Release pipeline: cargo-release config + Gitea Actions workflows
ci / quality (push) Failing after 1m43s

- release.toml: one shared workspace version, single vX.Y.Z tag,
  full test suite as the pre-release gate, no crates.io publishing.
- .gitea/workflows/ci.yml: the Woodpecker quality bar (fmt, clippy
  -D warnings, tests) for repos served by act_runner.
- .gitea/workflows/release.yml: on a version tag, build stripped
  release binaries for x86_64 and aarch64 Linux, bundle them with the
  systemd units, rendered man pages and example config, and attach the
  tarballs (+ sha256) to a Gitea release via the API.
- dist/PKGBUILD: point at the repo's new home on project.uhhm.no.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-16 14:54:17 +02:00
parent 4033c0ffab
commit c52c3b1238
5 changed files with 141 additions and 1 deletions
+81
View File
@@ -0,0 +1,81 @@
# Release pipeline: a `vX.Y.Z` tag (pushed by `cargo release`, see
# release.toml) builds distribution tarballs and attaches them to a
# Gitea release.
#
# Each tarball contains the two binaries (stripped, release profile),
# the systemd units, the example config, rendered man pages, and the
# license/readme — everything a distro package or a hand install needs.
name: release
on:
push:
tags: ["v*"]
jobs:
build:
runs-on: ubuntu-latest
container: rust:1
strategy:
matrix:
target: [x86_64-unknown-linux-gnu, aarch64-unknown-linux-gnu]
steps:
- uses: actions/checkout@v4
- name: install tooling
run: |
apt-get update
apt-get install -y --no-install-recommends scdoc jq
if [ "${{ matrix.target }}" = "aarch64-unknown-linux-gnu" ]; then
apt-get install -y --no-install-recommends gcc-aarch64-linux-gnu
fi
rustup target add ${{ matrix.target }}
- name: build
env:
CARGO_TARGET_AARCH64_UNKNOWN_LINUX_GNU_LINKER: aarch64-linux-gnu-gcc
run: |
cargo build --workspace --release --target ${{ matrix.target }}
- name: package
run: |
VERSION="${GITHUB_REF_NAME#v}"
PKG="varde-${VERSION}-${{ matrix.target }}"
mkdir -p "$PKG"/{bin,systemd/user,man}
cp "target/${{ matrix.target }}/release/varde-daemon" \
"target/${{ matrix.target }}/release/varde-ctl" "$PKG/bin/"
# Cross-strip is unavailable for the foreign target; native
# strip handles the host one.
if [ "${{ matrix.target }}" = "x86_64-unknown-linux-gnu" ]; then
strip "$PKG"/bin/*
else
aarch64-linux-gnu-strip "$PKG"/bin/*
fi
cp dist/varde.service dist/varde.socket "$PKG/systemd/"
cp dist/user/varde.service dist/user/varde.socket "$PKG/systemd/user/"
cp dist/config.toml "$PKG/config.toml.example"
scdoc < dist/varde.8.scd > "$PKG/man/varde.8"
scdoc < dist/varde-ctl.1.scd > "$PKG/man/varde-ctl.1"
cp README.md SPECS.md "$PKG/"
tar czf "$PKG.tar.gz" "$PKG"
sha256sum "$PKG.tar.gz" > "$PKG.tar.gz.sha256"
- name: create release and upload
env:
TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
API="${GITHUB_SERVER_URL}/api/v1/repos/${GITHUB_REPOSITORY}"
# Create the release if this matrix job is first; 409 = the
# other job already made it.
curl -sf -X POST "$API/releases" \
-H "Authorization: token $TOKEN" \
-H "Content-Type: application/json" \
-d "{\"tag_name\": \"${GITHUB_REF_NAME}\", \"name\": \"${GITHUB_REF_NAME}\", \"draft\": false}" \
|| true
RELEASE_ID=$(curl -sf "$API/releases/tags/${GITHUB_REF_NAME}" \
-H "Authorization: token $TOKEN" | jq .id)
for f in varde-*.tar.gz varde-*.tar.gz.sha256; do
curl -sf -X POST \
"$API/releases/${RELEASE_ID}/assets?name=$(basename "$f")" \
-H "Authorization: token $TOKEN" \
-F "attachment=@$f"
done