Repository navigation
ci: take the fleet's release workflow - #27
Merged
Merged
Conversation
jawohl publishes to crates.io by hand today, which is why 0.2.0 has been sitting unreleased. This is the fleet's release workflow and publish script, arriving through ordnung rather than written here. A tag is the whole trigger: the workflow checks it against Cargo.toml, drafts a GitHub release, and publishes the crate. The archive, checksum and install-smoke jobs skip themselves, because jawohl has no binary target for them to work on. Publishing authenticates over OIDC through crates.io Trusted Publishing, so no registry token is stored here. That needs two things outside this PR: a `crates-io` environment in this repository's settings, and a trusted publisher on crates.io naming this workflow file and that environment. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0144PU3MssnfbM5tZiqXW7d3
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The release half of setting jawohl up for crates.io Trusted Publishing. Both
files are fleet-managed and arrive through ordnung; the source change is
PowderworksCode/conf#18, which teaches the managed release workflow to handle a
library crate.
.github/workflows/release.yml— a tag is the whole trigger. It checks the tagagainst
Cargo.toml, drafts a GitHub release, publishes the crate, andun-drafts. The archive, checksum and install-smoke jobs skip themselves: jawohl
has no binary target, and the workflow asks cargo rather than assuming.
scripts/publish.sh— dry run by default,--executeto upload. It reads thesparse index to see whether the version is already published, so re-running a
release for an existing tag is a no-op rather than a failure. Verified here:
./scripts/publish.shpackages 42 files, compiles the packaged crate, and stopsat
aborting upload due to dry run, having correctly seen 0.2.0 as not yet onthe registry (0.1.0 is, from 2023).
Two steps outside this PR
crates-io.The publish job targets it, and it is the one place to require an approval
before an irreversible upload.
PowderworksCode, repositoryjawohl, workflowrelease.yml, environmentcrates-io. The form checks that the workflow exists on the default branch,so this has to merge first.
No registry token is stored: publishing authenticates over OIDC with a token
that lives under an hour. The workflow does still accept a
CARGO_REGISTRY_TOKENsecret as a bootstrap path, which jawohl does not need —that exists for a crate's first version, and jawohl is already on the registry.
Releasing 0.2.0 afterwards is
git tag v0.2.0 && git push origin v0.2.0.Unrelated, but noticed
jawohl declares
license = "MIT"and has noLICENSEfile. cargo is contentwith the field alone, so this does not block publishing, but the file is worth
adding.