Refactor publish and finalize conditions in workflow

Updated conditions for publishing and finalizing outcomes in the CI workflow.
This commit is contained in:
clsferguson 2025-09-10 21:05:46 -06:00 committed by GitHub
parent b1552e1dc2
commit a86c49b5ff
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -22,6 +22,7 @@ jobs:
with: with:
fetch-depth: 0 fetch-depth: 0
fetch-tags: true fetch-tags: true
- name: Install prerequisites (jq, curl, git) - name: Install prerequisites (jq, curl, git)
run: | run: |
set -e set -e
@ -29,6 +30,7 @@ jobs:
sudo apt-get update -y sudo apt-get update -y
sudo apt-get install -y jq curl git sudo apt-get install -y jq curl git
fi fi
- name: Check for New Upstream Release - name: Check for New Upstream Release
id: check_version id: check_version
shell: bash shell: bash
@ -41,6 +43,7 @@ jobs:
else else
echo "new_version=none" >> "$GITHUB_OUTPUT" echo "new_version=none" >> "$GITHUB_OUTPUT"
fi fi
- name: Cleanup workspace (always, scoped) - name: Cleanup workspace (always, scoped)
if: ${{ always() }} if: ${{ always() }}
run: | run: |
@ -58,10 +61,12 @@ jobs:
with: with:
fetch-depth: 0 fetch-depth: 0
fetch-tags: true fetch-tags: true
- name: Set Git Config - name: Set Git Config
run: | run: |
git config --global user.name "GitHub Actions" git config --global user.name "GitHub Actions"
git config --global user.email "actions@github.com" git config --global user.email "actions@github.com"
- name: Sync with Upstream (idempotent) - name: Sync with Upstream (idempotent)
run: | run: |
set -euo pipefail set -euo pipefail
@ -78,10 +83,12 @@ jobs:
git add README.md git add README.md
git commit -m "Merge upstream/master, keep local README.md" || true git commit -m "Merge upstream/master, keep local README.md" || true
git push origin master git push origin master
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3 uses: docker/setup-buildx-action@v3
with: with:
cleanup: true cleanup: true
- name: Check CR_PAT secret - name: Check CR_PAT secret
id: crpat id: crpat
shell: bash shell: bash
@ -91,6 +98,7 @@ jobs:
else else
echo "present=false" >> "$GITHUB_OUTPUT" echo "present=false" >> "$GITHUB_OUTPUT"
fi fi
- name: Login to GHCR with GITHUB_TOKEN - name: Login to GHCR with GITHUB_TOKEN
if: ${{ steps.crpat.outputs.present == 'false' }} if: ${{ steps.crpat.outputs.present == 'false' }}
uses: docker/login-action@v3 uses: docker/login-action@v3
@ -98,6 +106,7 @@ jobs:
registry: ghcr.io registry: ghcr.io
username: ${{ github.actor }} username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }} password: ${{ secrets.GITHUB_TOKEN }}
- name: Login to GHCR with CR_PAT - name: Login to GHCR with CR_PAT
if: ${{ steps.crpat.outputs.present == 'true' }} if: ${{ steps.crpat.outputs.present == 'true' }}
uses: docker/login-action@v3 uses: docker/login-action@v3
@ -105,6 +114,7 @@ jobs:
registry: ghcr.io registry: ghcr.io
username: ${{ github.repository_owner }} username: ${{ github.repository_owner }}
password: ${{ secrets.CR_PAT }} password: ${{ secrets.CR_PAT }}
- name: Free disk space (best effort) - name: Free disk space (best effort)
continue-on-error: true continue-on-error: true
run: | run: |
@ -112,6 +122,7 @@ jobs:
sudo rm -rf /usr/local/lib/android || true sudo rm -rf /usr/local/lib/android || true
sudo rm -rf /opt/ghc || true sudo rm -rf /opt/ghc || true
sudo rm -rf /opt/hostedtoolcache/CodeQL || true sudo rm -rf /opt/hostedtoolcache/CodeQL || true
- name: Build and Push (GH runner) - name: Build and Push (GH runner)
uses: docker/build-push-action@v6 uses: docker/build-push-action@v6
with: with:
@ -132,10 +143,12 @@ jobs:
with: with:
fetch-depth: 0 fetch-depth: 0
fetch-tags: true fetch-tags: true
- name: Set Git Config - name: Set Git Config
run: | run: |
git config --global user.name "GitHub Actions" git config --global user.name "GitHub Actions"
git config --global user.email "actions@github.com" git config --global user.email "actions@github.com"
- name: Sync with Upstream (idempotent) - name: Sync with Upstream (idempotent)
run: | run: |
set -euo pipefail set -euo pipefail
@ -152,10 +165,12 @@ jobs:
git add README.md git add README.md
git commit -m "Merge upstream/master, keep local README.md" || true git commit -m "Merge upstream/master, keep local README.md" || true
git push origin master git push origin master
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3 uses: docker/setup-buildx-action@v3
with: with:
cleanup: true cleanup: true
- name: Check CR_PAT secret - name: Check CR_PAT secret
id: crpat id: crpat
shell: bash shell: bash
@ -165,6 +180,7 @@ jobs:
else else
echo "present=false" >> "$GITHUB_OUTPUT" echo "present=false" >> "$GITHUB_OUTPUT"
fi fi
- name: Login to GHCR with GITHUB_TOKEN - name: Login to GHCR with GITHUB_TOKEN
if: ${{ steps.crpat.outputs.present == 'false' }} if: ${{ steps.crpat.outputs.present == 'false' }}
uses: docker/login-action@v3 uses: docker/login-action@v3
@ -172,6 +188,7 @@ jobs:
registry: ghcr.io registry: ghcr.io
username: ${{ github.actor }} username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }} password: ${{ secrets.GITHUB_TOKEN }}
- name: Login to GHCR with CR_PAT - name: Login to GHCR with CR_PAT
if: ${{ steps.crpat.outputs.present == 'true' }} if: ${{ steps.crpat.outputs.present == 'true' }}
uses: docker/login-action@v3 uses: docker/login-action@v3
@ -179,6 +196,7 @@ jobs:
registry: ghcr.io registry: ghcr.io
username: ${{ github.repository_owner }} username: ${{ github.repository_owner }}
password: ${{ secrets.CR_PAT }} password: ${{ secrets.CR_PAT }}
- name: Build and Push (self-hosted) - name: Build and Push (self-hosted)
uses: docker/build-push-action@v6 uses: docker/build-push-action@v6
with: with:
@ -188,12 +206,14 @@ jobs:
tags: | tags: |
${{ env.IMAGE_NAME }}:${{ needs.check-upstream.outputs.new_version }} ${{ env.IMAGE_NAME }}:${{ needs.check-upstream.outputs.new_version }}
${{ env.IMAGE_NAME }}:latest ${{ env.IMAGE_NAME }}:latest
- name: Remove BuildKit image (moby/buildkit) - name: Remove BuildKit image (moby/buildkit)
if: ${{ always() }} if: ${{ always() }}
shell: bash shell: bash
run: | run: |
set -euxo pipefail set -euxo pipefail
docker image rm -f $(docker images 'moby/buildkit*' -q) 2>/dev/null || true docker image rm -f $(docker images 'moby/buildkit*' -q) 2>/dev/null || true
- name: Cleanup (always, scoped) - name: Cleanup (always, scoped)
if: ${{ always() }} if: ${{ always() }}
run: | run: |
@ -206,8 +226,11 @@ jobs:
name: Publish Release name: Publish Release
needs: [check-upstream, build-gh, build-self] needs: [check-upstream, build-gh, build-self]
if: | if: |
needs.check-upstream.outputs.new_version != 'none' && ${{
(needs.build-gh.result == 'success' || needs.build-self.result == 'success') always() &&
needs.check-upstream.outputs.new_version != 'none' &&
(needs.build-gh.result == 'success' || needs.build-self.result == 'success')
}}
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Create GitHub Release - name: Create GitHub Release
@ -225,7 +248,7 @@ jobs:
finalize: finalize:
name: Finalize Outcome name: Finalize Outcome
needs: [check-upstream, build-gh, build-self, publish] needs: [check-upstream, build-gh, build-self, publish]
if: needs.check-upstream.outputs.new_version != 'none' if: ${{ always() && needs.check-upstream.outputs.new_version != 'none' }}
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Fail if no build path succeeded - name: Fail if no build path succeeded