| @@ -2,13 +2,27 @@ |
| 2 | |
2 | |
| 3 | Read the content below for the release process. |
3 | Read the content below for the release process. |
| 4 | |
4 | |
| |
5 | ** Where the repository lives |
| |
6 | =origin= is gitbay (=ssh://git@gitbay.org/krz/orgo.git=), which is where the issues and |
| |
7 | merge requests are. It push-mirrors to =https://github.com/krazywarez/orgo=, tags |
| |
8 | included. |
| |
9 | |
| |
10 | That mirror is what makes a release work. The automation is GitHub Actions and nothing |
| |
11 | triggers it directly: a tag pushed to gitbay reaches GitHub within a minute, and |
| |
12 | =.github/workflows/release.yml= runs there. =docs.yml= deploys the documentation site to |
| |
13 | Pages the same way, on a push to =main= that touches =docs/=, =src/=, =Cargo.toml= or |
| |
14 | =Cargo.lock=. |
| |
15 | |
| |
16 | Neither forge runs the tests. =ci.yml= is gone and there is no =.gitbay/ci.yml=, so the |
| |
17 | checks in step 2 are the only gate a release passes. |
| |
18 | |
| 5 | ** Before the first publish |
19 | ** Before the first publish |
| 6 | Nothing to install and no token to store. The release workflow mints a short-lived |
20 | Nothing to install and no token to store. The release workflow mints a short-lived |
| 7 | crates.io token with OIDC, configured on crates.io against this repository, the |
21 | crates.io token with OIDC, configured on crates.io against the GitHub repository, the |
| 8 | =release.yml= workflow file and the =crates-io= environment that job runs in. |
22 | =release.yml= workflow file and the =crates-io= environment that job runs in. |
| 9 | |
23 | |
| 10 | =repository= and =homepage= in =Cargo.toml= point at GitHub and at the documentation site |
24 | =repository= in =Cargo.toml= points at gitbay; =homepage= points at the documentation |
| 11 | on Pages. |
25 | site on Pages. |
| 12 | |
26 | |
| 13 | ** Every release |
27 | ** Every release |
| 14 | 1. Bump the version in =Cargo.toml=, and build once so =Cargo.lock= follows. |
28 | 1. Bump the version in =Cargo.toml=, and build once so =Cargo.lock= follows. |
| @@ -31,20 +45,34 @@ on Pages. |
| 31 | git push && git push --tags |
45 | git push && git push --tags |
| 32 | #+end_src |
46 | #+end_src |
| 33 | |
47 | |
| 34 | 5. The tag push is the release. It builds binaries for macOS (arm64 and x86_64) and |
48 | 5. The tag push is the release, by way of the mirror. It builds binaries for macOS |
| 35 | Linux (gnu and musl), opens a /draft/ GitHub release with them attached, and runs |
49 | (arm64 and x86_64) and Linux (gnu and musl), opens a /draft/ GitHub release with them |
| 36 | =cargo publish --locked= — there is nothing to publish by hand, and running |
50 | attached, and runs =cargo publish --locked= — there is nothing to publish by hand, and |
| 37 | =cargo publish= locally now only fails on a version crates.io already has. |
51 | running =cargo publish= locally now only fails on a version crates.io already has. The |
| |
52 | build checks the tag against =Cargo.toml= rather than trusting the two to match. |
| |
53 | |
| |
54 | =gh= talks to the mirror, so it is how you watch the run: |
| |
55 | |
| |
56 | #+begin_src sh |
| |
57 | gh run list -R krazywarez/orgo --limit 3 |
| |
58 | #+end_src |
| 38 | |
59 | |
| 39 | Publishing is the one step that cannot be undone: a version can be yanked but never |
60 | Publishing is the one step that cannot be undone: a version can be yanked but never |
| 40 | replaced. The publish job runs in the =crates-io= environment so it can be held — |
61 | replaced. The publish job runs in the =crates-io= environment so it can be held — |
| 41 | add a required reviewer to that environment in the repository settings and a tag |
62 | add a required reviewer to that environment in the GitHub repository settings and a |
| 42 | push waits for a human before it reaches crates.io. |
63 | tag push waits for a human before it reaches crates.io. |
| 43 | |
64 | |
| 44 | A release that fails halfway is re-run from the Actions tab: the workflow takes the |
65 | A release that fails halfway is re-run from the Actions tab: the workflow takes the |
| 45 | tag to build as an input, so it does not need a second tag. |
66 | tag to build as an input, so it does not need a second tag. |
| 46 | |
67 | |
| 47 | 6. Write the release notes and publish the draft. |
68 | 6. Write the release notes and publish the draft GitHub release. |
| |
69 | 7. Release on gitbay, which has no automation of its own. Same notes, same binaries. |
| |
70 | |
| |
71 | #+begin_src sh |
| |
72 | gitbay release create v0.18.0 --title 0.18.0 --file - < notes.md |
| |
73 | gh release download v0.18.0 -R krazywarez/orgo -D dist |
| |
74 | for f in dist/*; do gitbay release asset add v0.18.0 "$(basename "$f")" < "$f"; done |
| |
75 | #+end_src |
| 48 | |
76 | |
| 49 | ** If a release goes wrong |
77 | ** If a release goes wrong |
| 50 | Yank rather than delete, and ship a fix as a new version: |
78 | Yank rather than delete, and ship a fix as a new version: |