# Server RELEASE: on server-v* tags builds # and pushes the container image to the Gitea registry AND attaches static # binaries to a Gitea release (the artifact --self-update consumes). # # Tags are namespaced (server-v1.2.3) so app releases (v*) and server # releases don't trigger each other's pipelines. # # Required secrets: none beyond the built-in GITHUB_TOKEN — it can push to # the registry of its own repo and create releases. name: server-release on: push: tags: ["server-v*.*.*"] jobs: release: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-go@v5 with: { go-version: "1.26", cache-dependency-path: server/go.mod } - name: Derive version + registry coords id: meta run: | echo "version=${GITHUB_REF_NAME#server-}" >> "$GITHUB_OUTPUT" HOST="${GITHUB_SERVER_URL#https://}" echo "image=$HOST/${GITHUB_REPOSITORY,,}-server" >> "$GITHUB_OUTPUT" - name: Build static binaries (linux amd64+arm64) working-directory: server run: | for arch in amd64 arm64; do CGO_ENABLED=0 GOOS=linux GOARCH=$arch go build -trimpath \ -ldflags "-s -w -X main.Version=${{ steps.meta.outputs.version }}" \ -o "../dist/echolot-server_linux_${arch}" ./cmd/echolot-server done (cd ../dist && sha256sum * > SHA256SUMS) - name: Build + push image run: | echo "${{ secrets.GITHUB_TOKEN }}" | docker login "${GITHUB_SERVER_URL#https://}" -u "$GITHUB_ACTOR" --password-stdin docker build server \ --build-arg VERSION=${{ steps.meta.outputs.version }} \ -t "${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}" \ -t "${{ steps.meta.outputs.image }}:latest" docker push "${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}" docker push "${{ steps.meta.outputs.image }}:latest" - name: Create release + attach binaries env: TOKEN: ${{ secrets.GITHUB_TOKEN }} API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }} run: | REL=$(curl -sf -X POST "$API/releases" \ -H "Authorization: token $TOKEN" -H "Content-Type: application/json" \ -d "{\"tag_name\":\"$GITHUB_REF_NAME\",\"name\":\"$GITHUB_REF_NAME\"}") ID=$(echo "$REL" | jq -r .id) for f in dist/*; do curl -sf -X POST "$API/releases/$ID/assets?name=$(basename "$f")" \ -H "Authorization: token $TOKEN" -F "attachment=@$f" done