You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Make package generation and GPG signing optional in the CD build
Forks could not run the deployment workflow cleanly: the GPG import step
ran unconditionally, so a repository without GPG_PRIVATE_KEY got a failed
step on every run. The continue-on-error that hid it was also a hazard
upstream, where a broken key would silently republish the site with an
unsigned APT repository in place of a signed one and break apt-get update
for every client pinned with signed-by.
Resolve two independent feature flags up front, since the secrets context
is not readable from a step-level if condition:
- Package repository generation follows the BUILD_PACKAGES variable, and
defaults on for this repository and off for forks, so a fork build only
exercises the site and Pages publish.
- Signing follows the presence of GPG_PRIVATE_KEY. When the key is absent
the import step is skipped rather than failed; when it is present the
import must succeed, and the artifact check now asserts that InRelease,
Release.gpg and the exported keyring were produced.
Document the fork workflow and both settings in the readme.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Guanzhou Song <guanzhou.song@gmail.com>
Copy file name to clipboardExpand all lines: readme.md
+25Lines changed: 25 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -112,6 +112,31 @@ Documentation articles and API reference content are managed in a separate repos
112
112
> - API reference content (`api-reference/`)
113
113
>
114
114
115
+
### Testing the Deployment Workflow in a Fork
116
+
117
+
The [deployment workflow](.github/workflows/continuous-deployment.yml) builds the static site, mirrors the DocumentDB release packages into APT and YUM repositories, signs those repositories, and publishes everything to GitHub Pages.
118
+
119
+
Only the static site build is mandatory. Packaging and signing are resolved automatically at the start of the run, so a fork with no repository secrets can exercise the whole workflow:
120
+
121
+
1. Enable GitHub Pages in your fork (**Settings** > **Pages** > **Source**: *GitHub Actions*)
122
+
123
+
1. Push to `main` in your fork, or run the workflow manually from the **Actions** tab
124
+
125
+
1. Check the run summary, which reports which optional features were enabled and why
126
+
127
+
The two optional halves are controlled independently:
128
+
129
+
| Setting | Type | Default | Effect when enabled |
130
+
| --- | --- | --- | --- |
131
+
| `BUILD_PACKAGES` | Variable | On in `documentdb/documentdb.github.io`, off in forks | Downloads the release `.deb` and `.rpm` assets and builds the APT and YUM repositories |
132
+
| `GPG_PRIVATE_KEY` | Secret | *unset* | Signs the APT `Release` file and the RPM metadata, and publishes `documentdb-archive-keyring.gpg` |
133
+
| `DOCUMENTDB_VERSION` | Variable | `latest` | Release tag the packages are mirrored from |
134
+
135
+
Set `BUILD_PACKAGES` to `true` in your fork if you specifically want to test the packaging path; signing is then skipped unless you also add your own `GPG_PRIVATE_KEY`.
136
+
137
+
> [!IMPORTANT]
138
+
> Signing is optional, but it never fails quietly. When `GPG_PRIVATE_KEY` is set, the run fails if the key cannot be imported or the signatures are not produced. Publishing an unsigned repository over a signed one breaks `apt-get update` for every client that already trusts the keyring.
139
+
115
140
## Content Configuration
116
141
117
142
Documentation content is automatically compiled during builds from external repositories. The mapping is configured in [content.config.json](content.config.json).
0 commit comments