name: Release on: push: branches: - main paths-ignore: - 'README*' - 'docs/**' - 'LICENSE' workflow_dispatch: inputs: deploy_worker: description: Deploy the Worker to production required: false default: false type: boolean publish_oci: description: Publish the OCI image to GHCR required: false default: false type: boolean concurrency: group: release-${{ github.ref }} cancel-in-progress: false jobs: validate: permissions: contents: read uses: ./.github/workflows/validate-reusable.yml release-gates: runs-on: ubuntu-latest timeout-minutes: 5 permissions: {} outputs: has-cloudflare-secrets: ${{ steps.cloudflare.outputs.present }} steps: - name: Check Cloudflare credentials availability id: cloudflare shell: bash env: CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} run: | if [[ -n "$CLOUDFLARE_API_TOKEN" && -n "$CLOUDFLARE_ACCOUNT_ID" ]]; then echo "present=true" >> "$GITHUB_OUTPUT" else echo "present=false" >> "$GITHUB_OUTPUT" fi deploy-worker: needs: - validate - release-gates if: > needs.validate.result == 'success' && needs.release-gates.outputs.has-cloudflare-secrets == 'true' && ( (github.event_name == 'push' && github.ref == 'refs/heads/main') || (github.event_name == 'workflow_dispatch' && inputs.deploy_worker && github.ref == 'refs/heads/main') ) runs-on: ubuntu-latest timeout-minutes: 20 environment: production permissions: contents: read env: CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} steps: - name: Check out repository uses: actions/checkout@v6 - name: Set up Bun uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 with: bun-version: 1.3.12 - name: Install dependencies run: bun install --frozen-lockfile - name: Generate Worker types run: bun run cf-typegen - name: Deploy Worker run: bun run deploy publish-oci: needs: - validate if: > needs.validate.result == 'success' && ( (github.event_name == 'push' && github.ref == 'refs/heads/main') || ( github.event_name == 'workflow_dispatch' && inputs.publish_oci && github.ref == 'refs/heads/main' ) ) runs-on: ubuntu-latest timeout-minutes: 30 permissions: contents: read packages: write env: IMAGE_NAME: ghcr.io/xixu-me/paseo-relay steps: - name: Check out repository uses: actions/checkout@v6 - name: Set up QEMU uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a - name: Set up Docker Buildx uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f - name: Log in to GHCR uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Build and publish OCI image uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 with: context: . file: ./Dockerfile push: true provenance: true sbom: true platforms: linux/amd64,linux/arm64 tags: ${{ env.IMAGE_NAME }}:main