forked from modrinth/code
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
4 changed files
with
300 additions
and
6 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,227 @@ | ||
name: Release | ||
'on': | ||
push: | ||
branches: | ||
- test1 | ||
concurrency: | ||
group: '${{ github.workflow }}' | ||
cancel-in-progress: false | ||
permissions: | ||
contents: read | ||
pages: write | ||
id-token: write | ||
jobs: | ||
build: | ||
name: Build | ||
strategy: | ||
fail-fast: false | ||
matrix: | ||
platform: | ||
- macos-latest | ||
- windows-latest | ||
- ubuntu-22.04 | ||
runs-on: '${{ matrix.platform }}' | ||
steps: | ||
- uses: actions/checkout@v4 | ||
- name: Rust setup (mac) | ||
if: 'startsWith(matrix.platform, ''macos'')' | ||
uses: dtolnay/rust-toolchain@stable | ||
with: | ||
components: 'rustfmt, clippy' | ||
targets: 'aarch64-apple-darwin, x86_64-apple-darwin' | ||
- name: Rust setup | ||
if: '!startsWith(matrix.platform, ''macos'')' | ||
uses: dtolnay/rust-toolchain@stable | ||
with: | ||
components: 'rustfmt, clippy' | ||
- name: Setup rust cache | ||
uses: actions/cache@v4 | ||
with: | ||
path: | | ||
target/** | ||
!target/*/release/bundle/*/*.dmg | ||
!target/*/release/bundle/*/*.app.tar.gz | ||
!target/*/release/bundle/*/*.app.tar.gz.sig | ||
!target/release/bundle/*/*.dmg | ||
!target/release/bundle/*/*.app.tar.gz | ||
!target/release/bundle/*/*.app.tar.gz.sig | ||
!target/release/bundle/appimage/*.AppImage | ||
!target/release/bundle/appimage/*.AppImage.tar.gz | ||
!target/release/bundle/appimage/*.AppImage.tar.gz.sig | ||
!target/release/bundle/deb/*.deb | ||
!target/release/bundle/rpm/*.rpm | ||
!target/release/bundle/msi/*.msi | ||
!target/release/bundle/msi/*.msi.zip | ||
!target/release/bundle/msi/*.msi.zip.sig | ||
!target/release/bundle/nsis/*.exe | ||
!target/release/bundle/nsis/*.nsis.zip | ||
!target/release/bundle/nsis/*.nsis.zip.sig | ||
key: '${{ runner.os }}-rust-target-${{ hashFiles(''**/Cargo.lock'') }}' | ||
restore-keys: | | ||
${{ runner.os }}-rust-target- | ||
- name: Use Node.js | ||
uses: actions/setup-node@v4 | ||
with: | ||
node-version: 20 | ||
- name: Install pnpm via corepack | ||
shell: bash | ||
run: | | ||
corepack enable | ||
corepack prepare --activate | ||
- name: Get pnpm store directory | ||
id: pnpm-cache | ||
shell: bash | ||
run: | | ||
echo "STORE_PATH=$(pnpm store path)" >> $GITHUB_OUTPUT | ||
- name: Setup pnpm cache | ||
uses: actions/cache@v4 | ||
with: | ||
path: '${{ steps.pnpm-cache.outputs.STORE_PATH }}' | ||
key: '${{ runner.os }}-pnpm-store-${{ hashFiles(''**/pnpm-lock.yaml'') }}' | ||
restore-keys: | | ||
${{ runner.os }}-pnpm-store- | ||
- name: install dependencies (ubuntu only) | ||
if: 'startsWith(matrix.platform, ''ubuntu'')' | ||
run: > | ||
sudo apt-get update | ||
sudo apt-get install -y libwebkit2gtk-4.1-dev build-essential curl | ||
wget file libxdo-dev libssl-dev pkg-config | ||
libayatana-appindicator3-dev librsvg2-dev | ||
- name: Install frontend dependencies | ||
run: pnpm install | ||
- name: build app (macos) | ||
run: >- | ||
pnpm --filter=@modrinth/app run tauri build --target | ||
universal-apple-darwin --config "tauri-release.conf.json" | ||
if: 'startsWith(matrix.platform, ''macos'')' | ||
env: | ||
GITHUB_TOKEN: '${{ secrets.GITHUB_TOKEN }}' | ||
ENABLE_CODE_SIGNING: '${{ secrets.CSC_LINK }}' | ||
APPLE_CERTIFICATE: '${{ secrets.CSC_LINK }}' | ||
APPLE_CERTIFICATE_PASSWORD: '${{ secrets.CSC_KEY_PASSWORD }}' | ||
APPLE_SIGNING_IDENTITY: '${{ secrets.APPLE_SIGNING_IDENTITY }}' | ||
APPLE_ID: '${{ secrets.APPLE_ID }}' | ||
APPLE_TEAM_ID: '${{ secrets.APPLE_TEAM_ID }}' | ||
APPLE_PASSWORD: '${{ secrets.APPLE_APP_SPECIFIC_PASSWORD }}' | ||
TAURI_SIGNING_PRIVATE_KEY: '${{ secrets.TAURI_PRIVATE_KEY }}' | ||
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: '${{ secrets.TAURI_KEY_PASSWORD }}' | ||
|
||
- name: build app | ||
run: >- | ||
pnpm --filter=@modrinth/app run tauri build --config | ||
"tauri-release.conf.json" | ||
id: build_os | ||
if: '!startsWith(matrix.platform, ''macos'')' | ||
env: | ||
GITHUB_TOKEN: '${{ secrets.GITHUB_TOKEN }}' | ||
TAURI_SIGNING_PRIVATE_KEY: '${{ secrets.TAURI_PRIVATE_KEY }}' | ||
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: '${{ secrets.TAURI_KEY_PASSWORD }}' | ||
|
||
- name: Sign files with Trusted Signing | ||
if: startsWith(matrix.platform, 'windows') | ||
uses: azure/trusted-signing-action@v0.5.1 | ||
with: | ||
azure-tenant-id: ${{ secrets.AZURE_TENANT_ID }} | ||
azure-client-id: ${{ secrets.AZURE_CLIENT_ID }} | ||
azure-client-secret: ${{ secrets.AZURE_CLIENT_SECRET }} | ||
endpoint: https://weu.codesigning.azure.net/ | ||
trusted-signing-account-name: marcusklauncher | ||
certificate-profile-name: MarcuskStudioLauncher | ||
files-folder: ${{ github.workspace }}\target\release\bundle | ||
files-folder-filter: msi,exe | ||
files-folder-recurse: true | ||
file-digest: SHA256 | ||
timestamp-rfc3161: http://timestamp.acs.microsoft.com | ||
timestamp-digest: SHA256 | ||
|
||
- name: 'upload ${{ matrix.platform }}' | ||
uses: actions/upload-artifact@v4 | ||
with: | ||
name: '${{ matrix.platform }}' | ||
path: | | ||
target/*/release/bundle/*/*.dmg | ||
target/*/release/bundle/*/*.app.tar.gz | ||
target/*/release/bundle/*/*.app.tar.gz.sig | ||
target/release/bundle/*/*.dmg | ||
target/release/bundle/*/*.app.tar.gz | ||
target/release/bundle/*/*.app.tar.gz.sig | ||
target/release/bundle/*/*.AppImage | ||
target/release/bundle/*/*.AppImage.tar.gz | ||
target/release/bundle/*/*.AppImage.tar.gz.sig | ||
target/release/bundle/*/*.deb | ||
target/release/bundle/*/*.rpm | ||
target/release/bundle/msi/*.msi | ||
target/release/bundle/msi/*.msi.zip | ||
target/release/bundle/msi/*.msi.zip.sig | ||
target/release/bundle/nsis/*.exe | ||
target/release/bundle/nsis/*.nsis.zip | ||
target/release/bundle/nsis/*.nsis.zip.sig | ||
upload-s3: | ||
needs: build | ||
runs-on: ubuntu-latest | ||
steps: | ||
- name: Download all artifacts | ||
uses: actions/download-artifact@v4 | ||
with: | ||
path: artifacts | ||
|
||
- name: Extract version from Windows binary | ||
id: extract_version | ||
run: | | ||
# Find the first matching Windows executable | ||
exe_path=$(find artifacts/windows-latest/nsis -name "MARCUSK Launcher_*_x64-setup.exe" | head -1) | ||
# Extract version using pattern matching | ||
filename=$(basename "$exe_path") | ||
version=$(echo "$filename" | sed -E 's/MARCUSK Launcher_([0-9]+\.[0-9]+\.[0-9]+)_x64-setup.exe/\1/') | ||
echo "version=$version" >> $GITHUB_OUTPUT | ||
- name: Upload to Cloudflare R2 | ||
env: | ||
AWS_ACCESS_KEY_ID: ${{ secrets.CLOUDFLARE_R2_ACCESS_KEY_ID }} | ||
AWS_SECRET_ACCESS_KEY: ${{ secrets.CLOUDFLARE_R2_SECRET_ACCESS_KEY }} | ||
S3_ENDPOINT: ${{ secrets.CLOUDFLARE_R2_CDN_ENDPOINT }} | ||
DOWNLOAD_URL_BASE: 'https://cdn.marcuskstudio.live' | ||
VERSION: ${{ steps.extract_version.outputs.version }} | ||
run: | | ||
aws s3 cp artifacts s3://launcherbinaries/releases/latest/ \ | ||
--recursive \ | ||
--endpoint-url=${S3_ENDPOINT} | ||
cat > update-manifest.json << EOF | ||
{ | ||
"version": "${VERSION}", | ||
"notes": "See the assets to download this version and install.", | ||
"pub_date": "$(date -u +"%Y-%m-%dT%H:%M:%SZ")", | ||
"platforms": { | ||
"darwin-x86_64": { | ||
"signature": "$(cat artifacts/macos-latest/*/*.app.tar.gz.sig)", | ||
"url": "${DOWNLOAD_URL_BASE}/releases/latest/$(basename artifacts/macos-latest/*/*.app.tar.gz)" | ||
}, | ||
"darwin-aarch64": { | ||
"signature": "$(cat artifacts/macos-latest/*/*.app.tar.gz.sig)", | ||
"url": "${DOWNLOAD_URL_BASE}/releases/latest/$(basename artifacts/macos-latest/*/*.app.tar.gz)" | ||
}, | ||
"linux-x86_64": { | ||
"signature": "$(cat artifacts/ubuntu-22.04/*/*.AppImage.tar.gz.sig)", | ||
"url": "${DOWNLOAD_URL_BASE}/releases/latest/$(basename artifacts/ubuntu-22.04/*/*.AppImage.tar.gz)" | ||
}, | ||
"windows-x86_64": { | ||
"signature": "$(cat artifacts/windows-latest/msi/*.msi.zip.sig)", | ||
"url": "${DOWNLOAD_URL_BASE}/releases/latest/$(basename artifacts/windows-latest/msi/*.msi.zip)" | ||
} | ||
} | ||
} | ||
EOF | ||
aws s3 cp update-manifest.json s3://launcherbinaries/update-manifest.json \ | ||
--endpoint-url=${S3_ENDPOINT} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,68 @@ | ||
name: Test Upload Only | ||
'on': | ||
push: | ||
branches: | ||
- test | ||
permissions: | ||
contents: read | ||
actions: read # ← Required for cross-workflow artifact access | ||
id-token: write | ||
|
||
jobs: | ||
test-upload: | ||
runs-on: ubuntu-latest | ||
steps: | ||
- name: Download previous artifacts | ||
uses: actions/download-artifact@v4 | ||
with: | ||
run-id: 13145402165 | ||
|
||
- name: Extract version from Windows binary | ||
id: extract_version | ||
run: | | ||
# Find the Windows executable using known naming pattern | ||
exe_path=$(find artifacts/windows-latest/nsis -name "MARCUSK Launcher_*_x64-setup.exe" | head -1) | ||
# Extract version using pattern matching | ||
filename=$(basename "$exe_path") | ||
version=$(echo "$filename" | sed -E 's/MARCUSK Launcher_([0-9]+\.[0-9]+\.[0-9]+)_x64-setup.exe/\1/') | ||
echo "version=$version" >> $GITHUB_OUTPUT | ||
- name: Upload to Cloudflare R2 (Test) | ||
env: | ||
AWS_ACCESS_KEY_ID: ${{ secrets.CLOUDFLARE_R2_ACCESS_KEY_ID }} | ||
AWS_SECRET_ACCESS_KEY: ${{ secrets.CLOUDFLARE_R2_SECRET_ACCESS_KEY }} | ||
S3_ENDPOINT: ${{ secrets.CLOUDFLARE_R2_CDN_ENDPOINT }} | ||
DOWNLOAD_URL_BASE: 'https://cdn.marcuskstudio.live' | ||
VERSION: ${{ steps.extract_version.outputs.version }} | ||
run: | | ||
echo "=== TEST RUN - Would upload version ${VERSION} ===" | ||
aws s3 cp artifacts s3://launcherbinaries/releases/latest/ \ | ||
--recursive \ | ||
--endpoint-url=${S3_ENDPOINT} \ | ||
cat > update-manifest.json << EOF | ||
{ | ||
"version": "${VERSION}", | ||
"notes": "[TEST] See the assets to download this version and install.", | ||
"pub_date": "$(date -u +"%Y-%m-%dT%H:%M:%SZ")", | ||
"platforms": { | ||
"darwin-x86_64": { | ||
"signature": "$(cat artifacts/macos-latest/*/*.app.tar.gz.sig)", | ||
"url": "${DOWNLOAD_URL_BASE}/releases/latest/$(basename artifacts/macos-latest/*/*.app.tar.gz)" | ||
}, | ||
"windows-x86_64": { | ||
"signature": "$(cat artifacts/windows-latest/msi/*.msi.zip.sig)", | ||
"url": "${DOWNLOAD_URL_BASE}/releases/latest/$(basename artifacts/windows-latest/msi/*.msi.zip)" | ||
} | ||
} | ||
} | ||
EOF | ||
echo "=== Generated update-manifest.json ===" | ||
cat update-manifest.json | ||
aws s3 cp update-manifest.json s3://launcherbinaries/update-manifest.json \ | ||
--endpoint-url=${S3_ENDPOINT} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters