deploy/release.sh
47 lines · 1578 bytes · executable
1#!/bin/sh
2# Build release binaries for a tag: reproducible cross-compiled gitbay,
3# gitbayd and gitbay-runner, each gzipped, with a checksum manifest.
4#
5# git checkout v0.2.0 && ./deploy/release.sh v0.2.0
6#
7# Reproducibility: CGO off, -trimpath, stripped, empty build id; the VCS
8# revision embedded by the toolchain is deterministic per commit. Anyone on
9# the same Go toolchain and commit gets byte-identical binaries; compare
10# against the decompressed asset, since gzip output varies by implementation.
11set -eu
12
13V="${1:-}"
14[ -n "$V" ] || { echo "usage: $0 <version-tag>" >&2; exit 2; }
15
16out="dist/release/$V"
17rm -rf "$out"
18mkdir -p "$out"
19
20for target in linux/amd64 linux/arm64 darwin/arm64; do
21 goos="${target%/*}"
22 goarch="${target#*/}"
23 for bin in gitbay gitbayd gitbay-runner; do
24 name="${bin}-${V}-${goos}-${goarch}"
25 echo "building $name"
26 CGO_ENABLED=0 GOOS="$goos" GOARCH="$goarch" \
27 go build -trimpath -ldflags='-s -w -buildid=' \
28 -o "$out/$name" "./cmd/$bin"
29 gzip -n -9 "$out/$name"
30 done
31done
32
33cd "$out"
34if command -v sha256sum >/dev/null 2>&1; then
35 sha256sum -- * > SHA256SUMS
36else
37 shasum -a 256 -- * > SHA256SUMS
38fi
39echo "wrote $out/SHA256SUMS"
40
41# Optional detached signature over the manifest. Set MINISIGN_KEY to a
42# minisign secret key path to sign; downloaders verify with the public key.
43if [ -n "${MINISIGN_KEY:-}" ] && command -v minisign >/dev/null 2>&1; then
44 minisign -S -s "$MINISIGN_KEY" -m SHA256SUMS
45 echo "signed SHA256SUMS -> SHA256SUMS.minisig"
46fi
47cat SHA256SUMS