Compare commits
12 Commits
abf47646a1
...
develop
| Author | SHA1 | Date | |
|---|---|---|---|
| 662db558bd | |||
| c5cd0f0430 | |||
| 69fe519f7a | |||
| 6f1913a542 | |||
| cb84cb354d | |||
| 43d4a2b35e | |||
| 03513bb1e4 | |||
| 83723bd989 | |||
| 44bc0a3699 | |||
| 3aeae916f5 | |||
| 6e2e694cf3 | |||
| 5f6d8d8eab |
114
.github/actions/build-and-push-dotnet/action.yaml
vendored
Normal file
114
.github/actions/build-and-push-dotnet/action.yaml
vendored
Normal file
@@ -0,0 +1,114 @@
|
||||
name: Build and Push Docker Image (dotnet)
|
||||
description: Build a Docker image and push to a registry (dotnet)
|
||||
inputs:
|
||||
registry:
|
||||
description: Container registry hostname
|
||||
required: true
|
||||
image_name:
|
||||
description: Full image name including registry
|
||||
required: false
|
||||
default: ""
|
||||
tag:
|
||||
description: Override image tag (defaults to standard tags)
|
||||
required: false
|
||||
default: ""
|
||||
checkout_ref:
|
||||
description: Git ref to checkout before build (e.g. refs/tags/v1.2.3)
|
||||
required: false
|
||||
default: ""
|
||||
dockerfile:
|
||||
description: Path to Dockerfile
|
||||
required: false
|
||||
default: Dockerfile
|
||||
context:
|
||||
description: Build context
|
||||
required: false
|
||||
default: .
|
||||
push:
|
||||
description: Push image after build
|
||||
required: false
|
||||
default: "true"
|
||||
registry_username:
|
||||
description: Registry username
|
||||
required: true
|
||||
registry_password:
|
||||
description: Registry password or token
|
||||
required: true
|
||||
build_args:
|
||||
description: Optional build args (newline-separated KEY=VALUE)
|
||||
required: false
|
||||
default: ""
|
||||
runs:
|
||||
using: "composite"
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
fetch-tags: true
|
||||
ref: ${{ inputs.checkout_ref != '' && inputs.checkout_ref || '' }}
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
|
||||
- name: Resolve image name
|
||||
shell: bash
|
||||
env:
|
||||
REGISTRY: ${{ inputs.registry }}
|
||||
IMAGE_NAME: ${{ inputs.image_name }}
|
||||
REPO: ${{ gitea.repository != '' && gitea.repository || github.repository }}
|
||||
run: |
|
||||
if [ -z "${IMAGE_NAME}" ]; then
|
||||
IMAGE_NAME="${REGISTRY}/${REPO}"
|
||||
fi
|
||||
echo "IMAGE_NAME=${IMAGE_NAME}" >> "$GITHUB_ENV"
|
||||
|
||||
- name: Log in to container registry
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: ${{ inputs.registry }}
|
||||
username: ${{ inputs.registry_username }}
|
||||
password: ${{ inputs.registry_password }}
|
||||
|
||||
- name: Validate registry configuration
|
||||
shell: bash
|
||||
env:
|
||||
REGISTRY: ${{ inputs.registry }}
|
||||
run: |
|
||||
if [ -z "${REGISTRY}" ]; then
|
||||
echo "::error::REGISTRY input is missing or empty"
|
||||
exit 1
|
||||
fi
|
||||
if [ -z "${IMAGE_NAME}" ] || [[ "${IMAGE_NAME}" == */ ]]; then
|
||||
echo "::error::IMAGE_NAME is empty or malformed (resolved to '${IMAGE_NAME}')"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Derive image metadata
|
||||
id: vars
|
||||
shell: bash
|
||||
env:
|
||||
IMAGE_NAME: ${{ env.IMAGE_NAME }}
|
||||
TAG_INPUT: ${{ inputs.tag }}
|
||||
run: |
|
||||
bash "${GITHUB_ACTION_PATH}/../shared/derive-image-metadata.sh"
|
||||
|
||||
- name: Show build summary
|
||||
shell: bash
|
||||
env:
|
||||
IMAGE_NAME: ${{ env.IMAGE_NAME }}
|
||||
run: |
|
||||
echo "Commit: ${GITHUB_SHA:-${GITEA_SHA}}"
|
||||
echo "Image: ${IMAGE_NAME}"
|
||||
echo "Tags:"
|
||||
printf '%s\n' "${{ steps.vars.outputs.tags }}"
|
||||
echo "Deploy target: ${{ steps.vars.outputs.target }}"
|
||||
|
||||
- name: Build and push image
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: ${{ inputs.context }}
|
||||
file: ${{ inputs.dockerfile }}
|
||||
push: ${{ inputs.push }}
|
||||
tags: ${{ steps.vars.outputs.tags }}
|
||||
build-args: ${{ inputs.build_args }}
|
||||
98
.github/actions/build-and-push/action.yaml
vendored
98
.github/actions/build-and-push/action.yaml
vendored
@@ -12,6 +12,10 @@ inputs:
|
||||
description: Override image tag (defaults to standard tags)
|
||||
required: false
|
||||
default: ""
|
||||
checkout_ref:
|
||||
description: Git ref to checkout before build (e.g. refs/tags/v1.2.3)
|
||||
required: false
|
||||
default: ""
|
||||
dockerfile:
|
||||
description: Path to Dockerfile
|
||||
required: false
|
||||
@@ -24,6 +28,10 @@ inputs:
|
||||
description: Push image after build
|
||||
required: false
|
||||
default: "true"
|
||||
additional_build_args:
|
||||
description: Additional Docker build args as newline-separated KEY=VALUE pairs
|
||||
required: false
|
||||
default: ""
|
||||
registry_username:
|
||||
description: Registry username
|
||||
required: true
|
||||
@@ -38,6 +46,7 @@ runs:
|
||||
with:
|
||||
fetch-depth: 0
|
||||
fetch-tags: true
|
||||
ref: ${{ inputs.checkout_ref != '' && inputs.checkout_ref || '' }}
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
@@ -75,70 +84,14 @@ runs:
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Derive image tags
|
||||
- name: Derive image metadata
|
||||
id: vars
|
||||
shell: bash
|
||||
env:
|
||||
IMAGE_NAME: ${{ env.IMAGE_NAME }}
|
||||
TAG_INPUT: ${{ inputs.tag }}
|
||||
run: |
|
||||
IMAGE="${IMAGE_NAME}"
|
||||
TAGS=()
|
||||
|
||||
if [ -n "${TAG_INPUT}" ]; then
|
||||
TAGS+=("${IMAGE}:${TAG_INPUT}")
|
||||
else
|
||||
TAG_NAME=""
|
||||
REF="${GITHUB_REF:-${GITEA_REF}}"
|
||||
SHA="${GITHUB_SHA:-${GITEA_SHA}}"
|
||||
BRANCH=""
|
||||
SHORT_SHA="$(git rev-parse --short=7 "${SHA}")"
|
||||
|
||||
# Extract tag name when we are on a tag ref (e.g. v1.4)
|
||||
if [[ "${REF}" =~ refs/tags/(.+) ]]; then
|
||||
TAG_NAME="${BASH_REMATCH[1]}"
|
||||
fi
|
||||
|
||||
if [[ "${REF}" =~ refs/heads/(.+) ]]; then
|
||||
BRANCH="${BASH_REMATCH[1]}"
|
||||
else
|
||||
# Tag build: detect which branch contains the tagged commit
|
||||
git fetch --no-tags --depth=1 origin main release develop || true
|
||||
if git branch -r --contains "${SHA}" | grep -q "origin/main"; then
|
||||
BRANCH="main"
|
||||
elif git branch -r --contains "${SHA}" | grep -q "origin/release"; then
|
||||
BRANCH="release"
|
||||
elif git branch -r --contains "${SHA}" | grep -q "origin/develop"; then
|
||||
BRANCH="develop"
|
||||
fi
|
||||
fi
|
||||
|
||||
TAGS+=("${IMAGE}:${SHORT_SHA}")
|
||||
[[ -n "${TAG_NAME}" ]] && TAGS+=("${IMAGE}:${TAG_NAME}")
|
||||
|
||||
case "${BRANCH}" in
|
||||
main)
|
||||
TAGS+=("${IMAGE}:latest")
|
||||
;;
|
||||
release*)
|
||||
TAGS+=("${IMAGE}:latest-rc")
|
||||
;;
|
||||
develop)
|
||||
TAGS+=("${IMAGE}:latest-dev")
|
||||
;;
|
||||
*)
|
||||
TAGS+=("${IMAGE}:latest-snapshot")
|
||||
;;
|
||||
esac
|
||||
fi
|
||||
|
||||
echo "Computed tags:"
|
||||
printf '%s\n' "${TAGS[@]}"
|
||||
{
|
||||
echo "tags<<EOF"
|
||||
printf '%s\n' "${TAGS[@]}"
|
||||
echo "EOF"
|
||||
} >> "$GITHUB_OUTPUT"
|
||||
bash "${GITHUB_ACTION_PATH}/../shared/derive-image-metadata.sh"
|
||||
|
||||
- name: Show build summary
|
||||
shell: bash
|
||||
@@ -149,25 +102,7 @@ runs:
|
||||
echo "Image: ${IMAGE_NAME}"
|
||||
echo "Tags:"
|
||||
printf '%s\n' "${{ steps.vars.outputs.tags }}"
|
||||
|
||||
- name: Determine deploy target
|
||||
id: deploy
|
||||
shell: bash
|
||||
run: |
|
||||
REF="${GITHUB_REF:-${GITEA_REF}}"
|
||||
SHA="${GITHUB_SHA:-${GITEA_SHA}}"
|
||||
TARGET="dev"
|
||||
if [[ "${REF}" == "refs/heads/main" ]]; then
|
||||
TARGET="prod"
|
||||
elif [[ "${REF}" =~ refs/tags/ ]]; then
|
||||
# Tag builds deploy to prod only if the tagged commit is in main
|
||||
git fetch --no-tags --depth=1 origin main || true
|
||||
if git branch -r --contains "${SHA}" | grep -q "origin/main"; then
|
||||
TARGET="prod"
|
||||
fi
|
||||
fi
|
||||
echo "Deploy target: ${TARGET}"
|
||||
echo "target=${TARGET}" >> "$GITHUB_OUTPUT"
|
||||
echo "Deploy target: ${{ steps.vars.outputs.target }}"
|
||||
|
||||
- name: Build and push image
|
||||
uses: docker/build-push-action@v5
|
||||
@@ -177,6 +112,9 @@ runs:
|
||||
push: ${{ inputs.push }}
|
||||
tags: ${{ steps.vars.outputs.tags }}
|
||||
build-args: |
|
||||
VITE_KEYCLOAK_URL=${{ vars.VITE_KEYCLOAK_URL }}
|
||||
VITE_KEYCLOAK_REALM=${{ vars.VITE_KEYCLOAK_REALM }}
|
||||
VITE_KEYCLOAK_CLIENT_ID=${{ vars.VITE_KEYCLOAK_CLIENT_ID }}
|
||||
VITE_KEYCLOAK_URL=${{ env.VITE_KEYCLOAK_URL != '' && env.VITE_KEYCLOAK_URL || vars.VITE_KEYCLOAK_URL }}
|
||||
VITE_KEYCLOAK_REALM=${{ env.VITE_KEYCLOAK_REALM != '' && env.VITE_KEYCLOAK_REALM || vars.VITE_KEYCLOAK_REALM }}
|
||||
VITE_KEYCLOAK_CLIENT_ID=${{ env.VITE_KEYCLOAK_CLIENT_ID != '' && env.VITE_KEYCLOAK_CLIENT_ID || vars.VITE_KEYCLOAK_CLIENT_ID }}
|
||||
VITE_BASE_PATH=${{ env.VITE_BASE_PATH != '' && env.VITE_BASE_PATH || vars.VITE_BASE_PATH }}
|
||||
VITE_ADMIN_API_BASE=${{ env.VITE_ADMIN_API_BASE != '' && env.VITE_ADMIN_API_BASE || vars.VITE_ADMIN_API_BASE }}
|
||||
${{ inputs.additional_build_args }}
|
||||
|
||||
216
.github/actions/bump-version/action.yaml
vendored
216
.github/actions/bump-version/action.yaml
vendored
@@ -5,6 +5,10 @@ inputs:
|
||||
description: Node.js version to use
|
||||
required: false
|
||||
default: "24"
|
||||
release_line:
|
||||
description: Release line for dev builds (e.g. 2.4 or 2.4.1) when it cannot be derived from the branch or PR target
|
||||
required: false
|
||||
default: ""
|
||||
gitea_token:
|
||||
description: Token for checkout/push (optional)
|
||||
required: false
|
||||
@@ -34,72 +38,210 @@ runs:
|
||||
with:
|
||||
node-version: ${{ inputs.node_version }}
|
||||
|
||||
- name: Bump patch version and tag
|
||||
- name: Bump version and tag
|
||||
id: bump
|
||||
shell: bash
|
||||
env:
|
||||
INPUT_RELEASE_LINE: ${{ inputs.release_line }}
|
||||
run: |
|
||||
EXISTING_TAG="$(git tag --points-at HEAD "v*" | head -n 1)"
|
||||
if [ -n "${EXISTING_TAG}" ]; then
|
||||
echo "Tag ${EXISTING_TAG} already points at this commit; skipping bump."
|
||||
echo "tag=${EXISTING_TAG}" >> "${GITHUB_OUTPUT}"
|
||||
exit 0
|
||||
set -euo pipefail
|
||||
|
||||
REF="${GITHUB_HEAD_REF:-${GITEA_HEAD_REF:-${GITHUB_REF:-${GITEA_REF:-}}}}"
|
||||
BASE_REF="${GITHUB_BASE_REF:-${GITEA_BASE_REF:-}}"
|
||||
BRANCH="${REF#refs/heads/}"
|
||||
BASE_BRANCH="${BASE_REF#refs/heads/}"
|
||||
|
||||
if [[ -z "${BRANCH}" ]]; then
|
||||
echo "Unable to determine branch from workflow context." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
REF="${GITHUB_REF:-${GITEA_REF}}"
|
||||
BRANCH="${REF#refs/heads/}"
|
||||
git fetch origin "${BRANCH}" --tags
|
||||
git checkout "${BRANCH}"
|
||||
git pull --ff-only origin "${BRANCH}"
|
||||
BRANCH_SAFE="$(echo "${BRANCH}" | tr '/[:space:].' '-' | tr -cd '[:alnum:]_-')"
|
||||
BRANCH_SAFE="$(echo "${BRANCH_SAFE}" | sed 's/^-*//;s/-*$//')"
|
||||
BRANCH_SAFE="${BRANCH_SAFE:-unknown}"
|
||||
|
||||
set_version() {
|
||||
npm version "$1" --no-git-tag-version --allow-same-version >/dev/null
|
||||
}
|
||||
|
||||
read_package_version() {
|
||||
node -p "require('./package.json').version"
|
||||
}
|
||||
|
||||
normalize_release_base() {
|
||||
local value="$1"
|
||||
if [[ "${value}" =~ ^v?([0-9]+)\.([0-9]+)$ ]]; then
|
||||
echo "${BASH_REMATCH[1]}.${BASH_REMATCH[2]}.0"
|
||||
return 0
|
||||
fi
|
||||
if [[ "${value}" =~ ^v?([0-9]+)\.([0-9]+)\.([0-9]+)$ ]]; then
|
||||
echo "${BASH_REMATCH[1]}.${BASH_REMATCH[2]}.${BASH_REMATCH[3]}"
|
||||
return 0
|
||||
fi
|
||||
return 1
|
||||
}
|
||||
|
||||
extract_release_base() {
|
||||
local ref_name="$1"
|
||||
local normalized
|
||||
if [[ "${ref_name}" =~ ^release/(.+)$ ]]; then
|
||||
if normalized="$(normalize_release_base "${BASH_REMATCH[1]}")"; then
|
||||
echo "${normalized}"
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
return 1
|
||||
}
|
||||
|
||||
infer_release_base_from_ancestor_release_branch() {
|
||||
local best_release_base=""
|
||||
local best_commit_time=0
|
||||
local remote_ref
|
||||
local release_branch
|
||||
local release_base
|
||||
local commit_time
|
||||
|
||||
# Best effort: not every repository has release branches.
|
||||
git fetch --no-tags origin "+refs/heads/release/*:refs/remotes/origin/release/*" >/dev/null 2>&1 || true
|
||||
|
||||
while IFS= read -r remote_ref; do
|
||||
release_branch="${remote_ref#origin/}"
|
||||
if ! release_base="$(extract_release_base "${release_branch}")"; then
|
||||
continue
|
||||
fi
|
||||
|
||||
if ! git merge-base --is-ancestor "$(git rev-parse "${remote_ref}")" HEAD; then
|
||||
continue
|
||||
fi
|
||||
|
||||
commit_time="$(git show -s --format=%ct "${remote_ref}")"
|
||||
if [[ "${commit_time}" -gt "${best_commit_time}" ]]; then
|
||||
best_commit_time="${commit_time}"
|
||||
best_release_base="${release_base}"
|
||||
fi
|
||||
done < <(git for-each-ref --format='%(refname:short)' refs/remotes/origin/release/*)
|
||||
|
||||
if [[ -n "${best_release_base}" ]]; then
|
||||
echo "${best_release_base}"
|
||||
return 0
|
||||
fi
|
||||
|
||||
return 1
|
||||
}
|
||||
|
||||
resolve_release_base() {
|
||||
local package_version
|
||||
local normalized
|
||||
local inferred_release_base
|
||||
|
||||
if [[ -n "${INPUT_RELEASE_LINE}" ]]; then
|
||||
if ! normalized="$(normalize_release_base "${INPUT_RELEASE_LINE}")"; then
|
||||
echo "Invalid release_line input '${INPUT_RELEASE_LINE}'. Expected format: <major>.<minor> or <major>.<minor>.<patch>" >&2
|
||||
exit 1
|
||||
fi
|
||||
echo "${normalized}"
|
||||
return 0
|
||||
fi
|
||||
|
||||
if extract_release_base "${BRANCH}" >/dev/null; then
|
||||
extract_release_base "${BRANCH}"
|
||||
return 0
|
||||
fi
|
||||
|
||||
if [[ -n "${BASE_BRANCH}" ]] && extract_release_base "${BASE_BRANCH}" >/dev/null; then
|
||||
extract_release_base "${BASE_BRANCH}"
|
||||
return 0
|
||||
fi
|
||||
|
||||
if inferred_release_base="$(infer_release_base_from_ancestor_release_branch)"; then
|
||||
echo "${inferred_release_base}"
|
||||
return 0
|
||||
fi
|
||||
|
||||
package_version="$(read_package_version)"
|
||||
if [[ "${package_version}" =~ ^([0-9]+)\.([0-9]+)\.[0-9]+([-.].*)?$ ]]; then
|
||||
echo "${BASH_REMATCH[1]}.${BASH_REMATCH[2]}.0"
|
||||
return 0
|
||||
fi
|
||||
|
||||
echo "Unable to determine release base for branch '${BRANCH}'. Use release/<major>.<minor>[.<patch>], provide inputs.release_line, or ensure package.json contains a semantic version." >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
next_beta_version() {
|
||||
local release_base="$1"
|
||||
local escaped_base
|
||||
local highest_beta
|
||||
escaped_base="$(printf '%s' "${release_base}" | sed 's/\./\\./g')"
|
||||
highest_beta="$(
|
||||
git tag --list "v${release_base}-beta.*" \
|
||||
| sed -nE "s/^v${escaped_base}-beta\.([0-9]+)$/\\1/p" \
|
||||
| sort -n \
|
||||
| tail -n 1
|
||||
)"
|
||||
if [[ -z "${highest_beta}" ]]; then
|
||||
echo "${release_base}-beta.0"
|
||||
else
|
||||
echo "${release_base}-beta.$((highest_beta + 1))"
|
||||
fi
|
||||
}
|
||||
|
||||
next_dev_version() {
|
||||
local release_base="$1"
|
||||
local timestamp
|
||||
while true; do
|
||||
timestamp="$(date -u +%Y%m%d%H%M%S)"
|
||||
if ! git rev-parse -q --verify "refs/tags/v${release_base}-dev.${timestamp}" >/dev/null; then
|
||||
echo "${release_base}-dev.${timestamp}"
|
||||
return 0
|
||||
fi
|
||||
sleep 1
|
||||
done
|
||||
}
|
||||
|
||||
case "${BRANCH}" in
|
||||
main)
|
||||
COMMIT_MSG="$(git log -1 --pretty=%B)"
|
||||
TARGET_VERSION=""
|
||||
if [[ "${COMMIT_MSG}" =~ release/([0-9]+)\.([0-9]+) ]]; then
|
||||
if [[ "${COMMIT_MSG}" =~ release/v?([0-9]+\.[0-9]+\.[0-9]+) ]]; then
|
||||
TARGET_VERSION="${BASH_REMATCH[1]}"
|
||||
elif [[ "${COMMIT_MSG}" =~ release/([0-9]+)\.([0-9]+) ]]; then
|
||||
TARGET_VERSION="${BASH_REMATCH[1]}.${BASH_REMATCH[2]}.0"
|
||||
elif [[ "${COMMIT_MSG}" =~ hotfix/([0-9]+\.[0-9]+\.[0-9]+) ]]; then
|
||||
TARGET_VERSION="${BASH_REMATCH[1]}"
|
||||
fi
|
||||
|
||||
if [[ -n "${TARGET_VERSION}" ]]; then
|
||||
npm version "${TARGET_VERSION}" --no-git-tag-version --allow-same-version
|
||||
BUMP_CMD="npm version patch --no-git-tag-version"
|
||||
set_version "${TARGET_VERSION}"
|
||||
else
|
||||
npm version patch --no-git-tag-version
|
||||
BUMP_CMD="npm version patch --no-git-tag-version"
|
||||
npm version patch --no-git-tag-version >/dev/null
|
||||
fi
|
||||
;;
|
||||
develop)
|
||||
npm version prerelease --preid=dev --no-git-tag-version
|
||||
BUMP_CMD="npm version prerelease --preid=dev --no-git-tag-version"
|
||||
;;
|
||||
release*)
|
||||
RELEASE_VERSION=""
|
||||
if [[ "${BRANCH}" =~ ^release/v?([0-9]+\.[0-9]+\.[0-9]+)$ ]]; then
|
||||
RELEASE_VERSION="${BASH_REMATCH[1]}"
|
||||
fi
|
||||
|
||||
if [[ -n "${RELEASE_VERSION}" ]]; then
|
||||
npm version "${RELEASE_VERSION}-rc.0" --no-git-tag-version --allow-same-version
|
||||
BUMP_CMD="npm version prerelease --preid=rc --no-git-tag-version"
|
||||
else
|
||||
npm version prerelease --preid=rc-${BRANCH_SAFE} --no-git-tag-version
|
||||
BUMP_CMD="npm version prerelease --preid=rc-${BRANCH_SAFE} --no-git-tag-version"
|
||||
fi
|
||||
release/*)
|
||||
RELEASE_BASE="$(resolve_release_base)"
|
||||
set_version "$(next_beta_version "${RELEASE_BASE}")"
|
||||
;;
|
||||
*)
|
||||
npm version prerelease --preid=nightly-${BRANCH_SAFE} --no-git-tag-version
|
||||
BUMP_CMD="npm version prerelease --preid=nightly-${BRANCH_SAFE} --no-git-tag-version"
|
||||
RELEASE_BASE="$(resolve_release_base)"
|
||||
set_version "$(next_dev_version "${RELEASE_BASE}")"
|
||||
;;
|
||||
esac
|
||||
|
||||
VERSION="$(node -p "require('./package.json').version")"
|
||||
while git rev-parse -q --verify "refs/tags/v${VERSION}" >/dev/null; do
|
||||
echo "Tag v${VERSION} already exists; trying next version."
|
||||
${BUMP_CMD}
|
||||
VERSION="$(node -p "require('./package.json').version")"
|
||||
case "${BRANCH}" in
|
||||
main)
|
||||
npm version patch --no-git-tag-version >/dev/null
|
||||
;;
|
||||
release/*)
|
||||
set_version "$(next_beta_version "${RELEASE_BASE}")"
|
||||
;;
|
||||
*)
|
||||
set_version "$(next_dev_version "${RELEASE_BASE}")"
|
||||
;;
|
||||
esac
|
||||
VERSION="$(read_package_version)"
|
||||
done
|
||||
|
||||
if git diff --quiet; then
|
||||
|
||||
79
.github/actions/shared/derive-image-metadata.sh
vendored
Executable file
79
.github/actions/shared/derive-image-metadata.sh
vendored
Executable file
@@ -0,0 +1,79 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
IMAGE_NAME="${IMAGE_NAME:-}"
|
||||
TAG_INPUT="${TAG_INPUT:-}"
|
||||
REF="${GITHUB_REF:-${GITEA_REF:-}}"
|
||||
SHA="${GITHUB_SHA:-${GITEA_SHA:-}}"
|
||||
|
||||
if [ -z "${IMAGE_NAME}" ]; then
|
||||
echo "::error::IMAGE_NAME is missing"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ -z "${SHA}" ]; then
|
||||
SHA="$(git rev-parse HEAD)"
|
||||
fi
|
||||
|
||||
SHORT_SHA="$(git rev-parse --short=7 "${SHA}")"
|
||||
BRANCH=""
|
||||
TAG_NAME=""
|
||||
TAGS=()
|
||||
|
||||
if [[ "${REF}" =~ refs/tags/(.+) ]]; then
|
||||
TAG_NAME="${BASH_REMATCH[1]}"
|
||||
fi
|
||||
|
||||
if [[ "${REF}" =~ refs/heads/(.+) ]]; then
|
||||
BRANCH="${BASH_REMATCH[1]}"
|
||||
elif [[ "${REF}" =~ refs/tags/ ]]; then
|
||||
# Tag build: detect which branch contains the tagged commit.
|
||||
git fetch --no-tags origin '+refs/heads/*:refs/remotes/origin/*' || true
|
||||
if git branch -r --contains "${SHA}" | grep -q "origin/main"; then
|
||||
BRANCH="main"
|
||||
elif git branch -r --contains "${SHA}" | grep -q "origin/release/"; then
|
||||
BRANCH="release"
|
||||
elif git branch -r --contains "${SHA}" | grep -q "origin/develop"; then
|
||||
BRANCH="develop"
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ -n "${TAG_INPUT}" ]; then
|
||||
TAGS+=("${IMAGE_NAME}:${TAG_INPUT}")
|
||||
else
|
||||
TAGS+=("${IMAGE_NAME}:${SHORT_SHA}")
|
||||
[ -n "${TAG_NAME}" ] && TAGS+=("${IMAGE_NAME}:${TAG_NAME}")
|
||||
|
||||
case "${BRANCH}" in
|
||||
main)
|
||||
TAGS+=("${IMAGE_NAME}:latest")
|
||||
;;
|
||||
release*)
|
||||
TAGS+=("${IMAGE_NAME}:latest-rc")
|
||||
;;
|
||||
develop)
|
||||
TAGS+=("${IMAGE_NAME}:latest-dev")
|
||||
;;
|
||||
*)
|
||||
TAGS+=("${IMAGE_NAME}:latest-snapshot")
|
||||
;;
|
||||
esac
|
||||
fi
|
||||
|
||||
TARGET="dev"
|
||||
if [[ "${REF}" == "refs/heads/main" ]]; then
|
||||
TARGET="prod"
|
||||
elif [[ "${REF}" =~ refs/tags/ ]] && [[ "${BRANCH}" == "main" ]]; then
|
||||
TARGET="prod"
|
||||
fi
|
||||
|
||||
echo "Computed tags:"
|
||||
printf '%s\n' "${TAGS[@]}"
|
||||
echo "Deploy target: ${TARGET}"
|
||||
|
||||
{
|
||||
echo "tags<<EOF"
|
||||
printf '%s\n' "${TAGS[@]}"
|
||||
echo "EOF"
|
||||
echo "target=${TARGET}"
|
||||
} >> "$GITHUB_OUTPUT"
|
||||
56
README.md
56
README.md
@@ -4,6 +4,47 @@ This repo provides reusable Gitea Actions as composite actions that can be refer
|
||||
|
||||
### Bump Version
|
||||
|
||||
Creates or updates the version in `package.json`, commits it, creates a matching Git tag, and pushes both.
|
||||
|
||||
Inputs:
|
||||
|
||||
- `node_version`: Node.js version to use. Default: `24`
|
||||
- `release_line`: optional release line for dev builds. Format: `<major>.<minor>` or `<major>.<minor>.<patch>`. Overrides branch, PR target, inferred ancestor release branch, and `package.json`.
|
||||
- `gitea_token`: optional token used for checkout and push
|
||||
|
||||
Branch and tag rules:
|
||||
|
||||
- `main`: creates release tags from the latest commit message (`release/x.y.z`, `release/x.y`, `hotfix/x.y.z`) or falls back to a patch bump.
|
||||
- `release/<major>.<minor>` or `release/<major>.<minor>.<patch>`: creates the next beta tag for that release base, e.g. `v2.4.0-beta.3` or `v2.4.1-beta.3`.
|
||||
- all other branches: create a dev tag for the resolved release base using a UTC timestamp, e.g. `v2.4.0-dev.20260314153045`.
|
||||
|
||||
Dev release line resolution order:
|
||||
|
||||
- `inputs.release_line`
|
||||
- current branch if it matches `release/<major>.<minor>` or `release/<major>.<minor>.<patch>`
|
||||
- PR target branch if it matches `release/<major>.<minor>` or `release/<major>.<minor>.<patch>`
|
||||
- newest ancestor branch from `origin/release/*` (for feature branches created from release branches outside PR context)
|
||||
- `major.minor` from `package.json`
|
||||
|
||||
If no release line can be resolved for a dev build, the action fails intentionally.
|
||||
|
||||
Examples:
|
||||
|
||||
Commit message examples on `main`:
|
||||
|
||||
- `release/2.4.0` -> `v2.4.0`
|
||||
- `release/2.4` -> `v2.4.0`
|
||||
- `hotfix/2.4.1` -> `v2.4.1`
|
||||
|
||||
Branch examples:
|
||||
|
||||
- `release/2.4` -> next `v2.4.0-beta.N`
|
||||
- `release/v2.4.1` -> next `v2.4.1-beta.N`
|
||||
- feature branch in a PR to `release/2.4` -> `v2.4.0-dev.<UTC_TIMESTAMP>`
|
||||
- feature branch created from `release/v2.4.1` (without PR base) -> `v2.4.1-dev.<UTC_TIMESTAMP>` when the release branch tip is an ancestor
|
||||
- feature branch outside a PR with `package.json` version `2.4.0` -> `v2.4.0-dev.<UTC_TIMESTAMP>`
|
||||
- feature branch outside a PR with `release_line: 2.4` -> `v2.4.0-dev.<UTC_TIMESTAMP>`
|
||||
|
||||
Example:
|
||||
|
||||
```yaml
|
||||
@@ -18,6 +59,21 @@ jobs:
|
||||
gitea_token: ${{ secrets.GITEA_TOKEN }}
|
||||
```
|
||||
|
||||
Feature branch outside a PR:
|
||||
|
||||
```yaml
|
||||
jobs:
|
||||
bump-version:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- uses: tanztee/ci-cd/.github/actions/bump-version@main
|
||||
with:
|
||||
gitea_token: ${{ secrets.GITEA_TOKEN }}
|
||||
release_line: 2.4
|
||||
```
|
||||
|
||||
### Build and Push Docker Image
|
||||
|
||||
Example:
|
||||
|
||||
Reference in New Issue
Block a user