name: Release # Cut a SemVer tag from main HEAD, then call deploy. GITHUB_TOKEN is enough; # it cannot start other workflows via the tag push, so this file calls deploy. on: workflow_dispatch: inputs: environment: description: Target environment required: true type: choice options: [staging, prod] bump: description: SemVer bump from the last prod core tag required: true type: choice options: [patch, minor, major] message: description: Annotated tag message and GitHub Release body required: true type: string permissions: contents: write checks: read jobs: cut: name: Cut tag runs-on: ubuntu-latest timeout-minutes: 40 outputs: tag: ${{ steps.tag.outputs.tag }} sha: ${{ steps.tag.outputs.sha }} environment: ${{ github.event.inputs.environment }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 persist-credentials: true - name: Require main run: | set -euo pipefail if [ "${GITHUB_REF}" != "refs/heads/main" ]; then echo "Release must run from main (Use workflow from: main). Got ${GITHUB_REF}." >&2 exit 1 fi - name: Require CI env: GITHUB_TOKEN: ${{ github.token }} run: | python3 scripts/require_commit_checks.py \ --repo "${{ github.repository }}" \ --sha "$(git rev-parse HEAD)" \ --timeout-seconds 1200 - name: Compute and push tag id: tag env: ENVIRONMENT: ${{ github.event.inputs.environment }} BUMP: ${{ github.event.inputs.bump }} MESSAGE: ${{ github.event.inputs.message }} GH_TOKEN: ${{ github.token }} run: | set -euo pipefail git fetch --tags origin sha="$(git rev-parse HEAD)" tag="$(git tag | python3 scripts/next_release_tag.py --environment "${ENVIRONMENT}" --bump "${BUMP}")" git config user.name "github-actions[bot]" git config user.email "41898282+github-actions[bot]@users.noreply.github.com" git tag -a "${tag}" -m "${MESSAGE}" "${sha}" git push origin "refs/tags/${tag}" gh release create "${tag}" --target "${sha}" --notes "${MESSAGE}" --title "${tag}" { echo "tag=${tag}" echo "sha=${sha}" } >> "${GITHUB_OUTPUT}" echo "Created ${tag} at ${sha}" deploy: name: Deploy release needs: cut uses: ./.github/workflows/deploy.yaml with: environment: ${{ needs.cut.outputs.environment }} ref: ${{ needs.cut.outputs.tag }} secrets: inherit