2aff1e45a4
In commit 4f950bb60 we switched the publish workflow to use HTTPS and
changed CircleCI config accordingly. However, that wasn't working. The
error we get after merge to `master`, when we run the job, is: `The key
you are authenticating with has been marked as read only.`
The reason is that CircleCI configures SSH URL rewriting, which takes
precedence.
Fix by using git's `url.<base>.insteadOf` config to rewrite both HTTPS
and SSH URLs to use HTTPS with the GitHub token. This ensures the token
is used regardless of any SSH configuration.
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
326 lines
8.6 KiB
YAML
326 lines
8.6 KiB
YAML
version: 2.1
|
|
orbs:
|
|
# NB: this is not the Go version, but the Orb version
|
|
# https://circleci.com/developer/orbs/orb/circleci/go#usage-go-modules-cache
|
|
go: circleci/go@1.11.0
|
|
|
|
commands:
|
|
setup-home-local-bin:
|
|
steps:
|
|
- run:
|
|
shell: /bin/bash -euo pipefail
|
|
command: |
|
|
mkdir -p "$HOME/.local/bin"
|
|
line='export PATH="$HOME/.local/bin:$PATH"'
|
|
if grep "$line" $BASH_ENV >/dev/null; then
|
|
echo "$line" >> $BASH_ENV
|
|
fi
|
|
|
|
apt-update-and-install-common-deps:
|
|
steps:
|
|
- run: sudo apt-get update
|
|
- run: sudo apt-get install -y gawk make
|
|
# CircleCI doesn't update its cimg/go images.
|
|
# So, need to update manually to get up-to-date trust chains.
|
|
# The need for this was required for cimg/go:1.12, but let's future proof this here and now.
|
|
- run: sudo apt-get install -y git ca-certificates
|
|
|
|
|
|
# NOTE: when updating uv version, update both the install URL and cache keys below
|
|
install-docdep:
|
|
steps:
|
|
- apt-update-and-install-common-deps
|
|
# Python is managed by uv - it will automatically download the version
|
|
# specified in docs/.python-version when needed
|
|
- run:
|
|
name: Install uv
|
|
command: curl -LsSf https://astral.sh/uv/0.9.30/install.sh | sh
|
|
- run:
|
|
name: Add uv to PATH and set cache dir
|
|
command: |
|
|
echo 'export PATH="$HOME/.local/bin:$PATH"' >> $BASH_ENV
|
|
echo 'export UV_CACHE_DIR="$HOME/.cache/uv"' >> $BASH_ENV
|
|
- restore_cache:
|
|
name: Restore uv cache
|
|
keys:
|
|
- uv-cache-v1-0.9.30-{{ checksum "docs/uv.lock" }}
|
|
- uv-cache-v1-0.9.30-
|
|
|
|
save-uv-cache:
|
|
steps:
|
|
- run:
|
|
name: Prune uv cache for CI
|
|
command: uv cache prune --ci
|
|
- save_cache:
|
|
name: Save uv cache
|
|
key: uv-cache-v1-0.9.30-{{ checksum "docs/uv.lock" }}
|
|
paths:
|
|
- ~/.cache/uv
|
|
|
|
docs-publish-sh:
|
|
parameters:
|
|
push:
|
|
type: boolean
|
|
steps:
|
|
- checkout
|
|
- run:
|
|
command: |
|
|
git config --global user.email "zreplbot@cschwarz.com"
|
|
git config --global user.name "zrepl-github-io-ci"
|
|
|
|
# Configure git to use the GitHub token for HTTPS authentication.
|
|
# The token is stored in the 'zrepl-github-io-deploy' context.
|
|
- when:
|
|
condition: << parameters.push >>
|
|
steps:
|
|
- run:
|
|
name: Configure git to use GitHub token for push
|
|
# GITHUB_PAGES_TOKEN is from the 'zrepl-github-io-deploy' context.
|
|
# CircleCI's secret masking automatically redacts context variables in logs.
|
|
command: |
|
|
# Unset CircleCI's SSH URL rewriting that checkout step configured
|
|
git config --global --unset-all url."ssh://git@github.com".insteadOf || true
|
|
# Set up credential helper with GitHub token
|
|
git config --global credential.helper store
|
|
echo "https://x-access-token:${GITHUB_PAGES_TOKEN}@github.com" > ~/.git-credentials
|
|
chmod 600 ~/.git-credentials
|
|
|
|
# caller must install-docdep
|
|
- when:
|
|
condition: << parameters.push >>
|
|
steps:
|
|
- run: bash -x docs/publish.sh -c -a -P
|
|
- when:
|
|
condition:
|
|
not: << parameters.push >>
|
|
steps:
|
|
- run: bash -x docs/publish.sh -c -a
|
|
|
|
parameters:
|
|
do_ci:
|
|
type: boolean
|
|
default: true
|
|
|
|
do_release:
|
|
type: boolean
|
|
default: false
|
|
|
|
workflows:
|
|
version: 2
|
|
|
|
ci:
|
|
when: << pipeline.parameters.do_ci >>
|
|
jobs:
|
|
- quickcheck-docs
|
|
- quickcheck-go:
|
|
name: quickcheck-go-amd64-linux-1.25.6
|
|
goversion: &latest-go-release "1.25.6"
|
|
goos: linux
|
|
goarch: amd64
|
|
- test-go:
|
|
goversion: *latest-go-release
|
|
- quickcheck-go:
|
|
requires:
|
|
- quickcheck-go-amd64-linux-1.25.6 #quickcheck-go-smoketest.name
|
|
matrix:
|
|
alias: quickcheck-go-matrix
|
|
parameters:
|
|
goversion: [*latest-go-release, "1.24.12"]
|
|
goos: ["linux", "freebsd"]
|
|
goarch: ["amd64", "arm64"]
|
|
exclude:
|
|
# don't re-do quickcheck-go-smoketest
|
|
- goversion: *latest-go-release
|
|
goos: linux
|
|
goarch: amd64
|
|
- platformtest:
|
|
matrix:
|
|
parameters:
|
|
goversion: [*latest-go-release]
|
|
goos: ["linux"]
|
|
goarch: ["amd64"]
|
|
requires:
|
|
- test-go
|
|
- quickcheck-go-<< matrix.goarch >>-<< matrix.goos >>-<< matrix.goversion >>
|
|
|
|
release:
|
|
when: << pipeline.parameters.do_release >>
|
|
jobs:
|
|
- release-build
|
|
- release-deb:
|
|
requires:
|
|
- release-build
|
|
- release-rpm:
|
|
requires:
|
|
- release-build
|
|
- release-upload:
|
|
requires:
|
|
- release-build
|
|
- release-deb
|
|
- release-rpm
|
|
|
|
publish-zrepl.github.io:
|
|
jobs:
|
|
- publish-zrepl-github-io:
|
|
context:
|
|
- zrepl-github-io-deploy
|
|
filters:
|
|
branches:
|
|
only:
|
|
- master
|
|
|
|
jobs:
|
|
quickcheck-docs:
|
|
docker:
|
|
- image: cimg/base:2024.09
|
|
steps:
|
|
- checkout
|
|
- install-docdep
|
|
# do the current docs build
|
|
- run: make docs
|
|
- save-uv-cache
|
|
# does the publish.sh script still work?
|
|
- docs-publish-sh:
|
|
push: false
|
|
|
|
quickcheck-go:
|
|
parameters:
|
|
goversion:
|
|
type: string
|
|
goos:
|
|
type: string
|
|
goarch:
|
|
type: string
|
|
docker:
|
|
- image: &cimg_with_modern_go cimg/go:1.25
|
|
environment:
|
|
GOOS: <<parameters.goos>>
|
|
GOARCH: <<parameters.goarch>>
|
|
GOTOOLCHAIN: "go<<parameters.goversion>>"
|
|
|
|
steps:
|
|
- checkout
|
|
|
|
- go/load-cache:
|
|
key: quickcheck-<<parameters.goversion>>
|
|
- run: make build/install
|
|
- run: go mod download
|
|
- run: cd build && go mod download
|
|
- go/save-cache:
|
|
key: quickcheck-<<parameters.goversion>>
|
|
|
|
# ensure all code has been generated
|
|
- run: make generate
|
|
- run: |
|
|
if output=$(git status --porcelain) && [ -z "$output" ]; then
|
|
echo "Working directory clean"
|
|
else
|
|
echo "Uncommitted changes"
|
|
echo ""
|
|
echo "$output"
|
|
exit 1
|
|
fi
|
|
|
|
# other checks
|
|
- run: make zrepl-bin test-platform-bin
|
|
- run: make vet
|
|
- run: make lint
|
|
|
|
- store_artifacts:
|
|
path: artifacts
|
|
- persist_to_workspace:
|
|
root: .
|
|
paths: [.]
|
|
|
|
platformtest:
|
|
parameters:
|
|
goversion:
|
|
type: string
|
|
goos:
|
|
type: string
|
|
goarch:
|
|
type: string
|
|
machine:
|
|
image: ubuntu-2204:current
|
|
resource_class: medium
|
|
environment:
|
|
GOOS: <<parameters.goos>>
|
|
GOARCH: <<parameters.goarch>>
|
|
steps:
|
|
- attach_workspace:
|
|
at: .
|
|
- run: sudo apt-get update
|
|
- run: sudo apt-get install -y zfsutils-linux
|
|
- run: sudo zfs version
|
|
- run: sudo make test-platform GOOS="$GOOS" GOARCH="$GOARCH"
|
|
|
|
test-go:
|
|
parameters:
|
|
goversion:
|
|
type: string
|
|
docker:
|
|
- image: *cimg_with_modern_go
|
|
environment:
|
|
GOTOOLCHAIN: "go<<parameters.goversion>>"
|
|
steps:
|
|
- checkout
|
|
- go/load-cache:
|
|
key: make-test-go
|
|
- run: make test-go
|
|
- go/save-cache:
|
|
key: make-test-go
|
|
|
|
release-build:
|
|
machine:
|
|
image: &release-vm-image "ubuntu-2404:current"
|
|
resource_class: large
|
|
steps:
|
|
- checkout
|
|
- run: make release-docker
|
|
- persist_to_workspace:
|
|
root: .
|
|
paths: [.]
|
|
release-deb:
|
|
machine:
|
|
image: *release-vm-image
|
|
steps:
|
|
- attach_workspace:
|
|
at: .
|
|
- run: make debs-docker
|
|
- persist_to_workspace:
|
|
root: .
|
|
paths:
|
|
- "artifacts/*.deb"
|
|
|
|
release-rpm:
|
|
machine:
|
|
image: *release-vm-image
|
|
steps:
|
|
- attach_workspace:
|
|
at: .
|
|
- run: make rpms-docker
|
|
- persist_to_workspace:
|
|
root: .
|
|
paths:
|
|
- "artifacts/*.rpm"
|
|
|
|
release-upload:
|
|
docker:
|
|
- image: cimg/base:2024.09
|
|
steps:
|
|
- attach_workspace:
|
|
at: .
|
|
- run: make wrapup-and-checksum
|
|
- store_artifacts:
|
|
path: artifacts/release
|
|
|
|
publish-zrepl-github-io:
|
|
docker:
|
|
- image: cimg/base:2024.09
|
|
steps:
|
|
- checkout
|
|
- install-docdep
|
|
- docs-publish-sh:
|
|
push: true
|
|
- save-uv-cache
|