name: Refresh signed metadata on: schedule: - cron: '17 4 * * *' concurrency: group: tensamin-central-releases cancel-in-progress: false jobs: refresh: runs-on: nixos env: NIX_CONFIG: experimental-features = nix-command flakes FORGEJO_SERVER_URL: ${{ forgejo.server_url }} FORGEJO_REPOSITORY: ${{ forgejo.repository }} FORGEJO_RUN_ID: ${{ forgejo.run_id }} RELEASE_TOKEN: ${{ secrets.TENSAMIN_RELEASE_TOKEN }} IOTA_RELEASE_SIGNING_KEY: ${{ secrets.IOTA_RELEASE_SIGNING_KEY }} IOTA_RELEASE_PUBLIC_KEY: ${{ vars.IOTA_RELEASE_PUBLIC_KEY }} IOTA_RELEASE_SIGNING_KEY_ID: ${{ vars.IOTA_RELEASE_SIGNING_KEY_ID || 'primary' }} IOTA_BASE_VERSION: ${{ vars.IOTA_BASE_VERSION || '0.1.0' }} steps: - uses: https://data.forgejo.org/actions/checkout@v4 with: fetch-depth: 0 persist-credentials: false - name: Bootstrap pinned tools and source credentials uses: ./.forgejo/source-access with: source-key: ${{ secrets.TENSAMIN_SOURCE_SSH_KEY }} known-hosts: ${{ vars.TENSAMIN_SSH_KNOWN_HOSTS }} - name: Refresh signed metadata run: | set -euo pipefail root=$PWD revision=$(git rev-parse HEAD) for channel in stable canary; do git checkout --detach "$revision" nix develop --impure --expr "import $root/scripts/release-env.nix { root = builtins.toPath \"$root\"; }" --command python3 scripts/release.py refresh --channel "$channel" --directory "$RUNNER_TEMP/refresh-$FORGEJO_RUN_ID-$channel" done - name: Remove source credentials if: always() run: | if [[ -n ${SSH_AGENT_PID:-} ]]; then kill "$SSH_AGENT_PID"; fi rm -rf "$RUNNER_TEMP/tensamin-source"