Skip to content

docs: add DeepWiki badge to README (#182) #128

docs: add DeepWiki badge to README (#182)

docs: add DeepWiki badge to README (#182) #128

Workflow file for this run

name: Release
on:
push:
branches: [main]
workflow_dispatch:
inputs:
dry_run:
description: "Perform a dry run (no actual release)"
type: boolean
default: false
permissions:
contents: read
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
env:
CARGO_TERM_COLOR: always
APP_NAME: rook
DOCKER_IMAGE: dallay/rook
jobs:
# ==========================================================================
# Release Please - Determine version
# ==========================================================================
release-please:
name: Release Please
runs-on: ubuntu-latest
outputs:
new_release_created: ${{ steps.release.outputs.release_created }}
release_version: ${{ steps.release.outputs.version }}
release_git_tag: ${{ steps.release.outputs.tag_name }}
steps:
- name: Generate GitHub App Token
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3
with:
app-id: ${{ secrets.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
with:
fetch-depth: 0
token: ${{ steps.app-token.outputs.token }}
- name: Release Please
id: release
uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5.0.0
with:
token: ${{ steps.app-token.outputs.token }}
config-file: release-please-config.json
target-branch: main
fork: false
# ==========================================================================
# Build Release Binaries - Cross-platform
# ==========================================================================
build-binaries:
name: Build (${{ matrix.target }})
needs: release-please
if: needs.release-please.outputs.new_release_created == 'true'
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
include:
# Linux
- target: x86_64-unknown-linux-gnu
os: ubuntu-latest
archive: tar.gz
- target: aarch64-unknown-linux-gnu
os: ubuntu-latest
archive: tar.gz
# macOS
- target: x86_64-apple-darwin
os: macos-latest
archive: tar.gz
- target: aarch64-apple-darwin
os: macos-latest
archive: tar.gz
# Windows
- target: x86_64-pc-windows-msvc
os: windows-latest
archive: zip
- target: aarch64-pc-windows-msvc
os: windows-latest
archive: zip
steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
with:
ref: ${{ needs.release-please.outputs.release_git_tag }}
- name: Install and configure gcc-12 (Linux)
if: runner.os == 'Linux'
run: |
for i in {1..5}; do
sudo apt-get update && \
sudo apt-get install -y gcc-12 g++-12 && break || sleep 5
if [ $i -eq 5 ]; then exit 1; fi
done
sudo update-alternatives --install /usr/bin/gcc gcc /usr/bin/gcc-12 60
sudo update-alternatives --install /usr/bin/g++ g++ /usr/bin/g++-12 60
gcc --version
g++ --version
- name: Setup Rust toolchain
uses: dtolnay/rust-toolchain@dd44c20b1206a46e25fba8503d5d7c9a33bd355a
with:
toolchain: stable
targets: ${{ matrix.target }}
- name: Install cross
if: runner.os == 'Linux' && matrix.target != 'x86_64-unknown-linux-gnu'
run: cargo install cross --git https://github.com/cross-rs/cross
- name: Build binary (Linux native)
if: runner.os == 'Linux' && matrix.target == 'x86_64-unknown-linux-gnu'
run: cargo build --release --target x86_64-unknown-linux-gnu -p rook
- name: Build binary (Linux with cross)
if: runner.os == 'Linux' && matrix.target != 'x86_64-unknown-linux-gnu'
run: cross build --release --target ${{ matrix.target }} -p rook
- name: Build binary (macOS/Windows)
if: runner.os != 'Linux'
run: cargo build --release --target ${{ matrix.target }} -p rook
- name: Prepare artifact (Unix)
if: runner.os != 'Windows'
run: |
cd target/${{ matrix.target }}/release
BINARY_NAME="rook"
ARCHIVE_NAME="rook-${{ needs.release-please.outputs.release_version }}-${{ matrix.target }}"
mkdir -p "$ARCHIVE_NAME"
cp "$BINARY_NAME" "$ARCHIVE_NAME/"
cp ../../../README.md "$ARCHIVE_NAME/" 2>/dev/null || true
cp ../../../LICENSE "$ARCHIVE_NAME/" 2>/dev/null || true
tar -czvf "$ARCHIVE_NAME.tar.gz" "$ARCHIVE_NAME"
shasum -a 256 "$ARCHIVE_NAME.tar.gz" > "$ARCHIVE_NAME.tar.gz.sha256"
mv "$ARCHIVE_NAME.tar.gz" ../../../
mv "$ARCHIVE_NAME.tar.gz.sha256" ../../../
- name: Prepare artifact (Windows)
if: runner.os == 'Windows'
shell: pwsh
run: |
cd target/${{ matrix.target }}/release
$BINARY_NAME = "rook.exe"
$ARCHIVE_NAME = "rook-${{ needs.release-please.outputs.release_version }}-${{ matrix.target }}"
New-Item -ItemType Directory -Force -Path $ARCHIVE_NAME
Copy-Item $BINARY_NAME -Destination "$ARCHIVE_NAME/"
Copy-Item ../../../README.md -Destination "$ARCHIVE_NAME/" -ErrorAction SilentlyContinue
Copy-Item ../../../LICENSE -Destination "$ARCHIVE_NAME/" -ErrorAction SilentlyContinue
Compress-Archive -Path $ARCHIVE_NAME -DestinationPath "$ARCHIVE_NAME.zip"
(Get-FileHash "$ARCHIVE_NAME.zip" -Algorithm SHA256).Hash.ToLower() + " $ARCHIVE_NAME.zip" | Out-File -FilePath "$ARCHIVE_NAME.zip.sha256" -Encoding ascii
Move-Item "$ARCHIVE_NAME.zip" ../../../
Move-Item "$ARCHIVE_NAME.zip.sha256" ../../..
- name: Upload artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: rook-${{ matrix.target }}
path: |
rook-*.${{ matrix.archive }}
rook-*.${{ matrix.archive }}.sha256
if-no-files-found: error
# ==========================================================================
# Upload Release Assets to GitHub
# ==========================================================================
upload-assets:
name: Upload Release Assets
needs: [release-please, build-binaries]
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Generate GitHub App Token
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3
with:
app-id: ${{ secrets.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
- name: Download all artifacts
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
path: artifacts
pattern: rook-*
merge-multiple: true
- name: List artifacts
run: ls -la artifacts/
- name: Upload to GitHub Release
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0
with:
tag_name: ${{ needs.release-please.outputs.release_git_tag }}
files: artifacts/*
env:
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
# ==========================================================================
# Publish NPM Platform-Specific Packages
# ==========================================================================
publish-npm-binaries:
name: Publish NPM (${{ matrix.config.name }})
needs: [release-please, build-binaries]
if: needs.release-please.outputs.new_release_created == 'true'
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
strategy:
fail-fast: false
matrix:
config:
- name: linux-x64
target: x86_64-unknown-linux-gnu
os: linux
arch: x64
- name: linux-arm64
target: aarch64-unknown-linux-gnu
os: linux
arch: arm64
- name: darwin-x64
target: x86_64-apple-darwin
os: darwin
arch: x64
- name: darwin-arm64
target: aarch64-apple-darwin
os: darwin
arch: arm64
- name: windows-x64
target: x86_64-pc-windows-msvc
os: win32
arch: x64
- name: windows-arm64
target: aarch64-pc-windows-msvc
os: win32
arch: arm64
steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
with:
ref: ${{ needs.release-please.outputs.release_git_tag }}
- name: Download artifact
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: rook-${{ matrix.config.target }}
path: artifacts
- name: Setup Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: "24.16"
registry-url: "https://registry.npmjs.org"
- name: Setup pnpm
uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093 # v6.0.8
with:
version: 11
- name: Verify npm authentication
run: |
echo "Checking npm authentication..."
npm whoami
npm config get registry
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
- name: Publish platform package to NPM
shell: bash
run: |
cd apps/rook/npm
export node_version="${{ needs.release-please.outputs.release_version }}"
export node_os="${{ matrix.config.os }}"
export node_arch="${{ matrix.config.arch }}"
export node_pkg="rook-${{ matrix.config.name }}"
if [[ "${{ matrix.config.os }}" == "win32" ]]; then
export node_bin="rook.exe"
else
export node_bin="rook"
fi
mkdir -p "${node_pkg}/bin"
# Generate package.json from template
envsubst < rook/package.json.tmpl > "${node_pkg}/package.json"
# Extract binary from artifact
cd ../../artifacts
if [[ "${{ matrix.config.os }}" == "win32" ]]; then
matches=(rook-*.zip)
EXTRACT_CMD="unzip -o"
else
matches=(rook-*.tar.gz)
EXTRACT_CMD="tar -xzvf"
fi
if [ ! -e "${matches[0]}" ]; then
echo "Error: No matching archive found"
ls -la
exit 1
fi
ARCHIVE="${matches[0]}"
echo "Found archive: $ARCHIVE"
if ! $EXTRACT_CMD "$ARCHIVE"; then
echo "Error: Failed to extract $ARCHIVE"
exit 1
fi
BINARY_PATH=$(find . -name "$node_bin" -type f | head -1)
if [ -z "$BINARY_PATH" ] || [ ! -f "$BINARY_PATH" ]; then
echo "Error: Could not find binary $node_bin after extraction"
exit 1
fi
echo "Found binary at: $BINARY_PATH"
cp "$BINARY_PATH" "../apps/rook/npm/${node_pkg}/bin/"
chmod +x "../apps/rook/npm/${node_pkg}/bin/$node_bin"
# Verify executable bit in packed tarball
pushd ../apps/rook/npm/${node_pkg} > /dev/null
npm pack --pack-destination /tmp > /dev/null
PKG_TGZ=$(ls -1 /tmp/*.tgz | tail -n1)
PATTERN="^-..x.{6}[[:space:]]+.*bin/${node_bin}\$"
if command -v rg >/dev/null 2>&1; then
SEARCHER=(rg)
else
SEARCHER=(grep -E)
fi
if ! tar -tzvf "$PKG_TGZ" | "${SEARCHER[@]}" "$PATTERN" >/dev/null; then
echo "Error: packaged binary does not have executable bit set. Aborting publish."
tar -tzvf "$PKG_TGZ"
exit 1
fi
popd > /dev/null
# Publish the package
cd "../apps/rook/npm/${node_pkg}"
echo "Publishing ${node_pkg}@${node_version}..."
pnpm publish --provenance --access public --no-git-checks
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
# ==========================================================================
# Publish NPM Base Package
# ==========================================================================
publish-npm-base:
name: Publish NPM Base Package
needs: [release-please, publish-npm-binaries]
if: needs.publish-npm-binaries.result == 'success'
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
with:
ref: ${{ needs.release-please.outputs.release_git_tag }}
- name: Setup Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: "24.16"
registry-url: "https://registry.npmjs.org"
- name: Setup pnpm
uses: pnpm/action-setup@0e279bb959325dab635dd2c09392533439d90093 # v6.0.8
with:
version: 11
- name: Verify npm authentication
run: |
echo "Checking npm authentication..."
npm whoami
npm config get registry
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
- name: Update package.json version
run: |
cd apps/rook/npm/rook
VERSION="${{ needs.release-please.outputs.release_version }}"
node -e "
const fs = require('fs');
const pkg = JSON.parse(fs.readFileSync('package.json', 'utf8'));
pkg.version = '${VERSION}';
for (const dep in pkg.optionalDependencies) {
pkg.optionalDependencies[dep] = '${VERSION}';
}
fs.writeFileSync('package.json', JSON.stringify(pkg, null, 2) + '\n');
"
cat package.json
- name: Install dependencies and build
run: |
cd apps/rook/npm/rook
pnpm install --no-frozen-lockfile
pnpm run build
- name: Publish base package to NPM
run: |
cd apps/rook/npm/rook
pnpm publish --provenance --access public --no-git-checks
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
# ==========================================================================
# Publish to crates.io
# ==========================================================================
publish-crates:
name: Publish to crates.io
needs: [release-please, build-binaries]
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
with:
ref: ${{ needs.release-please.outputs.release_git_tag }}
- name: Setup Rust toolchain
uses: dtolnay/rust-toolchain@dd44c20b1206a46e25fba8503d5d7c9a33bd355a
with:
toolchain: stable
- name: Publish to crates.io
run: cargo publish --locked
env:
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
# ==========================================================================
# Publish Docker Image - Uses pre-built Linux binaries from artifacts
# ==========================================================================
publish-docker:
name: Publish Docker Image
needs: [release-please, build-binaries]
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
with:
ref: ${{ needs.release-please.outputs.release_git_tag }}
- name: Set up QEMU
uses: docker/setup-qemu-action@06116385d9baf250c9f4dcb4858b16962ea869c3 # v4.1.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
- name: Login to Docker Hub
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Download Linux artifacts
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
path: artifacts
pattern: rook-*-unknown-linux-gnu
merge-multiple: true
- name: List artifacts
run: ls -la artifacts/
- name: Extract Linux binaries to docker-context
run: |
mkdir -p docker-context/amd64 docker-context/arm64
tar -xzvf artifacts/rook-*-x86_64-unknown-linux-gnu.tar.gz -C docker-context/amd64 --strip-components=1
tar -xzvf artifacts/rook-*-aarch64-unknown-linux-gnu.tar.gz -C docker-context/arm64 --strip-components=1
mv docker-context/amd64/rook docker-context/amd64/rook-amd64
chmod +x docker-context/amd64/rook-amd64
mv docker-context/arm64/rook docker-context/arm64/rook-arm64
chmod +x docker-context/arm64/rook-arm64
- name: Copy Dockerfile to docker-context
run: cp apps/rook/Dockerfile docker-context/
- name: Extract metadata for Docker
id: meta
uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6.1.0
with:
images: |
${{ secrets.DOCKERHUB_USERNAME }}/rook
ghcr.io/${{ github.repository }}
tags: |
type=semver,pattern={{version}},value=${{ needs.release-please.outputs.release_version }}
type=semver,pattern={{major}}.{{minor}},value=${{ needs.release-please.outputs.release_version }}
type=semver,pattern={{major}},value=${{ needs.release-please.outputs.release_version }}
type=raw,value=latest
- name: Build and push multi-platform Docker image
uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
with:
context: docker-context
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
cache-to: type=gha,mode=max
platforms: linux/amd64,linux/arm64
file: docker-context/Dockerfile
# ==========================================================================
# Release Summary
# ==========================================================================
release-summary:
name: Release Summary
needs: [release-please, build-binaries, upload-assets, publish-crates, publish-docker, publish-npm-base]
runs-on: ubuntu-latest
if: always() && needs.release-please.outputs.new_release_created == 'true'
steps:
- name: Generate Summary
run: |
{
echo "# πŸŽ‰ Rook Release Summary"
echo ""
echo "## Version: ${{ needs.release-please.outputs.release_version }}"
echo ""
echo "### Build Status"
echo ""
echo "| Component | Status |"
echo "|-----------|--------|"
echo "| Release Please | βœ… ${{ needs.release-please.result }} |"
echo "| Build Binaries | ${{ needs.build-binaries.result == 'success' && 'βœ…' || '❌' }} ${{ needs.build-binaries.result }} |"
echo "| Upload Assets | ${{ needs.upload-assets.result == 'success' && 'βœ…' || '❌' }} ${{ needs.upload-assets.result }} |"
echo "| Publish to crates.io | ${{ needs.publish-crates.result == 'success' && 'βœ…' || '❌' }} ${{ needs.publish-crates.result }} |"
echo "| Publish to NPM | ${{ needs.publish-npm-base.result == 'success' && 'βœ…' || '❌' }} ${{ needs.publish-npm-base.result }} |"
echo "| Docker Image | ${{ needs.publish-docker.result == 'success' && 'βœ…' || '❌' }} ${{ needs.publish-docker.result }} |"
echo ""
echo "### Installation"
echo ""
echo '```bash'
echo "# NPM (easiest!)"
echo "npx @dallay/rook@${{ needs.release-please.outputs.release_version }} --help"
echo ""
echo "# Or install globally"
echo "npm install -g @dallay/rook@${{ needs.release-please.outputs.release_version }}"
echo ""
echo "# Cargo"
echo "cargo install rook"
echo ""
echo "# macOS (Apple Silicon)"
echo "curl -LO https://github.com/dallay/cortex/releases/download/${{ needs.release-please.outputs.release_git_tag }}/rook-${{ needs.release-please.outputs.release_version }}-aarch64-apple-darwin.tar.gz"
echo ""
echo "# Linux (x86_64)"
echo "curl -LO https://github.com/dallay/cortex/releases/download/${{ needs.release-please.outputs.release_git_tag }}/rook-${{ needs.release-please.outputs.release_version }}-x86_64-unknown-linux-gnu.tar.gz"
echo ""
echo "# Docker Hub"
echo "docker pull dallay/rook:${{ needs.release-please.outputs.release_version }}"
echo ""
echo "# GitHub Container Registry"
echo "docker pull ghcr.io/${{ github.repository }}:${{ needs.release-please.outputs.release_version }}"
echo '```'
} >> "$GITHUB_STEP_SUMMARY"