From 8447b6985b7b93ba0fa04adc565bb6de36e11ee7 Mon Sep 17 00:00:00 2001 From: Jason Date: Fri, 9 Feb 2024 10:42:51 +1100 Subject: [PATCH] ci(notation): remove release workflow --- .github/workflows/release-notation.yaml | 114 ------------------------ 1 file changed, 114 deletions(-) delete mode 100644 .github/workflows/release-notation.yaml diff --git a/.github/workflows/release-notation.yaml b/.github/workflows/release-notation.yaml deleted file mode 100644 index 850193c..0000000 --- a/.github/workflows/release-notation.yaml +++ /dev/null @@ -1,114 +0,0 @@ -name: release - -on: - push: - tags: - - '*' - -permissions: - contents: read - -jobs: - release: - runs-on: ubuntu-latest - permissions: - contents: write # needed to write releases - id-token: write # needed for keyless signing - packages: write # needed for ghcr access - steps: - - uses: actions/checkout@v4 - - name: Setup Notation CLI - uses: notaryproject/notation-action/setup@v1 - with: - version: "1.0.0" - - name: Setup Notation signing keys - run: | - mkdir -p ~/.config/notation/localkeys/ - cp ./.notation/signingkeys.json ~/.config/notation/ - cp ./.notation/notation.crt ~/.config/notation/localkeys/ - echo "$NOTATION_KEY" > ~/.config/notation/localkeys/notation.key - env: - NOTATION_KEY: ${{ secrets.SIGNING_KEY }} - - uses: fluxcd/flux2/action@main - - name: Setup Go - uses: actions/setup-go@v4 - with: - go-version: 1.21.x - - name: Setup Helm - uses: azure/setup-helm@v3 - with: - version: v3.12.3 - - name: Setup QEMU - uses: docker/setup-qemu-action@v3 - with: - platforms: all - - name: Setup Docker Buildx - id: buildx - uses: docker/setup-buildx-action@v3 - - name: Login to GitHub Container Registry - uses: docker/login-action@v3 - with: - registry: ghcr.io - username: ${{ github.actor }} - password: ${{ secrets.GITHUB_TOKEN }} - - name: Prepare - id: prep - run: | - VERSION=sha-${GITHUB_SHA::8} - if [[ $GITHUB_REF == refs/tags/* ]]; then - VERSION=${GITHUB_REF/refs\/tags\//} - fi - echo "BUILD_DATE=$(date -u +'%Y-%m-%dT%H:%M:%SZ')" >> $GITHUB_OUTPUT - echo "VERSION=${VERSION}" >> $GITHUB_OUTPUT - echo "REVISION=${GITHUB_SHA}" >> $GITHUB_OUTPUT - - name: Generate images meta - id: meta - uses: docker/metadata-action@v5 - with: - images: | - ghcr.io/jasonthedeveloper/podinfo - tags: | - type=raw,value=${{ steps.prep.outputs.VERSION }} - type=raw,value=latest - - name: Publish multi-arch image - uses: docker/build-push-action@v5 - with: - sbom: true - provenance: true - push: true - builder: ${{ steps.buildx.outputs.name }} - context: . - file: ./Dockerfile.xx - build-args: | - REVISION=${{ steps.prep.outputs.REVISION }} - platforms: linux/amd64,linux/arm/v7,linux/arm64 - tags: ${{ steps.meta.outputs.tags }} - labels: ${{ steps.meta.outputs.labels }} - - name: Publish Helm chart to GHCR - run: | - helm package charts/podinfo - helm push podinfo-${{ steps.prep.outputs.VERSION }}.tgz oci://ghcr.io/jasonthedeveloper/charts - rm podinfo-${{ steps.prep.outputs.VERSION }}.tgz - - name: Publish Flux OCI artifact to GHCR - run: | - flux push artifact oci://ghcr.io/jasonthedeveloper/manifests/podinfo:${{ steps.prep.outputs.VERSION }} \ - --path="./kustomize" \ - --source="${{ github.event.repository.html_url }}" \ - --revision="${GITHUB_REF_NAME}/${GITHUB_SHA}" - flux tag artifact oci://ghcr.io/jasonthedeveloper/manifests/podinfo:${{ steps.prep.outputs.VERSION }} --tag latest - - name: Sign OCI artifacts - run: | - notation sign --signature-format cose ghcr.io/jasonthedeveloper/podinfo:${{ steps.prep.outputs.VERSION }} - notation sign --signature-format cose ghcr.io/jasonthedeveloper/charts/podinfo:${{ steps.prep.outputs.VERSION }} - notation sign --signature-format cose ghcr.io/jasonthedeveloper/manifests/podinfo:${{ steps.prep.outputs.VERSION }} - - name: Publish config artifact - run: | - flux push artifact oci://ghcr.io/jasonthedeveloper/podinfo-deploy:${{ steps.prep.outputs.VERSION }} \ - --path="./kustomize" \ - --source="${{ github.event.repository.html_url }}" \ - --revision="${GITHUB_REF_NAME}/${GITHUB_SHA}" - flux tag artifact oci://ghcr.io/jasonthedeveloper/podinfo-deploy:${{ steps.prep.outputs.VERSION }} --tag latest - - name: Sign config artifact - run: | - notation sign --signature-format cose ghcr.io/jasonthedeveloper/podinfo-deploy:${{ steps.prep.outputs.VERSION }} - notation sign --signature-format cose ghcr.io/jasonthedeveloper/podinfo-deploy:latest