mirror of
https://github.com/helmfile/helmfile.git
synced 2026-10-05 11:31:54 +02:00
* ci: publish a signed packslip with each release Add a job after goreleaser that publishes a packslip.sigstore.json to tag releases: a manifest of the release archives, the helmfile executable in each, shell completions via `helmfile completion`, and the skills/helmfile agent skill at the release commit, signed keylessly with this workflow's OIDC identity and linked to build provenance. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: jdx <216188+jdx@users.noreply.github.com> * ci: include the 386 archives in the packslip packslip 1.4.0 reads goreleaser's 386 as i686 and leaves libc out for static Linux builds, so every archive can be listed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: jdx <216188+jdx@users.noreply.github.com> --------- Signed-off-by: jdx <216188+jdx@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
69 lines
1.8 KiB
YAML
69 lines
1.8 KiB
YAML
name: GoReleaser
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- 'v0*'
|
|
- 'v1*'
|
|
branches:
|
|
- 'main'
|
|
pull_request:
|
|
branches:
|
|
- 'main'
|
|
|
|
permissions:
|
|
contents: write
|
|
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
SNAPSHOT: ${{ !startsWith(github.ref, 'refs/tags/v') && '--snapshot' || '' }}
|
|
|
|
jobs:
|
|
goreleaser:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
with:
|
|
fetch-depth: 0
|
|
- name: check disk usage
|
|
run: df -h
|
|
- name: cleanup disk
|
|
run: |
|
|
sudo rm -rf /usr/share/dotnet
|
|
sudo rm -rf /opt/ghc
|
|
sudo rm -rf /usr/local/share/boost
|
|
sudo rm -fr /usr/local/lib/android
|
|
sudo rm -fr /opt/hostedtoolcache/CodeQL
|
|
sudo docker image prune --all --force
|
|
sudo docker builder prune -a -f
|
|
- uses: actions/setup-go@v7
|
|
with:
|
|
go-version-file: go.mod
|
|
- name: check disk usage
|
|
run: df -h
|
|
- uses: goreleaser/goreleaser-action@v7
|
|
with:
|
|
version: latest
|
|
args: release --clean ${{ env.SNAPSHOT }}
|
|
|
|
# Publish a signed packslip (https://packslip.dev) listing each archive's
|
|
# digest, the helmfile executable inside it, its shell completions, and the
|
|
# skill in skills/helmfile, signed with this workflow's identity so
|
|
# installers can verify a download without a key this project must hold.
|
|
packslip:
|
|
needs: goreleaser
|
|
if: startsWith(github.ref, 'refs/tags/v')
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write
|
|
id-token: write
|
|
attestations: write
|
|
steps:
|
|
- uses: jdx/packslip@v1
|
|
with:
|
|
download: helmfile_*.tar.gz
|
|
bin: helmfile
|
|
resources: |
|
|
completion/bash,zsh,fish,powershell=exec:helmfile completion {shell}
|
|
skill/helmfile=repo:skills/helmfile
|