deploy/release.sh

main
gitbay/deploy/release.sh history · blame · raw

47 lines · 1578 bytes · executable

 1#!/bin/sh
 2# Build release binaries for a tag: reproducible cross-compiled gitbay,
 3# gitbayd and gitbay-runner, each gzipped, with a checksum manifest.
 4#
 5#   git checkout v0.2.0 && ./deploy/release.sh v0.2.0
 6#
 7# Reproducibility: CGO off, -trimpath, stripped, empty build id; the VCS
 8# revision embedded by the toolchain is deterministic per commit. Anyone on
 9# the same Go toolchain and commit gets byte-identical binaries; compare
10# against the decompressed asset, since gzip output varies by implementation.
11set -eu
12
13V="${1:-}"
14[ -n "$V" ] || { echo "usage: $0 <version-tag>" >&2; exit 2; }
15
16out="dist/release/$V"
17rm -rf "$out"
18mkdir -p "$out"
19
20for target in linux/amd64 linux/arm64 darwin/arm64; do
21    goos="${target%/*}"
22    goarch="${target#*/}"
23    for bin in gitbay gitbayd gitbay-runner; do
24        name="${bin}-${V}-${goos}-${goarch}"
25        echo "building $name"
26        CGO_ENABLED=0 GOOS="$goos" GOARCH="$goarch" \
27            go build -trimpath -ldflags='-s -w -buildid=' \
28            -o "$out/$name" "./cmd/$bin"
29        gzip -n -9 "$out/$name"
30    done
31done
32
33cd "$out"
34if command -v sha256sum >/dev/null 2>&1; then
35    sha256sum -- * > SHA256SUMS
36else
37    shasum -a 256 -- * > SHA256SUMS
38fi
39echo "wrote $out/SHA256SUMS"
40
41# Optional detached signature over the manifest. Set MINISIGN_KEY to a
42# minisign secret key path to sign; downloaders verify with the public key.
43if [ -n "${MINISIGN_KEY:-}" ] && command -v minisign >/dev/null 2>&1; then
44    minisign -S -s "$MINISIGN_KEY" -m SHA256SUMS
45    echo "signed SHA256SUMS -> SHA256SUMS.minisig"
46fi
47cat SHA256SUMS