-
Notifications
You must be signed in to change notification settings - Fork 0
183 lines (166 loc) · 5.89 KB
/
release.yml
File metadata and controls
183 lines (166 loc) · 5.89 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
name: Release
on:
push:
tags:
- 'v*'
permissions:
contents: write
env:
DO_NOT_TRACK: '1'
jobs:
# Preflight: validate CHANGELOG has a section for the tag being released
# BEFORE Maven Central deploy happens. Maven Central is immutable —
# you cannot re-publish the same version — so a missing CHANGELOG section
# must fail the workflow cleanly instead of leaving a successfully-deployed
# artifact and a failed GitHub release with no recovery path.
preflight:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Extract CHANGELOG section
run: |
VERSION="${GITHUB_REF#refs/tags/v}"
awk -v ver="$VERSION" '$0 ~ "^## \\["ver"\\]" {p=1; next} p && /^## \[/ {exit} p {print}' CHANGELOG.md > /tmp/release-body.md
if [ ! -s /tmp/release-body.md ]; then
echo "::error::No CHANGELOG.md section found for version $VERSION — refusing to publish."
echo "::error::Add a '## [$VERSION] - YYYY-MM-DD' section to CHANGELOG.md and re-tag."
exit 1
fi
{
echo "## AxonFlow Java SDK v${VERSION}"
echo ""
echo "### Installation"
echo ""
echo "**Maven:**"
echo '```xml'
echo "<dependency>"
echo " <groupId>com.getaxonflow</groupId>"
echo " <artifactId>axonflow-sdk</artifactId>"
echo " <version>${VERSION}</version>"
echo "</dependency>"
echo '```'
echo ""
echo "**Gradle:**"
echo '```groovy'
echo "implementation 'com.getaxonflow:axonflow-sdk:${VERSION}'"
echo '```'
echo ""
cat /tmp/release-body.md
} > /tmp/release-body-final.md
echo "Release body: $(wc -l < /tmp/release-body-final.md) lines"
- name: Upload release body artifact
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: release-body
path: /tmp/release-body-final.md
retention-days: 1
release:
needs: preflight
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up JDK 17
uses: actions/setup-java@v4
with:
java-version: '17'
distribution: 'temurin'
cache: 'maven'
server-id: central
server-username: MAVEN_USERNAME
server-password: MAVEN_PASSWORD
gpg-private-key: ${{ secrets.GPG_PRIVATE_KEY }}
gpg-passphrase: GPG_PASSPHRASE
- name: Configure GPG for headless operation
run: |
echo "allow-loopback-pinentry" >> ~/.gnupg/gpg-agent.conf
echo "pinentry-mode loopback" >> ~/.gnupg/gpg.conf
gpg-connect-agent reloadagent /bye || true
- name: Configure Maven settings with mirror
run: |
mkdir -p ~/.m2
cat > ~/.m2/settings.xml << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<settings>
<servers>
<server>
<id>central</id>
<username>${env.MAVEN_USERNAME}</username>
<password>${env.MAVEN_PASSWORD}</password>
</server>
</servers>
<mirrors>
<mirror>
<id>central-mirror</id>
<name>Maven Central Mirror (repo1)</name>
<url>https://repo1.maven.org/maven2</url>
<mirrorOf>central</mirrorOf>
</mirror>
</mirrors>
</settings>
EOF
- name: Extract version from tag
id: version
run: echo "VERSION=${GITHUB_REF#refs/tags/v}" >> $GITHUB_OUTPUT
- name: Update version in pom.xml
run: |
# Retry logic for Maven Central 403 errors
for i in 1 2 3; do
echo "Attempt $i: Updating version..."
if mvn versions:set -DnewVersion=${{ steps.version.outputs.VERSION }} -B -U; then
echo "Version update successful"
break
fi
echo "Attempt $i failed, waiting 30 seconds..."
sleep 30
done
- name: Run tests
run: |
for i in 1 2 3; do
echo "Attempt $i: Running tests..."
if mvn test -B -U; then
echo "Tests passed"
break
fi
if [ $i -eq 3 ]; then
echo "Tests failed after 3 attempts"
exit 1
fi
echo "Attempt $i failed, waiting 30 seconds..."
sleep 30
done
- name: Build and deploy to Maven Central
env:
MAVEN_USERNAME: ${{ secrets.CENTRAL_USERNAME }}
MAVEN_PASSWORD: ${{ secrets.CENTRAL_TOKEN }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
for i in 1 2 3; do
echo "Attempt $i: Deploying to Maven Central..."
if mvn clean deploy -Prelease -DskipTests -B -U -Dgpg.passphrase="${GPG_PASSPHRASE}"; then
echo "Deploy successful"
break
fi
if [ $i -eq 3 ]; then
echo "Deploy failed after 3 attempts"
exit 1
fi
echo "Attempt $i failed, waiting 60 seconds..."
sleep 60
done
- name: Download release body artifact
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
name: release-body
path: /tmp/release-body
- name: Create GitHub Release
uses: softprops/action-gh-release@v1
with:
name: Release ${{ steps.version.outputs.VERSION }}
body_path: /tmp/release-body/release-body-final.md
files: |
target/*.jar
draft: false
prerelease: false
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}