name: Distribute Release # Auto-pushes new releases to package managers. Triggers on: # - tag push (e.g. v5.9.21) — the normal release flow # - workflow_dispatch — manual run for testing or backports # # Each step that needs a secret checks for it and skips gracefully with a # clear warning if it's not set, so the workflow can be merged and tested # before secrets are configured. on: push: tags: ['v*'] workflow_dispatch: inputs: version: description: 'Override version (e.g. 5.9.21). Leave blank to use tag.' required: false type: string permissions: contents: read jobs: version: name: Resolve version runs-on: ubuntu-22.04 outputs: version: ${{ steps.v.outputs.version }} steps: - id: v run: | if [ "${{ github.event_name }}" = "workflow_dispatch" ] && [ -n "${{ inputs.version }}" ]; then echo "version=${{ inputs.version }}" >> $GITHUB_OUTPUT else echo "version=${GITHUB_REF_NAME#v}" >> $GITHUB_OUTPUT fi - run: echo "Distributing v${{ steps.v.outputs.version }}" docker: name: Docker Hub needs: version runs-on: ubuntu-22.04 permissions: contents: read packages: write env: DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} VERSION: ${{ needs.version.outputs.version }} steps: - uses: actions/checkout@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Login to Docker Hub run: | if [ -z "$DOCKERHUB_TOKEN" ]; then echo "::warning::DOCKERHUB_TOKEN secret not set — skipping Docker push. Add it at Settings → Secrets → Actions." exit 0 fi echo "$DOCKERHUB_TOKEN" | docker login -u samiahmed7777 --password-stdin - name: Build and push run: | if [ -z "$DOCKERHUB_TOKEN" ]; then exit 0; fi docker buildx build \ --push \ --tag samiahmed7777/trianglesd:$VERSION \ --tag samiahmed7777/trianglesd:latest \ --cache-from type=gha \ --cache-to type=gha,mode=max \ --provenance=false \ ./packaging/docker - name: Verify pushed image run: | if [ -z "$DOCKERHUB_TOKEN" ]; then exit 0; fi docker pull samiahmed7777/trianglesd:$VERSION echo "--- trianglesd -version ---" docker run --rm samiahmed7777/trianglesd:$VERSION trianglesd -version 2>&1 | head -3 echo "--- triangles-cli getinfo (will fail without RPC, expected) ---" docker run --rm samiahmed7777/trianglesd:$VERSION triangles-cli getinfo 2>&1 | head -3 aur: name: AUR (triangles-qt-bin) needs: version runs-on: ubuntu-22.04 container: image: archlinux:latest options: --privileged env: AUR_SSH_KEY: ${{ secrets.AUR_SSH_KEY }} VERSION: ${{ needs.version.outputs.version }} steps: - uses: actions/checkout@v4 - name: Check AUR_SSH_KEY run: | if [ -z "$AUR_SSH_KEY" ]; then echo "::warning::AUR_SSH_KEY secret not set — skipping AUR push. Add it at Settings → Secrets → Actions." echo "::warning::The key should be the contents of ~/.ssh/aur_key (private key, not .pub)." fi - name: Install build tools + create non-root user if: env.AUR_SSH_KEY != '' run: | pacman -Syu --noconfirm --needed git openssh base-devel python sudo # makepkg refuses to run as root — create a build user useradd -m -s /bin/bash build echo 'build ALL=(ALL) NOPASSWD: ALL' >> /etc/sudoers chown -R build:build "$GITHUB_WORKSPACE" - name: Wait for release artifacts if: env.AUR_SSH_KEY != '' run: | for i in {1..30}; do URL="https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/cryptographic-triangles_${VERSION}_amd64.deb" if curl -fsSL --head "$URL" >/dev/null 2>&1; then echo "✓ Release .deb available: $URL" exit 0 fi echo " waiting for release v${VERSION}... ($i/30)" sleep 20 done echo "::error::Release v${VERSION} .deb never became available after 10 minutes" exit 1 - name: Download source .debs if: env.AUR_SSH_KEY != '' run: | cd /tmp curl -fsSL -o full.deb "https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/cryptographic-triangles_${VERSION}_amd64.deb" curl -fsSL -o daemon.deb "https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/cryptographic-triangles-daemon_${VERSION}_amd64.deb" ls -la /tmp/*.deb sha256sum /tmp/full.deb /tmp/daemon.deb - name: Update PKGBUILD with version + SHA256s if: env.AUR_SSH_KEY != '' run: | cp "$GITHUB_WORKSPACE/packaging/aur/PKGBUILD" /tmp/PKGBUILD chown build:build /tmp/PKGBUILD /tmp/full.deb /tmp/daemon.deb sudo -u build bash -c ' set -e cd /tmp FULL_SHA=$(sha256sum full.deb | awk "{print \$1}") DAEMON_SHA=$(sha256sum daemon.deb | awk "{print \$1}") echo "version='"$VERSION"' full=$FULL_SHA daemon=$DAEMON_SHA" python3 - < .SRCINFO echo "--- generated .SRCINFO ---" cat .SRCINFO ' - name: Setup SSH key for AUR if: env.AUR_SSH_KEY != '' run: | mkdir -p /home/build/.ssh printf '%s\n' "$AUR_SSH_KEY" > /home/build/.ssh/aur_key chmod 600 /home/build/.ssh/aur_key ssh-keyscan -t ed25519 aur.archlinux.org > /home/build/.ssh/known_hosts 2>/dev/null chown -R build:build /home/build/.ssh - name: Clone AUR repo if: env.AUR_SSH_KEY != '' run: | sudo -u build bash -c ' cd /tmp GIT_SSH_COMMAND="ssh -i ~/.ssh/aur_key -o IdentitiesOnly=yes" \ git clone ssh://aur@aur.archlinux.org/triangles-qt-bin.git ls -la /tmp/triangles-qt-bin ' - name: Stage updated files if: env.AUR_SSH_KEY != '' run: | cp /tmp/PKGBUILD /tmp/triangles-qt-bin/PKGBUILD cp /tmp/.SRCINFO /tmp/triangles-qt-bin/.SRCINFO cp "$GITHUB_WORKSPACE/packaging/aur/triangles-qt.desktop" /tmp/triangles-qt-bin/triangles-qt.desktop chown -R build:build /tmp/triangles-qt-bin sudo -u build bash -c ' cd /tmp/triangles-qt-bin git --no-pager diff --stat ' - name: Commit and push to AUR if: env.AUR_SSH_KEY != '' run: | sudo -u build bash -c ' cd /tmp/triangles-qt-bin git config user.name "Sami Ahmed" git config user.email "SamiAhmed7777@users.noreply.github.com" git add PKGBUILD .SRCINFO triangles-qt.desktop if git diff --cached --quiet; then echo "No changes to commit (AUR already at this version)" exit 0 fi git commit -m "triangles-qt-bin '"$VERSION"'-1" GIT_SSH_COMMAND="ssh -i ~/.ssh/aur_key -o IdentitiesOnly=yes" \ git push origin master ' - name: ✓ Summary if: always() run: | if [ -z "$AUR_SSH_KEY" ]; then echo "::notice::AUR job was skipped because AUR_SSH_KEY is not set." else echo "::notice::AUR distribution completed." fi