Commit 76385afe09

76385afe09eca57cb2b47f0a17b56c8bf6e3fd4c

parent: fecbf2c9d0

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-10-02 14:30 UTC

release: gzip each binary

SHA256SUMS covers the archives. About 117 MB a release becomes 46 MB.

Closes #321

Layout: unified · split

.gitbay/wiki/Admin.org +4 −3
@@ -9,11 +9,12 @@ startup and on every admin command.
9Build from source (=go build ./cmd/gitbayd=), install via the vanity 9Build from source (=go build ./cmd/gitbayd=), install via the vanity
10module path (=go install gitbay.org/gitbay/cmd/gitbayd@latest=), or use 10module path (=go install gitbay.org/gitbay/cmd/gitbayd@latest=), or use
11a release build: =deploy/release.sh <tag>= cross-compiles reproducible 11a release build: =deploy/release.sh <tag>= cross-compiles reproducible
12linux/amd64, linux/arm64, and darwin/arm64 binaries with a SHA256SUMS 12linux/amd64, linux/arm64, and darwin/arm64 binaries, each gzipped, with
13manifest (CGO off, trimpath, stripped — byte-identical per commit and 13a SHA256SUMS manifest over the =.gz= files (CGO off, trimpath, stripped —
14toolchain). 14the decompressed binary is byte-identical per commit and toolchain).
15 15
16#+begin_src sh 16#+begin_src sh
17gunzip -c gitbayd-<tag>-linux-amd64.gz > gitbayd
17install -m 755 gitbayd /usr/local/bin/ 18install -m 755 gitbayd /usr/local/bin/
18adduser --system --group --home /var/lib/gitbay --shell /usr/sbin/nologin gitbay 19adduser --system --group --home /var/lib/gitbay --shell /usr/sbin/nologin gitbay
19install -d -o gitbay -g gitbay -m 750 /var/lib/gitbay 20install -d -o gitbay -g gitbay -m 750 /var/lib/gitbay
.gitbay/wiki/Architecture/07-CI-and-Supply-Chain.org +1 −1
@@ -89,7 +89,7 @@ Who may do what:
89| CI | =build= (build, vet) and =test= (full suite against real git, ssh, sshd, gpg) on every push; =vuln= (govulncheck) nightly and before release (=.gitbay/ci.yml=) | 89| CI | =build= (build, vet) and =test= (full suite against real git, ssh, sshd, gpg) on every push; =vuln= (govulncheck) nightly and before release (=.gitbay/ci.yml=) |
90| Static checks | =deploy/audit.sh=: vet, govulncheck, short fuzz runs of the pkt-line, commit, signature, PGP key and tokenizer parsers | 90| Static checks | =deploy/audit.sh=: vet, govulncheck, short fuzz runs of the pkt-line, commit, signature, PGP key and tokenizer parsers |
91| Build | =CGO_ENABLED=0 -trimpath -ldflags='-s -w -buildid='= for reproducible binaries; the commit is stamped in (=deploy/release.sh=, =Makefile=) | 91| Build | =CGO_ENABLED=0 -trimpath -ldflags='-s -w -buildid='= for reproducible binaries; the commit is stamped in (=deploy/release.sh=, =Makefile=) |
92| Release | =SHA256SUMS= for every binary; a minisign signature of the manifest when the release key is present (optional) | 92| Release | binaries gzipped; =SHA256SUMS= for every archive; a minisign signature of the manifest when the release key is present (optional) |
93| Distribution | release assets on the forge; Homebrew formula in krz/homebrew-tap built from the tag; push mirror to GitHub (read-only copy) | 93| Distribution | release assets on the forge; Homebrew formula in krz/homebrew-tap built from the tag; push mirror to GitHub (read-only copy) |
94| Deploy | =make deploy= refuses a dirty tree, then copies, checks config and restarts over operator SSH | 94| Deploy | =make deploy= refuses a dirty tree, then copies, checks config and restarts over operator SSH |
95| CI image | built on the host from =deploy/Containerfile.ci= (=golang:1.27-trixie= plus git-lfs, gnupg, openssh, python3, sqlite3); tagged, never pulled at build time | 95| CI image | built on the host from =deploy/Containerfile.ci= (=golang:1.27-trixie= plus git-lfs, gnupg, openssh, python3, sqlite3); tagged, never pulled at build time |
deploy/release.sh +4 −2
@@ -1,12 +1,13 @@
1#!/bin/sh 1#!/bin/sh
2# Build release binaries for a tag: reproducible cross-compiled gitbay, 2# Build release binaries for a tag: reproducible cross-compiled gitbay,
3# gitbayd and gitbay-runner with a checksum manifest. 3# gitbayd and gitbay-runner, each gzipped, with a checksum manifest.
4# 4#
5# git checkout v0.2.0 && ./deploy/release.sh v0.2.0 5# git checkout v0.2.0 && ./deploy/release.sh v0.2.0
6# 6#
7# Reproducibility: CGO off, -trimpath, stripped, empty build id; the VCS 7# Reproducibility: CGO off, -trimpath, stripped, empty build id; the VCS
8# revision embedded by the toolchain is deterministic per commit. Anyone on 8# revision embedded by the toolchain is deterministic per commit. Anyone on
9# the same Go toolchain and commit gets byte-identical binaries. 9# the same Go toolchain and commit gets byte-identical binaries; compare
10# against the decompressed asset, since gzip output varies by implementation.
10set -eu 11set -eu
11 12
12V="${1:-}" 13V="${1:-}"
@@ -25,6 +26,7 @@ for target in linux/amd64 linux/arm64 darwin/arm64; do
25 CGO_ENABLED=0 GOOS="$goos" GOARCH="$goarch" \ 26 CGO_ENABLED=0 GOOS="$goos" GOARCH="$goarch" \
26 go build -trimpath -ldflags='-s -w -buildid=' \ 27 go build -trimpath -ldflags='-s -w -buildid=' \
27 -o "$out/$name" "./cmd/$bin" 28 -o "$out/$name" "./cmd/$bin"
29 gzip -n -9 "$out/$name"
28 done 30 done
29done 31done
30 32