Repository navigation
178 lines (154 loc) · 6.2 KB
/
Copy pathrelease.yml
File metadata and controls
178 lines (154 loc) · 6.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
name: Release
on:
push:
tags:
- 'v*'
workflow_dispatch:
inputs:
tag:
description: 'Release tag to (re)build and upload (e.g. v0.3.2)'
required: true
permissions:
contents: write
id-token: write
jobs:
goreleaser:
if: github.event_name == 'push'
runs-on: ubuntu-latest
outputs:
hashes: ${{ steps.hash.outputs.hashes }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
fetch-depth: 0
ref: ${{ inputs.tag || github.ref }}
- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
with:
go-version: '1.24'
- uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6
with:
distribution: goreleaser
version: '~> v2'
args: release --clean
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
HOMEBREW_TAP_TOKEN: ${{ secrets.HOMEBREW_TAP_TOKEN }}
- name: Install cosign
uses: sigstore/cosign-installer@v3
- name: Sign release artifacts
run: |
cosign sign-blob --yes \
--output-signature dist/checksums.txt.sig \
--output-certificate dist/checksums.txt.pem \
dist/checksums.txt
env:
COSIGN_EXPERIMENTAL: "true"
- name: Upload signature to release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TAG: ${{ github.ref_name }}
run: |
gh release upload "$TAG" \
dist/checksums.txt.sig \
dist/checksums.txt.pem \
--repo chiga0/agent-proxy \
--clobber
- name: Generate subject hashes for SLSA
id: hash
run: |
cd dist
sha256sum *.tar.gz *.zip checksums.txt | base64 -w0 > ../hashes.txt
echo "hashes=$(cat ../hashes.txt)" >> $GITHUB_OUTPUT
provenance:
needs: [goreleaser]
permissions:
actions: read
id-token: write
contents: write
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.0.0
with:
base64-subjects: "${{ needs.goreleaser.outputs.hashes }}"
upload-assets: true
upload-oss:
needs: goreleaser
if: always() && (needs.goreleaser.result == 'success' || needs.goreleaser.result == 'skipped')
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
ref: ${{ inputs.tag || github.ref }}
- name: Set version
id: ver
run: |
TAG="${{ inputs.tag || github.ref_name }}"
echo "tag=${TAG}" >> $GITHUB_OUTPUT
echo "version=${TAG#v}" >> $GITHUB_OUTPUT
- name: Download release assets
env:
GH_TOKEN: ${{ github.token }}
run: |
mkdir -p dist
gh release download "${{ steps.ver.outputs.tag }}" \
--repo chiga0/agent-proxy \
--dir dist \
--pattern '*.tar.gz' \
--pattern '*.zip' \
--pattern 'checksums.txt' \
--clobber
ls -la dist/
- name: Install aliyun CLI
run: |
curl -fsSL -o /tmp/aliyun-cli.tgz https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz
# Verify checksum if available
curl -fsSL -o /tmp/aliyun-cli.tgz.sha256 https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz.sha256 2>/dev/null || true
if [ -f /tmp/aliyun-cli.tgz.sha256 ]; then
cd /tmp && sha256sum -c aliyun-cli.tgz.sha256
fi
tar xzf /tmp/aliyun-cli.tgz -C /usr/local/bin
- name: Assume RAM Role (STS)
env:
AK_ID: ${{ secrets.ALIBABA_CLOUD_ACCESS_KEY_ID }}
AK_SECRET: ${{ secrets.ALIBABA_CLOUD_ACCESS_KEY_SECRET }}
ROLE_ARN: ${{ secrets.ALIBABA_CLOUD_ROLE_ARN }}
SESSION_NAME: ${{ secrets.ALIBABA_CLOUD_ROLE_SESSION_NAME }}
run: |
aliyun configure set --profile sts-base --mode AK \
--region cn-hangzhou \
--access-key-id "$AK_ID" \
--access-key-secret "$AK_SECRET"
CREDS=$(aliyun sts AssumeRole \
--RoleArn "$ROLE_ARN" \
--RoleSessionName "${SESSION_NAME:-github-action}" \
--DurationSeconds 3600 \
--profile sts-base)
echo "TMP_AK=$(echo "$CREDS" | jq -r .Credentials.AccessKeyId)" >> $GITHUB_ENV
echo "TMP_SK=$(echo "$CREDS" | jq -r .Credentials.AccessKeySecret)" >> $GITHUB_ENV
echo "TMP_TOKEN=$(echo "$CREDS" | jq -r .Credentials.SecurityToken)" >> $GITHUB_ENV
echo "::add-mask::$(echo "$CREDS" | jq -r .Credentials.AccessKeyId)"
echo "::add-mask::$(echo "$CREDS" | jq -r .Credentials.AccessKeySecret)"
echo "::add-mask::$(echo "$CREDS" | jq -r .Credentials.SecurityToken)"
- name: Upload to OSS
env:
TAG: ${{ steps.ver.outputs.tag }}
OSS_BUCKET: agent-proxy
OSS_REGION: cn-hangzhou
run: |
OSS_OPTS="--region $OSS_REGION \
--access-key-id $TMP_AK \
--access-key-secret $TMP_SK \
--sts-token $TMP_TOKEN"
for f in dist/*.tar.gz dist/*.zip dist/checksums.txt; do
[ -f "$f" ] || continue
echo "↑ $(basename $f)"
aliyun oss cp "$f" "oss://${OSS_BUCKET}/releases/${TAG}/$(basename $f)" \
$OSS_OPTS --force
done
aliyun oss cp install.sh "oss://${OSS_BUCKET}/install.sh" $OSS_OPTS --force
aliyun oss cp install.sh "oss://${OSS_BUCKET}/releases/${TAG}/install.sh" $OSS_OPTS --force
jq -n --arg v "$TAG" \
--arg base "https://${OSS_BUCKET}.oss-cn-hangzhou.aliyuncs.com/releases/${TAG}" \
--argjson assets "$(cd dist && ls *.tar.gz *.zip checksums.txt 2>/dev/null | jq -R . | jq -s .)" \
'{version: $v, base_url: $base, assets: $assets}' > dist/manifest.json
aliyun oss cp dist/manifest.json "oss://${OSS_BUCKET}/releases/${TAG}/manifest.json" $OSS_OPTS --force
aliyun oss cp dist/manifest.json "oss://${OSS_BUCKET}/releases/latest/manifest.json" $OSS_OPTS --force
echo "✓ Uploaded to oss://${OSS_BUCKET}/releases/${TAG}/"