Files
helmfile/.github/workflows/releaser.yaml
T
jdxandClaude Opus 5.5 5d901f8ac1 ci: publish a signed packslip with each release (#2809)
* ci: publish a signed packslip with each release

Add a job after goreleaser that publishes a packslip.sigstore.json to
tag releases: a manifest of the release archives, the helmfile
executable in each, shell completions via `helmfile completion`, and
the skills/helmfile agent skill at the release commit, signed keylessly
with this workflow's OIDC identity and linked to build provenance.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: jdx <216188+jdx@users.noreply.github.com>

* ci: include the 386 archives in the packslip

packslip 1.4.0 reads goreleaser's 386 as i686 and leaves libc out for
static Linux builds, so every archive can be listed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: jdx <216188+jdx@users.noreply.github.com>

---------

Signed-off-by: jdx <216188+jdx@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 21:49:35 +08:00

69 lines
1.8 KiB
YAML

name: GoReleaser
on:
push:
tags:
- 'v0*'
- 'v1*'
branches:
- 'main'
pull_request:
branches:
- 'main'
permissions:
contents: write
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
SNAPSHOT: ${{ !startsWith(github.ref, 'refs/tags/v') && '--snapshot' || '' }}
jobs:
goreleaser:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- name: check disk usage
run: df -h
- name: cleanup disk
run: |
sudo rm -rf /usr/share/dotnet
sudo rm -rf /opt/ghc
sudo rm -rf /usr/local/share/boost
sudo rm -fr /usr/local/lib/android
sudo rm -fr /opt/hostedtoolcache/CodeQL
sudo docker image prune --all --force
sudo docker builder prune -a -f
- uses: actions/setup-go@v7
with:
go-version-file: go.mod
- name: check disk usage
run: df -h
- uses: goreleaser/goreleaser-action@v7
with:
version: latest
args: release --clean ${{ env.SNAPSHOT }}
# Publish a signed packslip (https://packslip.dev) listing each archive's
# digest, the helmfile executable inside it, its shell completions, and the
# skill in skills/helmfile, signed with this workflow's identity so
# installers can verify a download without a key this project must hold.
packslip:
needs: goreleaser
if: startsWith(github.ref, 'refs/tags/v')
runs-on: ubuntu-latest
permissions:
contents: write
id-token: write
attestations: write
steps:
- uses: jdx/packslip@v1
with:
download: helmfile_*.tar.gz
bin: helmfile
resources: |
completion/bash,zsh,fish,powershell=exec:helmfile completion {shell}
skill/helmfile=repo:skills/helmfile