# Server RELEASE: on server-v* tags, builds static binaries and attaches them # to a Gitea release (the artifact --self-update consumes), and separately # builds + pushes the container image to the Gitea registry. # # Two independent jobs on purpose: the release job needs only Go + curl and # must succeed on any runner; the image job needs a Docker-capable runner and # may fail without taking the release down with it. # # Tags are namespaced (server-v1.2.3) so app releases (v*) and server # releases don't trigger each other's pipelines. # # Required secrets: # REGISTRY_TOKEN personal access token with read+write package scope — # the built-in Actions token is NOT accepted by the # container registry (docker login → unauthorized). # Create: user Settings → Applications → Generate token. # REGISTRY_USER optional; defaults to the pushing actor's username. # The release job needs only the built-in GITHUB_TOKEN. name: server-release on: push: tags: ["server-v*.*.*"] jobs: release: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-go@v5 with: { go-version: "1.26", cache-dependency-path: server/go.mod } - name: Derive version id: meta run: echo "version=${GITHUB_REF_NAME#server-}" >> "$GITHUB_OUTPUT" - name: Build static binaries (linux amd64+arm64) working-directory: server run: | for arch in amd64 arm64; do CGO_ENABLED=0 GOOS=linux GOARCH=$arch go build -trimpath \ -ldflags "-s -w -X main.Version=${{ steps.meta.outputs.version }}" \ -o "../dist/echolot-server_linux_${arch}" ./cmd/echolot-server done (cd ../dist && sha256sum * > SHA256SUMS) - name: Create release + attach binaries env: TOKEN: ${{ secrets.GITHUB_TOKEN }} API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }} run: | # Create the release; if it already exists (re-run), fetch it by tag. if ! REL=$(curl -sf -X POST "$API/releases" \ -H "Authorization: token $TOKEN" -H "Content-Type: application/json" \ -d "{\"tag_name\":\"$GITHUB_REF_NAME\",\"name\":\"$GITHUB_REF_NAME\"}"); then REL=$(curl -sf "$API/releases/tags/$GITHUB_REF_NAME" -H "Authorization: token $TOKEN") fi # jq-free id extraction. grep -o, NOT greedy sed: a greedy leading .* # matches the LAST "id" in the payload (a nested user/repo id) and # the uploads 404 — that broke the first v0.1.0 release run. ID=$(echo "$REL" | grep -o '"id":[0-9]*' | head -1 | cut -d: -f2) for f in dist/*; do # Tolerate re-runs: an existing asset of the same name may 4xx. curl -sf -X POST "$API/releases/$ID/assets?name=$(basename "$f")" \ -H "Authorization: token $TOKEN" -F "attachment=@$f" \ || echo "::warning::upload of $(basename "$f") failed (already attached?)" done image: # Dedicated docker-capable repo runner ("compilesau-echolot"). runs-on: echolot steps: - uses: actions/checkout@v4 - name: Derive version + registry coords id: meta run: | echo "version=${GITHUB_REF_NAME#server-}" >> "$GITHUB_OUTPUT" # GITHUB_SERVER_URL inside the runner is the INTERNAL url # (http://app:3000); the registry needs the public host so pulled # image references work outside. Env var overrides if it changes. HOST="${ECHOLOT_REGISTRY_HOST:-git.rambossek.at}" echo "host=$HOST" >> "$GITHUB_OUTPUT" echo "image=$HOST/${GITHUB_REPOSITORY,,}-server" >> "$GITHUB_OUTPUT" - name: Build + push image (needs a Docker-capable runner) env: REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }} REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }} run: | command -v docker >/dev/null || { echo "::error::no docker on this runner — image skipped; binaries/release are unaffected"; exit 1; } [ -n "$REGISTRY_TOKEN" ] || { echo "::error::secret REGISTRY_TOKEN missing — the registry rejects the built-in Actions token. Create a PAT with package read/write scope and add it under Settings → Actions → Secrets."; exit 1; } echo "$REGISTRY_TOKEN" | docker login "${{ steps.meta.outputs.host }}" -u "$REGISTRY_USER" --password-stdin docker build server \ --build-arg VERSION=${{ steps.meta.outputs.version }} \ -t "${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}" \ -t "${{ steps.meta.outputs.image }}:latest" docker push "${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}" docker push "${{ steps.meta.outputs.image }}:latest"