Merge pull request #34 from gynzy/PF-3329 #13
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # GENERATED with jsonnet - DO NOT EDIT MANUALLY | |
| "jobs": | |
| "pnpm-publish": | |
| "container": | |
| "image": "mirror.gcr.io/node:24" | |
| "permissions": | |
| "contents": "read" | |
| "packages": "write" | |
| "pull-requests": "read" | |
| "runs-on": "ubuntu-latest" | |
| "steps": | |
| - "id": "check-binaries" | |
| "name": "check for ssh/git binaries" | |
| "run": | | |
| if command -v git; | |
| then | |
| echo "gitBinaryExists=true" >> $GITHUB_OUTPUT; | |
| echo "Git binary exists"; | |
| else | |
| echo "Attempt to install git binary"; | |
| if command -v apk; then | |
| echo "apk exists"; | |
| apk add git && echo "gitBinaryExists=true" >> $GITHUB_OUTPUT; | |
| elif command -v apt; then | |
| echo "apt exists"; | |
| apt update && apt install -y git && echo "gitBinaryExists=true" >> $GITHUB_OUTPUT; | |
| else | |
| echo "No package manager found, unable to install git cli binary"; | |
| echo "gitBinaryExists=false" >> $GITHUB_OUTPUT; | |
| fi; | |
| fi; | |
| if command -v ssh; | |
| then | |
| echo "sshBinaryExists=true" >> $GITHUB_OUTPUT; | |
| echo "SSH binary exists"; | |
| exit 0; | |
| else | |
| echo "Attempt to install ssh binary"; | |
| if command -v apk; then | |
| echo "apk exists"; | |
| apk add openssh-client && echo "sshBinaryExists=true" >> $GITHUB_OUTPUT && exit 0; | |
| elif command -v apt; then | |
| echo "apt exists"; | |
| apt update && apt install -y openssh-client && echo "sshBinaryExists=true" >> $GITHUB_OUTPUT && exit 0; | |
| else | |
| echo "No package manager found, unable to install ssh cli binary"; | |
| echo "sshBinaryExists=false" >> $GITHUB_OUTPUT; | |
| fi; | |
| fi; | |
| echo "sshBinaryExists=false" >> $GITHUB_OUTPUT; | |
| - "id": "checkout-ssh-0" | |
| "if": "${{ ( steps.check-binaries.outputs.sshBinaryExists == 'true' && steps.check-binaries.outputs.gitBinaryExists == 'true' ) }}" | |
| "name": "Check out repository code via ssh" | |
| "timeout-minutes": 10 | |
| "uses": "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" | |
| "with": | |
| "ref": "${{ github.sha }}" | |
| "ssh-key": "${{ secrets.VIRKO_GITHUB_SSH_KEY }}" | |
| "submodules": "recursive" | |
| - "id": "checkout-https-0" | |
| "if": "${{ ( steps.check-binaries.outputs.sshBinaryExists == 'false' || steps.check-binaries.outputs.gitBinaryExists == 'false' ) }}" | |
| "name": "Check out repository code via https" | |
| "timeout-minutes": 10 | |
| "uses": "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" | |
| "with": | |
| "ref": "${{ github.sha }}" | |
| "submodules": "recursive" | |
| - "name": "git safe directory" | |
| "run": "command -v git && git config --global --add safe.directory '*' || true" | |
| - "env": | |
| "NODE_AUTH_TOKEN": "${{ secrets.VIRKO_GITHUB_PKG_READONLY }}" | |
| "name": "set github npm_token" | |
| "run": | | |
| cat <<EOF > .npmrc | |
| @gynzy:registry=https://npm.pkg.github.com | |
| //npm.pkg.github.com/:_authToken=${NODE_AUTH_TOKEN} | |
| public-hoist-pattern[]=@pulumi/pulumi | |
| EOF | |
| - "name": "Install pnpm tool" | |
| "uses": "pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320" | |
| - "name": "Run pnpm install" | |
| "run": "pnpm config set store-dir .pnpm-store && pnpm install --frozen-lockfile" | |
| - "name": "build" | |
| "run": "pnpm run build" | |
| - "env": | |
| "NODE_AUTH_TOKEN": "${{ secrets.GITHUB_TOKEN }}" | |
| "name": "set github npm_token" | |
| "run": | | |
| cat <<EOF > .npmrc | |
| @gynzy:registry=https://npm.pkg.github.com | |
| //npm.pkg.github.com/:_authToken=${NODE_AUTH_TOKEN} | |
| public-hoist-pattern[]=@pulumi/pulumi | |
| EOF | |
| - "env": {} | |
| "name": "publish" | |
| "run": | | |
| bash -c 'set -xeo pipefail; | |
| cp package.json package.json.bak; | |
| VERSION=$(node -p "require(\"./package.json\").version"); | |
| if [[ ! -z "${PR_NUMBER}" ]]; then | |
| echo "Setting tag/version for pr build."; | |
| TAG=pr-$PR_NUMBER; | |
| PUBLISHVERSION="$VERSION-pr$PR_NUMBER.$GITHUB_RUN_NUMBER"; | |
| elif [[ "${GITHUB_REF_TYPE}" == "tag" ]]; then | |
| if [[ "${GITHUB_REF_NAME}" != "${VERSION}" ]]; then | |
| echo "Tag version does not match package version. They should match. Exiting"; | |
| exit 1; | |
| fi | |
| echo "Setting tag/version for release/tag build."; | |
| PUBLISHVERSION=$VERSION; | |
| TAG="latest"; | |
| elif [[ "${GITHUB_REF_TYPE}" == "branch" && "${GITHUB_REF_NAME}" == "main" ]] || [[ "${GITHUB_EVENT_NAME}" == "deployment" ]]; then | |
| echo "Setting tag/version for release/tag build."; | |
| PUBLISHVERSION=$VERSION; | |
| TAG="latest"; | |
| else | |
| exit 1 | |
| fi | |
| npm version --no-git-tag-version --allow-same-version "$PUBLISHVERSION"; | |
| pnpm publish --no-git-checks --tag "$TAG"; | |
| mv package.json.bak package.json; | |
| '; | |
| "timeout-minutes": 30 | |
| "name": "publish-prod" | |
| "on": | |
| "push": | |
| "branches": | |
| - "main" |