diff --git a/.github/workflows/check-authorized-user.yml b/.github/workflows/check-authorized-user.yml deleted file mode 100644 index 432d372..0000000 --- a/.github/workflows/check-authorized-user.yml +++ /dev/null @@ -1,19 +0,0 @@ -name: Check Authorized User -on: - workflow_call: -jobs: - check-authorized-user: - runs-on: ubuntu-latest - defaults: - run: - shell: pwsh - steps: - - name: Verify authorized user - run: | - $actor = "${{ github.actor }}" - $authorizedUsers = "${{ vars.AUTHORIZED_RELEASE_USERS }}" -split ',' | ForEach-Object { $_.Trim() } - if ($authorizedUsers -notcontains $actor) { - Write-Error "User '$actor' is not authorized to run this workflow." - exit 1 - } - Write-Output "User '$actor' is authorized to run this workflow." diff --git a/.github/workflows/generate-release-notes.yml b/.github/workflows/generate-release-notes.yml deleted file mode 100644 index e6f5e6f..0000000 --- a/.github/workflows/generate-release-notes.yml +++ /dev/null @@ -1,34 +0,0 @@ -name: Generate Release Notes -on: - workflow_call: - inputs: - version: - required: true - type: string -jobs: - generate-release-notes: - runs-on: ubuntu-latest - defaults: - run: - shell: pwsh - steps: - - name: Checkout - uses: actions/checkout@v7.0.1 - - name: Setup .NET SDK - uses: actions/setup-dotnet@v6.0.0 - with: - global-json-file: global.json - - name: Setup GitReleaseManager - # https://github.com/GitTools/GitReleaseManager#net-global-tool - run: | - dotnet tool install --global GitReleaseManager.Tool - Write-Output "`nGitReleaseManager.yaml contents:" - Get-Content .release/GitReleaseManager.yaml - Write-Output "`n`nGitReleaseManager issue-note.sbn template:" - Get-Content .release/.templates/default/issue-note.sbn - - name: Update draft release notes from milestone - run: | - Write-Output "Updating draft release body for ${{ github.event.repository.name }} ${{ inputs.version }} from milestone '${{ inputs.version }}'" - dotnet-gitreleasemanager create --token $env:GITHUB_TOKEN -o "${{ github.repository_owner }}" -r "${{ github.event.repository.name }}" -m "${{ inputs.version }}" -n "${{ inputs.version }}" -d .release - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/publish-release-notes.yml b/.github/workflows/publish-release-notes.yml deleted file mode 100644 index ef0c346..0000000 --- a/.github/workflows/publish-release-notes.yml +++ /dev/null @@ -1,27 +0,0 @@ -name: Publish Release Notes -on: - workflow_call: - inputs: - version: - required: true - type: string -jobs: - publish-release-notes: - runs-on: ubuntu-latest - defaults: - run: - shell: pwsh - steps: - - name: Setup .NET SDK - uses: actions/setup-dotnet@v6 - with: - dotnet-version: 'latest' - - name: Setup GitReleaseManager - # https://github.com/GitTools/GitReleaseManager#net-global-tool - run: dotnet tool install --global GitReleaseManager.Tool - - name: Publish release - run: | - Write-Output "Publishing release ${{ inputs.version }} for ${{ github.event.repository.name }}" - dotnet-gitreleasemanager publish --token $env:GITHUB_TOKEN -o "${{ github.repository_owner }}" -r "${{ github.event.repository.name }}" -t "${{ inputs.version }}" - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/push-docker-images.yml b/.github/workflows/push-docker-images.yml deleted file mode 100644 index 6641ae0..0000000 --- a/.github/workflows/push-docker-images.yml +++ /dev/null @@ -1,12 +0,0 @@ -name: Push Docker Images -on: - workflow_call: -jobs: - push-docker-images: - runs-on: ubuntu-latest - defaults: - run: - shell: bash - steps: - - name: Placeholder - run: echo "Placeholder for pushing Docker images" diff --git a/.github/workflows/push-nuget-packages-staging.yml b/.github/workflows/push-nuget-packages-staging.yml deleted file mode 100644 index 5833a58..0000000 --- a/.github/workflows/push-nuget-packages-staging.yml +++ /dev/null @@ -1,50 +0,0 @@ -name: Push NuGet Packages to Staging -on: - workflow_call: - inputs: - version: - required: true - type: string - exclude-package-pattern: - required: false - type: string - default: '' -jobs: - push-nuget-packages: - permissions: - id-token: write - contents: write - runs-on: ubuntu-latest - defaults: - run: - shell: pwsh - steps: - - name: Setup .NET SDK - uses: actions/setup-dotnet@v6 - with: - dotnet-version: 'latest' - - name: Download assets from draft release - run: | - $name = "${{ inputs.version }}" - $releases = gh api "repos/${{ github.repository }}/releases" | ConvertFrom-Json - $release = $releases | Where-Object { $_.name -eq $name } | Select-Object -First 1 - if (-not $release) { - throw "Could not find a release named '$name'" - } - Write-Output "Found draft release id $($release.id) with tag '$($release.tag_name)' for '$name'" - - gh release download $release.tag_name --repo "${{ github.repository }}" --pattern "*.nupkg" --dir nugets - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - - name: Push NuGet packages to staging feed - run: | - $getChildItemParams = @{ Path = 'nugets/*'; Include = '*.nupkg' } - $excludePattern = "${{ inputs.exclude-package-pattern }}" - if ($excludePattern) { $getChildItemParams.Exclude = $excludePattern } - $packages = Get-ChildItem @getChildItemParams - Write-Output "Pushing $($packages.Count) NuGet package(s) to ${{ vars.PARTICULAR_TESTING_FEED_URL }}:" - $packages | ForEach-Object { Write-Output " - $($_.Name)" } - foreach ($package in $packages) - { - dotnet nuget push $package.FullName --source ${{ vars.PARTICULAR_TESTING_FEED_URL }} --api-key ${{ secrets.FEEDZIO_PUBLISH_API_KEY }} - } diff --git a/.github/workflows/push-nuget-packages.yml b/.github/workflows/push-nuget-packages.yml deleted file mode 100644 index 19face1..0000000 --- a/.github/workflows/push-nuget-packages.yml +++ /dev/null @@ -1,48 +0,0 @@ -name: Push NuGet Packages -on: - workflow_call: - inputs: - version: - required: true - type: string - exclude-package-pattern: - required: false - type: string - default: '' -jobs: - push-nuget-packages: - permissions: - id-token: write - runs-on: ubuntu-latest - defaults: - run: - shell: pwsh - steps: - - name: Setup .NET SDK - uses: actions/setup-dotnet@v6 - with: - dotnet-version: 'latest' - - name: Download assets from release - run: | - gh release download "${{ inputs.version }}" --repo "${{ github.repository }}" --pattern "*.nupkg" --dir nugets - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - - name: Get NuGet trusted publishing API key - uses: NuGet/login@v1 - id: login - with: - user: ${{ secrets.TEST_NUGET_USER }} - token-service-url: ${{ vars.NUGET_SOURCE_DOMAIN }}/api/v2/token - audience: ${{ vars.NUGET_SOURCE_DOMAIN }} - - name: Push NuGet packages to production feed - run: | - $getChildItemParams = @{ Path = 'nugets/*'; Include = '*.nupkg' } - $excludePattern = "${{ inputs.exclude-package-pattern }}" - if ($excludePattern) { $getChildItemParams.Exclude = $excludePattern } - $packages = Get-ChildItem @getChildItemParams - Write-Output "Pushing $($packages.Count) NuGet package(s) to ${{ vars.NUGET_SOURCE_DOMAIN }}:" - $packages | ForEach-Object { Write-Output " - $($_.Name)" } - foreach ($package in $packages) - { - dotnet nuget push $package.FullName --source ${{ vars.NUGET_SOURCE_DOMAIN }}/api/v2/package --api-key ${{steps.login.outputs.NUGET_API_KEY}} - } diff --git a/.github/workflows/push-powershell-packages.yml b/.github/workflows/push-powershell-packages.yml deleted file mode 100644 index 4d48ce8..0000000 --- a/.github/workflows/push-powershell-packages.yml +++ /dev/null @@ -1,38 +0,0 @@ -name: Push PowerShell Packages -on: - workflow_call: - inputs: - version: - required: true - type: string - package-pattern: - required: true - type: string -jobs: - push-powershell-packages: - runs-on: ubuntu-latest - defaults: - run: - shell: pwsh - steps: - - name: Download assets from release - run: | - gh release download "${{ inputs.version }}" --repo "${{ github.repository }}" --pattern "${{ inputs.package-pattern }}" --dir powershellModules - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - - - name: Push Powershell modules packages to gallery - run: | - $repo = Get-PSResourceRepository -Name ${{ vars.GALLERY_NAME }} -ErrorAction Ignore - - if ($null -eq $repo) - { - Register-PSResourceRepository -Name ${{ vars.GALLERY_NAME }} -Uri ${{ vars.GALLERY_SOURCE_LOCATION }} -Trusted - } - $psModules = Get-ChildItem powershellModules -File - Write-Output "Pushing $($psModules.Count) PowerShell module package(s) to ${{ vars.GALLERY_NAME }}:" - $psModules | ForEach-Object { Write-Output " - $($_.Name)" } - foreach ($module in $psModules) - { - Publish-PSResource -NupkgPath $module.FullName -Repository ${{ vars.GALLERY_NAME }} -ApiKey ${{ secrets.GALLERY_KEY }} - } diff --git a/.github/workflows/push-release-info-to-aws-s3.yml b/.github/workflows/push-release-info-to-aws-s3.yml deleted file mode 100644 index f37b951..0000000 --- a/.github/workflows/push-release-info-to-aws-s3.yml +++ /dev/null @@ -1,84 +0,0 @@ -name: Push Release Info to AWS S3 -on: - workflow_call: - inputs: - version: - required: true - type: string - product: - required: true - type: string - bucket: - required: true - type: string -jobs: - push-release-info-to-aws-s3: - runs-on: ubuntu-latest - defaults: - run: - shell: pwsh - steps: - - name: Setup AWS Credentials - uses: aws-actions/configure-aws-credentials@v5.1.1 - with: - aws-access-key-id: ${{ secrets.AWS_ACCESSKEY }} - aws-secret-access-key: ${{ secrets.AWS_SECRETKEY }} - aws-region: us-west-2 - - name: Push release info to S3 - run: | - $product = "${{ inputs.product }}" - - try { - $response = Invoke-WebRequest -Uri https://api.github.com/repos/${{ github.repository }}/releases/tags/${{ inputs.version }} -UseBasicParsing - } - catch { - Write-Error "Failed to fetch release ${{ inputs.version }}: $($_.Exception.Message)" - exit 1 - } - - # Filter and rework the JSON - $obj = ConvertFrom-Json $response.Content -ErrorAction Stop - - if ($obj.Draft -or $obj.Prerelease) { - Write-Error "Release $($obj.tag_name) is a draft or prerelease, aborting" - exit 1 - } - - $release = $obj | Select-Object -Property @{Name="tag";Expression={$_."tag_name"}}, @{Name="release";Expression={$_."html_url"}}, @{Name="published";Expression={$_."published_at"}}, assets - if (-not ($release.tag -match '^\d+\.\d+\.\d+$')) { - Write-Error "Release $($release.tag) has an invalid tag format, aborting" - exit 1 - } - - $release.assets = @($release.assets | Where-Object name -Like "*.exe" | Select-Object -Property name, size, @{Name="download";Expression={$_."browser_download_url"}}) - - if (-not $release.assets) { - Write-Error "Release $($release.tag) has no exe assets, aborting" - exit 1 - } - - $newobj = @($release) - $json = ConvertTo-Json $newobj -Depth 100 -ErrorAction Stop - - # Write JSON to S3 - $bucket = "${{ inputs.bucket }}" - $key = "{0}.txt" -f $product.ToLower() - $tempFile = New-TemporaryFile - Set-Content -Path $tempFile -Value $json -NoNewline - - aws s3 cp $tempFile "s3://$bucket/$key" --content-type application/json - if ($LASTEXITCODE -ne 0) { - Write-Error "Upload to S3 failed" - exit 1 - } - - # Double check upload - $expectedSize = ([System.Text.Encoding]::UTF8.GetByteCount($json)) - $uploadedSize = aws s3api head-object --bucket $bucket --key $key --query ContentLength --output text - if ([int]$uploadedSize -ne $expectedSize) { - Write-Error "Content verification failed" - exit 1 - } - else { - Write-Output ("Updated file now be available at http://{0}/{1} (case sensitive URL)" -f $bucket, $key) - } diff --git a/.github/workflows/release-deploy-production.yml b/.github/workflows/release-deploy-production.yml index de0e855..36b0979 100644 --- a/.github/workflows/release-deploy-production.yml +++ b/.github/workflows/release-deploy-production.yml @@ -7,10 +7,10 @@ on: type: string jobs: check-authorized-user: - uses: ./.github/workflows/check-authorized-user.yml + uses: Particular/deployment-workflows/.github/workflows/authorize-user.yml@0.0.1 publish-release-notes: needs: check-authorized-user - uses: ./.github/workflows/publish-release-notes.yml + uses: Particular/deployment-workflows/.github/workflows/publish-release-notes.yml@0.0.1 with: version: ${{ inputs.version }} secrets: inherit @@ -33,24 +33,24 @@ jobs: permissions: id-token: write needs: publish-release-notes - uses: ./.github/workflows/push-nuget-packages.yml + uses: Particular/deployment-workflows/.github/workflows/push-nuget-packages.yml@0.0.1 with: version: ${{ inputs.version }} exclude-package-pattern: "TotallyLegit.ServiceControl.Management.*.nupkg" secrets: inherit push-docker-images: needs: publish-release-notes - uses: ./.github/workflows/push-docker-images.yml + uses: Particular/deployment-workflows/.github/workflows/push-docker-images.yml@0.0.1 push-powershell-packages: needs: publish-release-notes - uses: ./.github/workflows/push-powershell-packages.yml + uses: Particular/deployment-workflows/.github/workflows/push-powershell-packages.yml@0.0.1 with: version: ${{ inputs.version }} package-pattern: "TotallyLegit.ServiceControl.Management.*.nupkg" secrets: inherit push-release-info-to-aws-s3: needs: publish-release-notes - uses: ./.github/workflows/push-release-info-to-aws-s3.yml + uses: Particular/deployment-workflows/.github/workflows/push-release-info-to-aws-s3.yml@0.0.1 with: version: ${{ inputs.version }} product: "TotallyLegit.App" diff --git a/.github/workflows/release-deploy-staging.yml b/.github/workflows/release-deploy-staging.yml index f2741b1..10e46c7 100644 --- a/.github/workflows/release-deploy-staging.yml +++ b/.github/workflows/release-deploy-staging.yml @@ -7,20 +7,20 @@ on: type: string jobs: check-authorized-user: - uses: ./.github/workflows/check-authorized-user.yml + uses: Particular/deployment-workflows/.github/workflows/authorize-user.yml@0.0.1 push-nuget-packages-staging: needs: check-authorized-user permissions: id-token: write contents: write - uses: ./.github/workflows/push-nuget-packages-staging.yml + uses: Particular/deployment-workflows/.github/workflows/push-nuget-packages-staging.yml@0.0.1 with: version: ${{ inputs.version }} exclude-package-pattern: "TotallyLegit.ServiceControl.Management.*.nupkg" secrets: inherit generate-release-notes: needs: check-authorized-user - uses: ./.github/workflows/generate-release-notes.yml + uses: Particular/deployment-workflows/.github/workflows/generate-release-notes.yml@0.0.1 with: version: ${{ inputs.version }} secrets: inherit