deploy/release.sh

e2a32d5f8d59e4213571c602bd9009b6c8fa86ed
gitbay/deploy/release.sh history · blame · raw

45 lines · 1445 bytes · executable

 1#!/bin/sh
 2# Build release binaries for a tag: reproducible cross-compiled gitbay,
 3# gitbayd and gitbay-runner with a checksum manifest.
 4#
 5#   git checkout v0.2.0 && ./deploy/release.sh v0.2.0
 6#
 7# Reproducibility: CGO off, -trimpath, stripped, empty build id; the VCS
 8# revision embedded by the toolchain is deterministic per commit. Anyone on
 9# the same Go toolchain and commit gets byte-identical binaries.
10set -eu
11
12V="${1:-}"
13[ -n "$V" ] || { echo "usage: $0 <version-tag>" >&2; exit 2; }
14
15out="dist/release/$V"
16rm -rf "$out"
17mkdir -p "$out"
18
19for target in linux/amd64 linux/arm64 darwin/arm64; do
20    goos="${target%/*}"
21    goarch="${target#*/}"
22    for bin in gitbay gitbayd gitbay-runner; do
23        name="${bin}-${V}-${goos}-${goarch}"
24        echo "building $name"
25        CGO_ENABLED=0 GOOS="$goos" GOARCH="$goarch" \
26            go build -trimpath -ldflags='-s -w -buildid=' \
27            -o "$out/$name" "./cmd/$bin"
28    done
29done
30
31cd "$out"
32if command -v sha256sum >/dev/null 2>&1; then
33    sha256sum -- * > SHA256SUMS
34else
35    shasum -a 256 -- * > SHA256SUMS
36fi
37echo "wrote $out/SHA256SUMS"
38
39# Optional detached signature over the manifest. Set MINISIGN_KEY to a
40# minisign secret key path to sign; downloaders verify with the public key.
41if [ -n "${MINISIGN_KEY:-}" ] && command -v minisign >/dev/null 2>&1; then
42    minisign -S -s "$MINISIGN_KEY" -m SHA256SUMS
43    echo "signed SHA256SUMS -> SHA256SUMS.minisig"
44fi
45cat SHA256SUMS