Commit 76385afe09

76385afe09eca57cb2b47f0a17b56c8bf6e3fd4c

parent: fecbf2c9d0

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-10-02 14:30 UTC

release: gzip each binary

SHA256SUMS covers the archives. About 117 MB a release becomes 46 MB.

Closes #321

Layout: unified · split

.gitbay/wiki/Admin.org +4 −3
@@ -9,11 +9,12 @@ startup and on every admin command.
99Build from source (=go build ./cmd/gitbayd=), install via the vanity
1010module path (=go install gitbay.org/gitbay/cmd/gitbayd@latest=), or use
1111a release build: =deploy/release.sh <tag>= cross-compiles reproducible
12linux/amd64, linux/arm64, and darwin/arm64 binaries with a SHA256SUMS
13manifest (CGO off, trimpath, stripped — byte-identical per commit and
14toolchain).
12linux/amd64, linux/arm64, and darwin/arm64 binaries, each gzipped, with
13a SHA256SUMS manifest over the =.gz= files (CGO off, trimpath, stripped —
14the decompressed binary is byte-identical per commit and toolchain).
1515
1616#+begin_src sh
17gunzip -c gitbayd-<tag>-linux-amd64.gz > gitbayd
1718install -m 755 gitbayd /usr/local/bin/
1819adduser --system --group --home /var/lib/gitbay --shell /usr/sbin/nologin gitbay
1920install -d -o gitbay -g gitbay -m 750 /var/lib/gitbay
.gitbay/wiki/Architecture/07-CI-and-Supply-Chain.org +1 −1
@@ -89,7 +89,7 @@ Who may do what:
8989| CI | =build= (build, vet) and =test= (full suite against real git, ssh, sshd, gpg) on every push; =vuln= (govulncheck) nightly and before release (=.gitbay/ci.yml=) |
9090| Static checks | =deploy/audit.sh=: vet, govulncheck, short fuzz runs of the pkt-line, commit, signature, PGP key and tokenizer parsers |
9191| Build | =CGO_ENABLED=0 -trimpath -ldflags='-s -w -buildid='= for reproducible binaries; the commit is stamped in (=deploy/release.sh=, =Makefile=) |
92| Release | =SHA256SUMS= for every binary; a minisign signature of the manifest when the release key is present (optional) |
92| Release | binaries gzipped; =SHA256SUMS= for every archive; a minisign signature of the manifest when the release key is present (optional) |
9393| Distribution | release assets on the forge; Homebrew formula in krz/homebrew-tap built from the tag; push mirror to GitHub (read-only copy) |
9494| Deploy | =make deploy= refuses a dirty tree, then copies, checks config and restarts over operator SSH |
9595| CI image | built on the host from =deploy/Containerfile.ci= (=golang:1.27-trixie= plus git-lfs, gnupg, openssh, python3, sqlite3); tagged, never pulled at build time |
deploy/release.sh +4 −2
@@ -1,12 +1,13 @@
11#!/bin/sh
22# Build release binaries for a tag: reproducible cross-compiled gitbay,
3# gitbayd and gitbay-runner with a checksum manifest.
3# gitbayd and gitbay-runner, each gzipped, with a checksum manifest.
44#
55# git checkout v0.2.0 && ./deploy/release.sh v0.2.0
66#
77# Reproducibility: CGO off, -trimpath, stripped, empty build id; the VCS
88# revision embedded by the toolchain is deterministic per commit. Anyone on
9# the same Go toolchain and commit gets byte-identical binaries.
9# the same Go toolchain and commit gets byte-identical binaries; compare
10# against the decompressed asset, since gzip output varies by implementation.
1011set -eu
1112
1213V="${1:-}"
@@ -25,6 +26,7 @@ for target in linux/amd64 linux/arm64 darwin/arm64; do
2526 CGO_ENABLED=0 GOOS="$goos" GOARCH="$goarch" \
2627 go build -trimpath -ldflags='-s -w -buildid=' \
2728 -o "$out/$name" "./cmd/$bin"
29 gzip -n -9 "$out/$name"
2830 done
2931done
3032