Files
DocsGPT/.github/workflows/backend-release.yml
T
Alex 01dfe473d3 ci: publish the frontend image from the release chain
backend-release.yml creates the GitHub release with GITHUB_TOKEN, and GitHub
never starts workflows from events that token produces, so the frontend image
workflow's `release: published` trigger does not fire for a version bump on
main. It was the only publish workflow left out of the workflow_call fix, so
the next bump would push arc53/docsgpt:<version> and move docsgpt:latest while
docsgpt-fe stayed on the previous release — and the standalone compose file
defaults both images to latest.

Give cife.yml a workflow_call trigger with a version input (same shape as
ci.yml) and call it from backend-release.yml after the release is created. The
release trigger stays for releases created by hand.

While here, bring it in line with ci.yml: run the publishing jobs in the
docker-hub environment, tag from the public arc53 namespace instead of the
login secret, pin the actions by digest, add the OCI version label, and drop
the QEMU step that only ran on the native arm64 runner.
2026-09-12 20:28:58 +01:00

135 lines
4.6 KiB
YAML

name: Backend release
# A version bump on main tags the commit, creates the GitHub release, then
# publishes the backend and frontend Docker images and the PyPI package by
# calling those workflows.
# The release is created with GITHUB_TOKEN, and GitHub never starts workflows
# from events that token produces, so the `release: published` triggers on the
# publish workflows would not fire (0.18.0 got no images that way). Releases
# created by hand still publish through those triggers.
on:
push:
branches: [main]
paths:
- 'docsgpt/version.py'
workflow_dispatch:
permissions: {}
concurrency:
group: backend-release
cancel-in-progress: false
jobs:
release:
if: github.repository == 'arc53/DocsGPT'
runs-on: ubuntu-latest
permissions:
contents: write
outputs:
version: ${{ steps.ver.outputs.version }}
# The publish jobs run only for a release this run created. A release
# that already existed was either made by hand (its release event
# published it) or made by an earlier run: re-run that run's failed jobs.
created: ${{ steps.check.outputs.release == 'missing' }}
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
persist-credentials: false
- name: Read version from docsgpt/version.py
id: ver
run: |
VERSION=$(python3 -c "g={}; exec(open('docsgpt/version.py').read(), g); print(g['__version__'])")
if [ -z "$VERSION" ]; then
echo "::error::Could not read __version__ from docsgpt/version.py"
exit 1
fi
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
echo "Resolved version: $VERSION"
- name: Check what already exists
id: check
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
VERSION: ${{ steps.ver.outputs.version }}
run: |
# The tag and the release are checked separately: a run that pushed
# the tag and then failed to create the release must still create
# it (and publish) when re-run.
if git ls-remote --tags --exit-code origin "refs/tags/$VERSION" >/dev/null 2>&1; then
echo "tag=exists" >> "$GITHUB_OUTPUT"
echo "Tag $VERSION already exists on origin."
else
echo "tag=missing" >> "$GITHUB_OUTPUT"
fi
if gh release view "$VERSION" >/dev/null 2>&1; then
echo "release=exists" >> "$GITHUB_OUTPUT"
echo "Release $VERSION already exists — nothing to publish."
else
echo "release=missing" >> "$GITHUB_OUTPUT"
fi
- name: Create and push tag
if: steps.check.outputs.tag == 'missing'
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
VERSION: ${{ steps.ver.outputs.version }}
run: |
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
git tag "$VERSION"
# Authenticate this single push via a one-shot tokenized remote URL
# instead of leaving GITHUB_TOKEN persisted in .git/config (see
# persist-credentials: false on the checkout step above).
git push \
"https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" \
"$VERSION"
- name: Create GitHub release
if: steps.check.outputs.release == 'missing'
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
VERSION: ${{ steps.ver.outputs.version }}
run: |
gh release create "$VERSION" \
--title "v$VERSION" \
--generate-notes
docker:
needs: release
if: needs.release.outputs.created == 'true'
uses: $/.github/workflows/ci.yml
with:
version: ${{ needs.release.outputs.version }}
secrets:
DOCKER_USERNAME: ${{ secrets.DOCKER_USERNAME }}
DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }}
permissions:
contents: write # release-assets attaches the compose file to the release
packages: write
frontend:
needs: release
if: needs.release.outputs.created == 'true'
uses: $/.github/workflows/cife.yml
with:
version: ${{ needs.release.outputs.version }}
secrets:
DOCKER_USERNAME: ${{ secrets.DOCKER_USERNAME }}
DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }}
permissions:
contents: read
packages: write
pypi:
needs: release
if: needs.release.outputs.created == 'true'
uses: $/.github/workflows/pypi-publish.yml
with:
version: ${{ needs.release.outputs.version }}
permissions:
contents: read
id-token: write