| @@ -2,13 +2,27 @@ |
| 2 | 2 | |
| 3 | 3 | Read the content below for the release process. |
| 4 | 4 | |
| 5 | ** Where the repository lives |
| 6 | =origin= is gitbay (=ssh://git@gitbay.org/krz/orgo.git=), which is where the issues and |
| 7 | merge requests are. It push-mirrors to =https://github.com/krazywarez/orgo=, tags |
| 8 | included. |
| 9 | |
| 10 | That mirror is what makes a release work. The automation is GitHub Actions and nothing |
| 11 | triggers it directly: a tag pushed to gitbay reaches GitHub within a minute, and |
| 12 | =.github/workflows/release.yml= runs there. =docs.yml= deploys the documentation site to |
| 13 | Pages the same way, on a push to =main= that touches =docs/=, =src/=, =Cargo.toml= or |
| 14 | =Cargo.lock=. |
| 15 | |
| 16 | Neither forge runs the tests. =ci.yml= is gone and there is no =.gitbay/ci.yml=, so the |
| 17 | checks in step 2 are the only gate a release passes. |
| 18 | |
| 5 | 19 | ** Before the first publish |
| 6 | 20 | Nothing to install and no token to store. The release workflow mints a short-lived |
| 7 | | crates.io token with OIDC, configured on crates.io against this repository, the |
| 21 | crates.io token with OIDC, configured on crates.io against the GitHub repository, the |
| 8 | 22 | =release.yml= workflow file and the =crates-io= environment that job runs in. |
| 9 | 23 | |
| 10 | | =repository= and =homepage= in =Cargo.toml= point at GitHub and at the documentation site |
| 11 | | on Pages. |
| 24 | =repository= in =Cargo.toml= points at gitbay; =homepage= points at the documentation |
| 25 | site on Pages. |
| 12 | 26 | |
| 13 | 27 | ** Every release |
| 14 | 28 | 1. Bump the version in =Cargo.toml=, and build once so =Cargo.lock= follows. |
| @@ -31,20 +45,34 @@ on Pages. |
| 31 | 45 | git push && git push --tags |
| 32 | 46 | #+end_src |
| 33 | 47 | |
| 34 | | 5. The tag push is the release. It builds binaries for macOS (arm64 and x86_64) and |
| 35 | | Linux (gnu and musl), opens a /draft/ GitHub release with them attached, and runs |
| 36 | | =cargo publish --locked= — there is nothing to publish by hand, and running |
| 37 | | =cargo publish= locally now only fails on a version crates.io already has. |
| 48 | 5. The tag push is the release, by way of the mirror. It builds binaries for macOS |
| 49 | (arm64 and x86_64) and Linux (gnu and musl), opens a /draft/ GitHub release with them |
| 50 | attached, and runs =cargo publish --locked= — there is nothing to publish by hand, and |
| 51 | running =cargo publish= locally now only fails on a version crates.io already has. The |
| 52 | build checks the tag against =Cargo.toml= rather than trusting the two to match. |
| 53 | |
| 54 | =gh= talks to the mirror, so it is how you watch the run: |
| 55 | |
| 56 | #+begin_src sh |
| 57 | gh run list -R krazywarez/orgo --limit 3 |
| 58 | #+end_src |
| 38 | 59 | |
| 39 | 60 | Publishing is the one step that cannot be undone: a version can be yanked but never |
| 40 | 61 | replaced. The publish job runs in the =crates-io= environment so it can be held — |
| 41 | | add a required reviewer to that environment in the repository settings and a tag |
| 42 | | push waits for a human before it reaches crates.io. |
| 62 | add a required reviewer to that environment in the GitHub repository settings and a |
| 63 | tag push waits for a human before it reaches crates.io. |
| 43 | 64 | |
| 44 | 65 | A release that fails halfway is re-run from the Actions tab: the workflow takes the |
| 45 | 66 | tag to build as an input, so it does not need a second tag. |
| 46 | 67 | |
| 47 | | 6. Write the release notes and publish the draft. |
| 68 | 6. Write the release notes and publish the draft GitHub release. |
| 69 | 7. Release on gitbay, which has no automation of its own. Same notes, same binaries. |
| 70 | |
| 71 | #+begin_src sh |
| 72 | gitbay release create v0.18.0 --title 0.18.0 --file - < notes.md |
| 73 | gh release download v0.18.0 -R krazywarez/orgo -D dist |
| 74 | for f in dist/*; do gitbay release asset add v0.18.0 "$(basename "$f")" < "$f"; done |
| 75 | #+end_src |
| 48 | 76 | |
| 49 | 77 | ** If a release goes wrong |
| 50 | 78 | Yank rather than delete, and ship a fix as a new version: |