOCKER_LATEST: nightly
|
|
|
|
jobs:
|
|
goreleaser:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
with:
|
|
fetch-depth: 0
|
|
# Custom publishers (the R2 mirror below) run as the very last
|
|
# step of goreleaser's publish pipeline, after the Gitea release
|
|
# has already been created and every artifact already uploaded
|
|
# to S3. Fail here instead, before anything is built or
|
|
# published, if the R2 secrets are missing.
|
|
- name: check R2 configuration
|
|
run: sh scripts/upload-r2.sh --check-config
|
|
env:
|
|
R2_ENDPOINT: ${{ secrets.R2_ENDPOINT }}
|
|
R2_BUCKET: ${{ secrets.R2_BUCKET }}
|
|
R2_ACCESS_KEY_ID: ${{ secrets.R2_ACCESS_KEY_ID }}
|
|
R2_SECRET_ACCESS_KEY: ${{ secrets.R2_SECRET_ACCESS_KEY }}
|
|
- uses: actions/setup-go@v7
|
|
with:
|
|
go-version-file: "go.mod"
|
|
- name: goreleaser
|
|
uses: goreleaser/goreleaser-action@v7
|
|
with:
|
|
distribution: goreleaser-pro
|
|
args: release --nightly
|
|
env:
|
|
GORELEASER_KEY: ${{ secrets.GORELEASER_KEY }}
|
|
AWS_REGION: ${{ secrets.AWS_REGION }}
|
|
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_KEY_ID }}
|
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
|
S3_REGION: ${{ secrets.AWS_REGION }}
|
|
S3_BUCKET: ${{ secrets.AWS_BUCKET }}
|
|
R2_ENDPOINT: ${{ secrets.R2_ENDPOINT }}
|
|
R2_BUCKET: ${{ secrets.R2_BUCKET }}
|
|
R2_ACCESS_KEY_ID: ${{ secrets.R2_ACCESS_KEY_ID }}
|
|
R2_SECRET_ACCESS_KEY: ${{ secrets.R2_SECRET_ACCESS_KEY }}
|
|
GORELEASER_FORCE_TOKEN: "gitea"
|
|
GITEA_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
release-image:
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
matrix:
|
|
variant:
|
|
# The basic image is built from source and can target any arch the
|
|
# toolchain supports. The dind variants are limited to the arches the
|
|
# docker:dind base image publishes.
|
|
- target: basic
|
|
tag_suffix: ""
|
|
platforms: linux/amd64,linux/arm64,linux/riscv64,linux/s390x
|
|
- target: dind
|
|
tag_suffix: "-dind"
|
|
platforms: linux/amd64,linux/arm64
|
|
- target: dind-rootless
|
|
tag_suffix: "-dind-rootless"
|
|
platforms: linux/amd64,linux/arm64
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v7
|
|
with:
|
|
fetch-depth: 0 # all history for all branches and tags
|
|
|
|
- name: Set up QEMU
|
|
uses: docker/setup-qemu-action@v4
|
|
|
|
- name: Set up Docker BuildX
|
|
uses: docker/setup-buildx-action@v4
|
|
|
|
- name: Login to DockerHub
|
|
uses: docker/login-action@v4
|
|
with:
|
|
username: ${{ secrets.DOCKER_USERNAME }}
|
|
password: ${{ secrets.DOCKER_PASSWORD }}
|
|
|
|
- name: Echo the tag
|
|
run: echo "${{ env.DOCKER_ORG }}/runner:nightly${{ matrix.variant.tag_suffix }}"
|
|
|
|
- name: Get Meta
|
|
id: meta
|
|
run: |
|
|
echo REPO_VERSION=$(git describe --tags --always | sed 's/-/+/' | sed 's/^v//') >> $GITHUB_OUTPUT
|
|
|
|
- name: Build and push
|
|
uses: docker/build-push-action@v7
|
|
with:
|
|
context: .
|
|
file: ./Dockerfile
|
|
target: ${{ matrix.variant.target }}
|
|
platforms: ${{ matrix.variant.platforms }}
|
|
push: true
|
|
tags: |
|
|
${{ env.DOCKER_ORG }}/runner:nightly${{ matrix.variant.tag_suffix }}
|
|
build-args: |
|
|
VERSION=${{ steps.meta.outputs.REPO_VERSION }}
|