Files
plainleaf/.github/workflows/_build.yml
T

233 lines
7.8 KiB
YAML

name: Build (reusable)
on:
workflow_call:
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
# sccache caches compiled objects across Cargo.lock changes (rust-cache alone
# invalidates fully on dep changes). Valuable here: each job compiles several
# release targets.
SCCACHE_GHA_ENABLED: "true"
RUSTC_WRAPPER: sccache
jobs:
build-linux:
runs-on: ubuntu-latest
steps:
- name: Setup repo
uses: actions/checkout@v4
with:
fetch-depth: 0
fetch-tags: true
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version-file: ".nvmrc"
- name: Setup Rust (linux musl + windows-gnu + freebsd targets)
uses: dtolnay/rust-toolchain@stable
with:
targets: x86_64-unknown-linux-musl,aarch64-unknown-linux-musl,armv7-unknown-linux-musleabihf,x86_64-pc-windows-gnu,x86_64-unknown-freebsd
- uses: Swatinem/rust-cache@v2
with:
key: linux-cross
- name: Setup sccache
uses: mozilla-actions/sccache-action@v0.0.10
# GHA Cache occasionally returns Azure edge errors; if the sccache daemon
# can't reach the backend it refuses to start, failing every rustc call.
# Probe once and disable for this job on outage — a slow build beats a
# failed release.
- name: Probe sccache backend, disable on outage
shell: bash
run: |
if sccache --start-server; then
echo "sccache backend reachable"
else
echo "::warning::sccache backend unreachable — disabling for this job"
echo "RUSTC_WRAPPER=" >> "$GITHUB_ENV"
echo "SCCACHE_GHA_ENABLED=false" >> "$GITHUB_ENV"
fi
- name: Install cross-toolchains
run: |
sudo apt-get update
# apt-only C cross-compilers; Rust supplies the static musl libc itself.
# clang/lld/llvm are for the FreeBSD cross-build (no apt freebsd gcc).
# (linker/CC wiring lives in .cargo/config.toml)
sudo apt-get install -y musl-tools gcc-aarch64-linux-gnu \
gcc-arm-linux-gnueabihf gcc-mingw-w64-x86-64 \
clang lld llvm
- name: Install npm dependencies
run: npm ci
- name: Build linux/windows binaries (compile once → raw + zips)
run: make build-linux-ci
- name: Build FreeBSD sb CLI
# FreeBSD cross is fiddly (clang + sysroot): this step fetches a FreeBSD
# base sysroot and cross-builds the `sb` CLI against it. It's a
# first-class build like the others — a failure here fails the job.
run: |
sudo mkdir -p /opt/freebsd-sysroot
VER=$(curl -fsSL https://download.freebsd.org/releases/amd64/ \
| grep -oE '[0-9]+\.[0-9]+-RELEASE' | sort -V | uniq | tail -1)
echo "Latest FreeBSD release: $VER"
curl -fsSL "https://download.freebsd.org/releases/amd64/$VER/base.txz" \
| sudo tar -xJf - -C /opt/freebsd-sysroot ./lib ./usr/lib ./usr/include
make build-cli-releases-freebsd
- name: Upload release zips (linux/windows/freebsd)
uses: actions/upload-artifact@v4
with:
name: release-zips-linux
path: |
silverbullet-server-*.zip
sb-*.zip
if-no-files-found: error
- name: Upload raw docker binaries
uses: actions/upload-artifact@v4
with:
name: docker-binaries
path: |
silverbullet-amd64
silverbullet-arm64
silverbullet-arm
if-no-files-found: error
build-macos:
runs-on: macos-latest
steps:
- name: Setup repo
uses: actions/checkout@v4
with:
fetch-depth: 0
fetch-tags: true
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version-file: ".nvmrc"
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
with:
key: macos
- name: Setup sccache
uses: mozilla-actions/sccache-action@v0.0.10
- name: Probe sccache backend, disable on outage
shell: bash
run: |
if sccache --start-server; then
echo "sccache backend reachable"
else
echo "::warning::sccache backend unreachable — disabling for this job"
echo "RUSTC_WRAPPER=" >> "$GITHUB_ENV"
echo "SCCACHE_GHA_ENABLED=false" >> "$GITHUB_ENV"
fi
- name: Install npm dependencies
run: npm ci
- name: Build server + CLI release archives (darwin x2)
run: |
make build-server-releases-macos
make build-cli-releases-rust-macos
- name: Import certificate into keychain
env:
APPLE_CERTIFICATE_P12_BASE64: ${{ secrets.APPLE_CERTIFICATE_P12_BASE64 }}
APPLE_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }}
run: |
echo "$APPLE_CERTIFICATE_P12_BASE64" | base64 --decode > certificate.p12
KEYCHAIN_PATH="$RUNNER_TEMP/signing.keychain-db"
KEYCHAIN_PASSWORD="$(openssl rand -hex 20)"
security create-keychain -p "$KEYCHAIN_PASSWORD" "$KEYCHAIN_PATH"
security set-keychain-settings -lut 21600 "$KEYCHAIN_PATH"
security unlock-keychain -p "$KEYCHAIN_PASSWORD" "$KEYCHAIN_PATH"
security import certificate.p12 \
-P "$APPLE_CERTIFICATE_PASSWORD" \
-A \
-t cert \
-f pkcs12 \
-k "$KEYCHAIN_PATH"
security list-keychain -d user -s "$KEYCHAIN_PATH"
security set-key-partition-list -S apple-tool:,apple:,codesign: \
-s -k "$KEYCHAIN_PASSWORD" "$KEYCHAIN_PATH"
rm certificate.p12
- name: Sign and notarize macOS binaries
env:
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
APPLE_API_KEY_ID: ${{ secrets.APPLE_API_KEY_ID }}
APPLE_API_KEY_ISSUER_ID: ${{ secrets.APPLE_API_KEY_ISSUER_ID }}
APPLE_API_KEY_P8_BASE64: ${{ secrets.APPLE_API_KEY_P8_BASE64 }}
run: |
mkdir -p "$HOME/private_keys"
echo "$APPLE_API_KEY_P8_BASE64" | base64 --decode \
> "$HOME/private_keys/AuthKey_${APPLE_API_KEY_ID}.p8"
IDENTITY="Developer ID Application: Zef Hemel ($APPLE_TEAM_ID)"
# Both the server and the `sb` CLI darwin archives.
for zip_file in *-darwin-*.zip; do
echo "=== Processing $zip_file ==="
zip_file="$(pwd)/$zip_file"
WORK_DIR=$(mktemp -d)
unzip -o "$zip_file" -d "$WORK_DIR"
BINARY=$(ls "$WORK_DIR")
codesign --force --options runtime \
--sign "$IDENTITY" \
--timestamp \
"$WORK_DIR/$BINARY"
codesign --verify --verbose "$WORK_DIR/$BINARY"
NOTARIZE_ZIP="$WORK_DIR/notarize.zip"
ditto -c -k --keepParent "$WORK_DIR/$BINARY" "$NOTARIZE_ZIP"
xcrun notarytool submit "$NOTARIZE_ZIP" \
--key "$HOME/private_keys/AuthKey_${APPLE_API_KEY_ID}.p8" \
--key-id "$APPLE_API_KEY_ID" \
--issuer "$APPLE_API_KEY_ISSUER_ID" \
--wait --timeout 10m
rm "$zip_file"
(cd "$WORK_DIR" && zip "$zip_file" "$BINARY")
rm -rf "$WORK_DIR"
done
rm -rf "$HOME/private_keys"
- name: Clean up keychain
if: always()
run: |
security delete-keychain "$RUNNER_TEMP/signing.keychain-db" 2>/dev/null || true
- name: Upload macOS release zips
uses: actions/upload-artifact@v4
with:
name: release-zips-macos
path: |
silverbullet-server-darwin-*.zip
sb-darwin-*.zip
if-no-files-found: error