-
Notifications
You must be signed in to change notification settings - Fork 0
109 lines (104 loc) · 4.74 KB
/
Copy pathrelease.yml
File metadata and controls
109 lines (104 loc) · 4.74 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
name: Release
# 打 v* tag → 构建多架构镜像推 ghcr.io/filescodebox/server 与
# ghcr.io/filescodebox/frontend(同一版本列车:前后端分离部署,
# chart 以单一 appVersion 同时锁两个镜像)。
# server 镜像为纯后端(0.9.0 起不含前端静态资源),frontend 镜像
# (nginx 静态+API 反代)承担全部对外入口。
on:
push:
tags: ["v*"]
env:
REGISTRY: ghcr.io
IMAGE: ghcr.io/filescodebox/server
jobs:
release:
runs-on: ubuntu-latest
permissions:
contents: write # Ensure GitHub Release 步骤建 Release 页(此前 read 致 403 静默跳过)
packages: write
steps:
- uses: actions/checkout@v4
with: { path: server }
- uses: actions/checkout@v4
with: { repository: filescodebox/frontend, path: frontend }
- name: 工作区布局 + ignore 规则
run: |
mkdir -p ${{ github.workspace }}/ws
mv server frontend ${{ github.workspace }}/ws/
printf '*/.git\n**/node_modules\n*/bin\n*/data\n*/logs\ngo.work\ngo.work.sum\n' > ${{ github.workspace }}/ws/.dockerignore
- uses: docker/setup-qemu-action@v3
- uses: docker/setup-buildx-action@v3
- uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.IMAGE }}
tags: |
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=raw,value=latest
- uses: docker/build-push-action@v6
with:
context: ${{ github.workspace }}/ws
file: ${{ github.workspace }}/ws/server/Dockerfile
platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
# buildx 默认 provenance 认证清单会使 GitHub Packages 页面渲染 500
# (registry 拉取不受影响,仅 Web UI 坏),关掉保证包页可开、可见性可改
provenance: false
build-args: |
VERSION=${{ github.ref_name }}
COMMIT=${{ github.sha }}
BUILD_TIME=${{ steps.meta.outputs.date }}
GOPROXY=https://proxy.golang.org,direct
# ── frontend 镜像(k8s 前后端分离部署;tag 与 server 完全一致)──
- id: meta-frontend
uses: docker/metadata-action@v5
with:
images: ghcr.io/filescodebox/frontend
tags: |
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=raw,value=latest
- uses: docker/build-push-action@v6
with:
context: ${{ github.workspace }}/ws/frontend
file: ${{ github.workspace }}/ws/frontend/Dockerfile
platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.meta-frontend.outputs.tags }}
labels: ${{ steps.meta-frontend.outputs.labels }}
provenance: false
build-args: |
NPM_REGISTRY=https://registry.npmjs.org
# ── GitHub Release 自动创建(无则建,有则跳过;带自动变更notes并标 Latest)──
- name: Ensure GitHub Release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
if ! gh release view "${{ github.ref_name }}" -R ${{ github.repository }} >/dev/null 2>&1; then
gh release create "${{ github.ref_name }}" -R ${{ github.repository }} --generate-notes --latest
else
echo "Release 已存在,跳过"
fi
# 不再 continue-on-error:权限修复后本步骤已被证明可用,再静默吞错只会
# 重演 v0.12.6/v0.13.0 Release 页缺失数日无人知(2026-10-06 治理)
# ── chart appVersion 自动对齐 ──
# 镜像发布成功后通知 charts 仓:appVersion 对齐本 tag、chart version 自动
# +1 并由其既有 Release Charts 工作流发版(Pages + OCI)。CHARTS_PAT 为
# 对 charts 仓有 contents:write/dispatch 权限的 token(仓库 Secrets 配置)。
- name: Dispatch charts appVersion sync
run: |
curl -fsSL -X POST \
-H "Authorization: Bearer ${{ secrets.CHARTS_PAT }}" \
-H "Accept: application/vnd.github+json" \
https://api.github.com/repos/filescodebox/charts/dispatches \
-d '{"event_type":"component-release","client_payload":{"app_version":"${{ github.ref_name }}"}}'
# 不再 continue-on-error:CHARTS_PAT→charts RELEASE_PAT 链路已通,断链要
# 响(此前静默吞 403 致 chart 1.3.12/13/14 发版缺失,2026-10-06 治理)