Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
54 changes: 49 additions & 5 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,15 +6,59 @@ on:
tags:
- '*'

permissions: {}

jobs:
build:
name: Build gem
runs-on: ubuntu-24.04
if: github.repository_owner == 'theforeman'
permissions:
contents: read
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- uses: ruby/setup-ruby@v1
with:
ruby-version: ruby
- name: Build man page
run: |
sudo apt-get update
sudo apt-get install --yes --no-install-recommends \
asciidoc-base docbook-xml docbook-xsl xsltproc libxml2-utils
a2x -d manpage -f manpage -D man/ man/hammer.1.asciidoc
gzip -f9 man/hammer.1
- name: Build gem
run: gem build --verbose hammer_cli.gemspec
- name: Check that the gem version matches the tag
run: test -f "hammer_cli-${GITHUB_REF_NAME}.gem"
- uses: actions/upload-artifact@v7
with:
name: gem-artifact
path: hammer_cli-*.gem
if-no-files-found: error
retention-days: 1
compression-level: 0

release:
name: Release gem
runs-on: ubuntu-latest
needs: build
runs-on: ubuntu-24.04
environment: release
if: github.repository_owner == 'theforeman'

permissions:
id-token: write

steps:
- uses: voxpupuli/ruby-release@v0

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why can't we keep using the voxpupuli one as we use in all other repos? We need to fix the gemspec to make it work.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The gemspec lists man/hammer.1.gz because it needs to ship in the gem, but that file must be generated before gem build. Removing it would make the build pass while dropping the man page.

I raised this in voxpupuli/ruby-release#13, where ekohl suggested starting with a longer Hammer-specific workflow that separates building from publishing. This PR follows that approach, keeping build steps outside the job with publishing permissions. I prefer shared tooling too, but we’d need support for generated files or a prebuilt gem, not just a gemspec change.

- uses: actions/download-artifact@v8
with:
name: gem-artifact
- uses: ruby/setup-ruby@v1
with:
ruby-version: ruby
- uses: rubygems/[email protected]
- name: Publish gem to rubygems.org
run: gem push hammer_cli-*.gem
- name: Wait for release to propagate
run: |
gem install rubygems-await
gem await hammer_cli-*.gem
Loading