Commit 76385afe09
76385afe09eca57cb2b47f0a17b56c8bf6e3fd4c
parent: fecbf2c9d0
Verified · cmc ci/build: success ci/test: success
cmc <hello@cleberg.net> · 2026-10-02 14:30 UTC
release: gzip each binary
SHA256SUMS covers the archives. About 117 MB a release becomes 46 MB.
Closes #321
Layout: unified · split
.gitbay/wiki/Admin.org
+4 −3
| @@ -9,11 +9,12 @@ startup and on every admin command. |
| 9 | Build from source (=go build ./cmd/gitbayd=), install via the vanity |
9 | Build from source (=go build ./cmd/gitbayd=), install via the vanity |
| 10 | module path (=go install gitbay.org/gitbay/cmd/gitbayd@latest=), or use |
10 | module path (=go install gitbay.org/gitbay/cmd/gitbayd@latest=), or use |
| 11 | a release build: =deploy/release.sh <tag>= cross-compiles reproducible |
11 | a release build: =deploy/release.sh <tag>= cross-compiles reproducible |
| 12 | linux/amd64, linux/arm64, and darwin/arm64 binaries with a SHA256SUMS |
12 | linux/amd64, linux/arm64, and darwin/arm64 binaries, each gzipped, with |
| 13 | manifest (CGO off, trimpath, stripped — byte-identical per commit and |
13 | a SHA256SUMS manifest over the =.gz= files (CGO off, trimpath, stripped — |
| 14 | toolchain). |
14 | the decompressed binary is byte-identical per commit and toolchain). |
| 15 | |
15 | |
| 16 | #+begin_src sh |
16 | #+begin_src sh |
| |
17 | gunzip -c gitbayd-<tag>-linux-amd64.gz > gitbayd |
| 17 | install -m 755 gitbayd /usr/local/bin/ |
18 | install -m 755 gitbayd /usr/local/bin/ |
| 18 | adduser --system --group --home /var/lib/gitbay --shell /usr/sbin/nologin gitbay |
19 | adduser --system --group --home /var/lib/gitbay --shell /usr/sbin/nologin gitbay |
| 19 | install -d -o gitbay -g gitbay -m 750 /var/lib/gitbay |
20 | install -d -o gitbay -g gitbay -m 750 /var/lib/gitbay |
.gitbay/wiki/Architecture/07-CI-and-Supply-Chain.org
+1 −1
| @@ -89,7 +89,7 @@ Who may do what: |
| 89 | | CI | =build= (build, vet) and =test= (full suite against real git, ssh, sshd, gpg) on every push; =vuln= (govulncheck) nightly and before release (=.gitbay/ci.yml=) | |
89 | | CI | =build= (build, vet) and =test= (full suite against real git, ssh, sshd, gpg) on every push; =vuln= (govulncheck) nightly and before release (=.gitbay/ci.yml=) | |
| 90 | | Static checks | =deploy/audit.sh=: vet, govulncheck, short fuzz runs of the pkt-line, commit, signature, PGP key and tokenizer parsers | |
90 | | Static checks | =deploy/audit.sh=: vet, govulncheck, short fuzz runs of the pkt-line, commit, signature, PGP key and tokenizer parsers | |
| 91 | | Build | =CGO_ENABLED=0 -trimpath -ldflags='-s -w -buildid='= for reproducible binaries; the commit is stamped in (=deploy/release.sh=, =Makefile=) | |
91 | | Build | =CGO_ENABLED=0 -trimpath -ldflags='-s -w -buildid='= for reproducible binaries; the commit is stamped in (=deploy/release.sh=, =Makefile=) | |
| 92 | | Release | =SHA256SUMS= for every binary; a minisign signature of the manifest when the release key is present (optional) | |
92 | | Release | binaries gzipped; =SHA256SUMS= for every archive; a minisign signature of the manifest when the release key is present (optional) | |
| 93 | | Distribution | release assets on the forge; Homebrew formula in krz/homebrew-tap built from the tag; push mirror to GitHub (read-only copy) | |
93 | | Distribution | release assets on the forge; Homebrew formula in krz/homebrew-tap built from the tag; push mirror to GitHub (read-only copy) | |
| 94 | | Deploy | =make deploy= refuses a dirty tree, then copies, checks config and restarts over operator SSH | |
94 | | Deploy | =make deploy= refuses a dirty tree, then copies, checks config and restarts over operator SSH | |
| 95 | | CI image | built on the host from =deploy/Containerfile.ci= (=golang:1.27-trixie= plus git-lfs, gnupg, openssh, python3, sqlite3); tagged, never pulled at build time | |
95 | | CI image | built on the host from =deploy/Containerfile.ci= (=golang:1.27-trixie= plus git-lfs, gnupg, openssh, python3, sqlite3); tagged, never pulled at build time | |
deploy/release.sh
+4 −2
| @@ -1,12 +1,13 @@ |
| 1 | #!/bin/sh |
1 | #!/bin/sh |
| 2 | # Build release binaries for a tag: reproducible cross-compiled gitbay, |
2 | # Build release binaries for a tag: reproducible cross-compiled gitbay, |
| 3 | # gitbayd and gitbay-runner with a checksum manifest. |
3 | # gitbayd and gitbay-runner, each gzipped, with a checksum manifest. |
| 4 | # |
4 | # |
| 5 | # git checkout v0.2.0 && ./deploy/release.sh v0.2.0 |
5 | # git checkout v0.2.0 && ./deploy/release.sh v0.2.0 |
| 6 | # |
6 | # |
| 7 | # Reproducibility: CGO off, -trimpath, stripped, empty build id; the VCS |
7 | # Reproducibility: CGO off, -trimpath, stripped, empty build id; the VCS |
| 8 | # revision embedded by the toolchain is deterministic per commit. Anyone on |
8 | # revision embedded by the toolchain is deterministic per commit. Anyone on |
| 9 | # the same Go toolchain and commit gets byte-identical binaries. |
9 | # the same Go toolchain and commit gets byte-identical binaries; compare |
| |
10 | # against the decompressed asset, since gzip output varies by implementation. |
| 10 | set -eu |
11 | set -eu |
| 11 | |
12 | |
| 12 | V="${1:-}" |
13 | V="${1:-}" |
| @@ -25,6 +26,7 @@ for target in linux/amd64 linux/arm64 darwin/arm64; do |
| 25 | CGO_ENABLED=0 GOOS="$goos" GOARCH="$goarch" \ |
26 | CGO_ENABLED=0 GOOS="$goos" GOARCH="$goarch" \ |
| 26 | go build -trimpath -ldflags='-s -w -buildid=' \ |
27 | go build -trimpath -ldflags='-s -w -buildid=' \ |
| 27 | -o "$out/$name" "./cmd/$bin" |
28 | -o "$out/$name" "./cmd/$bin" |
| |
29 | gzip -n -9 "$out/$name" |
| 28 | done |
30 | done |
| 29 | done |
31 | done |
| 30 | |
32 | |