ci: publish releases with the Fluxer CI app instead of the Actions token (#1695)

This commit is contained in:
Hampus
2026-08-17 12:59:29 +02:00
committed by GitHub
parent d271f3112c
commit 10ae4bfe1e
16 changed files with 72 additions and 6 deletions
+20 -2
View File
@@ -65,10 +65,19 @@ jobs:
uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9 uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9
with: with:
toolchain: "1.93.0" toolchain: "1.93.0"
- name: Create token
id: create-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1
with:
client-id: ${{ vars.FLUXER_CI_APP_ID }}
private-key: ${{ secrets.FLUXER_CI_APP_KEY }}
owner: fluxerapp
repositories: fluxer
permission-contents: read
- name: set variables - name: set variables
id: vars id: vars
env: env:
GH_TOKEN: ${{ github.token }} GH_TOKEN: ${{ steps.create-token.outputs.token }}
FLUXER_BUILD_VERSION: ${{ inputs['build-version'] }} FLUXER_BUILD_VERSION: ${{ inputs['build-version'] }}
run: >- run: >-
cargo run --locked --quiet --manifest-path tools/ci/Cargo.toml -- resolve-calver cargo run --locked --quiet --manifest-path tools/ci/Cargo.toml -- resolve-calver
@@ -151,9 +160,18 @@ jobs:
"${IMAGE}:${VERSION}-arm64" "${IMAGE}:${VERSION}-arm64"
docker buildx imagetools inspect "${IMAGE}:${VERSION}" docker buildx imagetools inspect "${IMAGE}:${VERSION}"
- name: Create token
id: create-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1
with:
client-id: ${{ vars.FLUXER_CI_APP_ID }}
private-key: ${{ secrets.FLUXER_CI_APP_KEY }}
owner: fluxerapp
repositories: fluxer
permission-contents: write
- name: Publish GitHub release - name: Publish GitHub release
env: env:
GH_TOKEN: ${{ github.token }} GH_TOKEN: ${{ steps.create-token.outputs.token }}
SOURCE_SHA: ${{ github.sha }} SOURCE_SHA: ${{ github.sha }}
VERSION: ${{ needs.meta.outputs.build_version }} VERSION: ${{ needs.meta.outputs.build_version }}
RELEASE_BASELINE_SHA: ${{ vars.RELEASE_BASELINE_SHA }} RELEASE_BASELINE_SHA: ${{ vars.RELEASE_BASELINE_SHA }}
+1
View File
@@ -29,6 +29,7 @@ jobs:
image: image:
needs: approve needs: approve
uses: ./.github/workflows/_build-image.yaml uses: ./.github/workflows/_build-image.yaml
secrets: inherit
with: with:
image: fluxer-admin image: fluxer-admin
dockerfile: fluxer_admin/Dockerfile dockerfile: fluxer_admin/Dockerfile
+1
View File
@@ -29,6 +29,7 @@ jobs:
image: image:
needs: approve needs: approve
uses: ./.github/workflows/_build-image.yaml uses: ./.github/workflows/_build-image.yaml
secrets: inherit
with: with:
image: fluxer-api image: fluxer-api
dockerfile: fluxer_api/Dockerfile dockerfile: fluxer_api/Dockerfile
@@ -29,6 +29,7 @@ jobs:
build: build:
needs: approve needs: approve
uses: ./.github/workflows/_build-image.yaml uses: ./.github/workflows/_build-image.yaml
secrets: inherit
with: with:
image: fluxer-app-proxy-self-hosted image: fluxer-app-proxy-self-hosted
dockerfile: fluxer_app_proxy/Dockerfile dockerfile: fluxer_app_proxy/Dockerfile
+10 -1
View File
@@ -187,9 +187,18 @@ jobs:
"${IMAGE}:${VERSION}-arm64" "${IMAGE}:${VERSION}-arm64"
docker buildx imagetools inspect "${IMAGE}:${VERSION}" docker buildx imagetools inspect "${IMAGE}:${VERSION}"
- name: Create token
id: create-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1
with:
client-id: ${{ vars.FLUXER_CI_APP_ID }}
private-key: ${{ secrets.FLUXER_CI_APP_KEY }}
owner: fluxerapp
repositories: fluxer
permission-contents: write
- name: Publish GitHub release - name: Publish GitHub release
env: env:
GH_TOKEN: ${{ github.token }} GH_TOKEN: ${{ steps.create-token.outputs.token }}
SOURCE_SHA: ${{ github.sha }} SOURCE_SHA: ${{ github.sha }}
VERSION: ${{ needs.meta.outputs.build_version }} VERSION: ${{ needs.meta.outputs.build_version }}
RELEASE_BASELINE_SHA: ${{ vars.RELEASE_BASELINE_SHA }} RELEASE_BASELINE_SHA: ${{ vars.RELEASE_BASELINE_SHA }}
+20 -2
View File
@@ -67,10 +67,19 @@ jobs:
with: with:
toolchain: "1.93.0" toolchain: "1.93.0"
- name: Create token
id: create-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1
with:
client-id: ${{ vars.FLUXER_CI_APP_ID }}
private-key: ${{ secrets.FLUXER_CI_APP_KEY }}
owner: fluxerapp
repositories: fluxer
permission-contents: read
- name: Set metadata - name: Set metadata
id: meta id: meta
env: env:
GH_TOKEN: ${{ github.token }} GH_TOKEN: ${{ steps.create-token.outputs.token }}
FLUXER_BUILD_VERSION: ${{ inputs.build_version }} FLUXER_BUILD_VERSION: ${{ inputs.build_version }}
run: >- run: >-
cargo run --locked --quiet --manifest-path tools/ci/Cargo.toml -- build-desktop cargo run --locked --quiet --manifest-path tools/ci/Cargo.toml -- build-desktop
@@ -581,9 +590,18 @@ jobs:
uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9 uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9
with: with:
toolchain: "1.93.0" toolchain: "1.93.0"
- name: Create token
id: create-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1
with:
client-id: ${{ vars.FLUXER_CI_APP_ID }}
private-key: ${{ secrets.FLUXER_CI_APP_KEY }}
owner: fluxerapp
repositories: fluxer
permission-contents: write
- name: Publish GitHub desktop release - name: Publish GitHub desktop release
env: env:
GH_TOKEN: ${{ github.token }} GH_TOKEN: ${{ steps.create-token.outputs.token }}
CHANNEL: ${{ needs.meta.outputs.build_channel }} CHANNEL: ${{ needs.meta.outputs.build_channel }}
VERSION: ${{ needs.meta.outputs.version }} VERSION: ${{ needs.meta.outputs.version }}
SOURCE_SHA: ${{ needs.meta.outputs.source_sha }} SOURCE_SHA: ${{ needs.meta.outputs.source_sha }}
+1
View File
@@ -29,6 +29,7 @@ jobs:
image: image:
needs: approve needs: approve
uses: ./.github/workflows/_build-image.yaml uses: ./.github/workflows/_build-image.yaml
secrets: inherit
with: with:
image: fluxer-docs image: fluxer-docs
dockerfile: fluxer_docs/Dockerfile dockerfile: fluxer_docs/Dockerfile
+1
View File
@@ -29,6 +29,7 @@ jobs:
image: image:
needs: approve needs: approve
uses: ./.github/workflows/_build-image.yaml uses: ./.github/workflows/_build-image.yaml
secrets: inherit
with: with:
image: fluxer-gateway image: fluxer-gateway
dockerfile: fluxer_gateway/Dockerfile dockerfile: fluxer_gateway/Dockerfile
+1
View File
@@ -29,6 +29,7 @@ jobs:
image: image:
needs: approve needs: approve
uses: ./.github/workflows/_build-image.yaml uses: ./.github/workflows/_build-image.yaml
secrets: inherit
with: with:
image: fluxer-gifs image: fluxer-gifs
dockerfile: fluxer_gifs/Dockerfile dockerfile: fluxer_gifs/Dockerfile
+1
View File
@@ -29,6 +29,7 @@ jobs:
image: image:
needs: approve needs: approve
uses: ./.github/workflows/_build-image.yaml uses: ./.github/workflows/_build-image.yaml
secrets: inherit
with: with:
image: fluxer-media-proxy image: fluxer-media-proxy
dockerfile: fluxer_media_proxy/Dockerfile dockerfile: fluxer_media_proxy/Dockerfile
+1
View File
@@ -29,6 +29,7 @@ jobs:
image: image:
needs: approve needs: approve
uses: ./.github/workflows/_build-image.yaml uses: ./.github/workflows/_build-image.yaml
secrets: inherit
with: with:
image: fluxer-messages image: fluxer-messages
dockerfile: fluxer_messages/Dockerfile dockerfile: fluxer_messages/Dockerfile
+1
View File
@@ -29,6 +29,7 @@ jobs:
image: image:
needs: approve needs: approve
uses: ./.github/workflows/_build-image.yaml uses: ./.github/workflows/_build-image.yaml
secrets: inherit
with: with:
image: fluxer-snowflakes image: fluxer-snowflakes
dockerfile: fluxer_snowflakes/Dockerfile dockerfile: fluxer_snowflakes/Dockerfile
+1
View File
@@ -29,6 +29,7 @@ jobs:
image: image:
needs: approve needs: approve
uses: ./.github/workflows/_build-image.yaml uses: ./.github/workflows/_build-image.yaml
secrets: inherit
with: with:
image: fluxer-static image: fluxer-static
dockerfile: fluxer_static/Dockerfile dockerfile: fluxer_static/Dockerfile
+1
View File
@@ -29,6 +29,7 @@ jobs:
image: image:
needs: approve needs: approve
uses: ./.github/workflows/_build-image.yaml uses: ./.github/workflows/_build-image.yaml
secrets: inherit
with: with:
image: fluxer-unfurl image: fluxer-unfurl
dockerfile: fluxer_unfurl/Dockerfile dockerfile: fluxer_unfurl/Dockerfile
+1
View File
@@ -29,6 +29,7 @@ jobs:
image: image:
needs: approve needs: approve
uses: ./.github/workflows/_build-image.yaml uses: ./.github/workflows/_build-image.yaml
secrets: inherit
with: with:
image: fluxer-users image: fluxer-users
dockerfile: fluxer_users/Dockerfile dockerfile: fluxer_users/Dockerfile
@@ -40,11 +40,20 @@ jobs:
build_version: ${{ steps.inputs.outputs.build_version }} build_version: ${{ steps.inputs.outputs.build_version }}
correlation_id: ${{ steps.inputs.outputs.correlation_id }} correlation_id: ${{ steps.inputs.outputs.correlation_id }}
steps: steps:
- name: Create token
id: create-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1
with:
client-id: ${{ vars.FLUXER_CI_APP_ID }}
private-key: ${{ secrets.FLUXER_CI_APP_KEY }}
owner: fluxerapp
repositories: fluxer
permission-contents: read
- name: Resolve trusted build inputs - name: Resolve trusted build inputs
id: inputs id: inputs
env: env:
EVENT_AFTER: ${{ github.event.after }} EVENT_AFTER: ${{ github.event.after }}
GH_TOKEN: ${{ github.token }} GH_TOKEN: ${{ steps.create-token.outputs.token }}
PARENT_SHA: ${{ github.sha }} PARENT_SHA: ${{ github.sha }}
PUBLIC_REPOSITORY: ${{ github.repository }} PUBLIC_REPOSITORY: ${{ github.repository }}
RUN_ID: ${{ github.run_id }} RUN_ID: ${{ github.run_id }}