client/.forgejo/workflows/deploy-prod.yml
Alois faf695d92c
Some checks failed
/ build-web (push) Failing after 1s
/ build-mobile (push) Failing after 2s
/ build-desktop (push) Failing after 2s
/ release (push) Has been skipped
(fix): correctly update workflows for self-hosted runner
2026-05-14 14:32:40 +02:00

162 lines
5.3 KiB
YAML

on:
push:
branches:
- main
jobs:
build-web:
runs-on: self-hosted
steps:
- name: Check out repo
uses: https://data.forgejo.org/actions/checkout@v4
- name: Install dependencies
run: nix-shell --run "bun install --frozen-lockfile"
- name: Copy licenses
run: nix-shell --run "bun run copy-licenses"
- name: Build packages
run: nix-shell --run "bun run build:packages"
- name: Build web
run: nix-shell --run "bun run build:web"
- name: Deploy
run: rsync -a --delete apps/web/dist/ /var/lib/www/tensamin-web-prod/
build-mobile:
runs-on: self-hosted
steps:
- name: Check out repo
uses: https://data.forgejo.org/actions/checkout@v4
- name: Install dependencies
run: nix-shell --run "bun install --frozen-lockfile"
- name: Copy licenses
run: nix-shell --run "bun run copy-licenses"
- name: Build packages
run: nix-shell --run "bun run build:packages"
- name: Setup Android Keystore
env:
KEYSTORE_BASE64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }}
KEYSTORE_PROPERTIES: ${{ secrets.ANDROID_KEYSTORE_PROPERTIES }}
run: |
nix-shell --run "bun -e \"require('fs').writeFileSync('keystore.jks', Buffer.from(process.env.KEYSTORE_BASE64.replace(/\\s+/g, ''), 'base64'))\""
nix-shell --run "bun -e \"const content = process.env.KEYSTORE_PROPERTIES.replace(/\\\\n/g, '\\n').replace(/\\r/g, '').split('\\n').map(l => l.trim()).filter(l => l).join('\\n'); require('fs').writeFileSync('keystore.properties', content)\""
- name: Build mobile
run: nix-shell --run "bun run build:mobile"
- name: Upload mobile artifact
uses: https://data.forgejo.org/actions/upload-artifact@v3
with:
name: mobile-apk
path: apps/tauri/src-tauri/gen/android/app/build/outputs/apk/universal/release/app-universal-release.apk
build-desktop:
runs-on: self-hosted
steps:
- name: Check out repo
uses: https://data.forgejo.org/actions/checkout@v4
- name: Install dependencies
run: nix-shell --run "bun install --frozen-lockfile"
- name: Copy licenses
run: nix-shell --run "bun run copy-licenses"
- name: Build packages
run: nix-shell --run "bun run build:packages"
- name: Build desktop
run: nix-shell --run "bun run build:desktop"
- name: Upload desktop artifacts
uses: https://data.forgejo.org/actions/upload-artifact@v3
with:
name: desktop-bundles
path: apps/tauri/src-tauri/target/release/bundle/
release:
runs-on: self-hosted
needs: [build-web, build-mobile, build-desktop]
steps:
- name: Check out repo
uses: https://data.forgejo.org/actions/checkout@v4
- name: Install dependencies
run: nix-shell --run "bun install --frozen-lockfile"
- name: Download mobile artifact
uses: https://data.forgejo.org/actions/download-artifact@v3
with:
name: mobile-apk
path: apps/tauri/src-tauri/gen/android/app/build/outputs/apk/universal/release/
- name: Download desktop artifacts
uses: https://data.forgejo.org/actions/download-artifact@v3
with:
name: desktop-bundles
path: apps/tauri/src-tauri/target/release/bundle/
- name: Copy releases
run: nix-shell --run "bun --bun run copy-releases"
- name: Read version
id: version
run: |
VERSION="$(nix-shell --run "node -p \"require('./package.json').version\"")"
echo "version=$VERSION" >> "$FORGEJO_OUTPUT"
echo "tag=${VERSION}-prod" >> "$FORGEJO_OUTPUT"
- name: Create release and upload files
env:
TOKEN: ${{ forgejo.token }}
API: ${{ forgejo.api_url }}
REPO: ${{ forgejo.repository }}
SHA: ${{ forgejo.sha }}
TAG: ${{ steps.version.outputs.tag }}
run: |
set -eu
test -d releases
find releases -type f | grep -q .
COMMIT_MSG="$(git log -1 --pretty=%B | sed 's/$/ /')"
HTTP_STATUS=$(curl -s -w "%{http_code}" -o release_out.json -H "Authorization: token $TOKEN" "$API/repos/$REPO/releases/tags/$TAG")
if [ "$HTTP_STATUS" = "200" ]; then
echo "Release $TAG already exists."
exit 0
fi
echo "Creating new release for $TAG"
RELEASE_JSON="$(curl -f -sS -X POST "$API/repos/$REPO/releases" \
-H "Authorization: token $TOKEN" \
-H "Content-Type: application/json" \
-d "$(jq -n \
--arg tag "$TAG" \
--arg name "$TAG" \
--arg body "$COMMIT_MSG" \
--arg target "$SHA" \
'{
tag_name: $tag,
name: $name,
body: $body,
target_commitish: $target,
draft: false,
prerelease: false
}')")"
RELEASE_ID="$(echo "$RELEASE_JSON" | jq -r .id)"
find releases -type f -print0 | while IFS= read -r -d '' file; do
name="$(basename "$file")"
curl -fsS -X POST "$API/repos/$REPO/releases/$RELEASE_ID/assets?name=$name" \
-H "Authorization: token $TOKEN" \
-F "attachment=@$file"
done