From ebe725cbec59fe2b4b3dd2fb99abdef4601feccd Mon Sep 17 00:00:00 2001 From: HarshwardhanPatil07 Date: Thu, 1 Oct 2026 16:17:16 +0530 Subject: [PATCH 1/3] release: draft from an existing tag Signed-off-by: HarshwardhanPatil07 --- .github/workflows/release.yaml | 20 +++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 98933c5..23e447a 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -4,6 +4,12 @@ on: push: tags: - 'v*' + workflow_dispatch: + inputs: + tag: + description: Existing release tag + required: true + type: string env: REGISTRY: ghcr.io @@ -17,10 +23,18 @@ jobs: steps: - name: Checkout uses: actions/checkout@v7 + with: + ref: ${{ inputs.tag || github.ref }} + fetch-depth: 0 - name: Extract version from tag id: version - run: echo "version=${GITHUB_REF_NAME}" >> "$GITHUB_OUTPUT" + env: + RELEASE_TAG: ${{ inputs.tag || github.ref_name }} + run: | + [[ "$RELEASE_TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]] || exit 1 + git rev-parse -q --verify "refs/tags/$RELEASE_TAG^{commit}" >/dev/null + echo "version=$RELEASE_TAG" >> "$GITHUB_OUTPUT" - name: Log in to GHCR run: podman login -u ${{ github.actor }} -p ${{ secrets.GITHUB_TOKEN }} ${{ env.REGISTRY }} @@ -33,7 +47,7 @@ jobs: podman cp bink-builder-tmp:/output/bink ./bink podman rm bink-builder-tmp chmod +x ./bink - ./bink version + podman run --rm localhost/bink-builder:latest /output/bink version - name: Build and push bink image run: | @@ -66,4 +80,4 @@ jobs: gh release create ${{ steps.version.outputs.version }} \ ./bink \ --title "${{ steps.version.outputs.version }}" \ - --generate-notes + --generate-notes --draft From f5598f2e63416b2d058c77beff28df49b4ab1d06 Mon Sep 17 00:00:00 2001 From: HarshwardhanPatil07 Date: Thu, 1 Oct 2026 16:27:05 +0530 Subject: [PATCH 2/3] release: Build downloadable binary on runner Build the release asset with the Ubuntu dependencies used by CI so the runner can execute it before attaching it to the draft release. Assisted-by: AI Signed-off-by: HarshwardhanPatil07 --- .github/workflows/release.yaml | 28 ++++++++++++++++++++-------- 1 file changed, 20 insertions(+), 8 deletions(-) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 23e447a..6d977e3 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -39,15 +39,27 @@ jobs: - name: Log in to GHCR run: podman login -u ${{ github.actor }} -p ${{ secrets.GITHUB_TOKEN }} ${{ env.REGISTRY }} - - name: Build bink binary + - name: Set up Go + uses: actions/setup-go@v7 + with: + go-version-file: go.mod + cache: true + + - name: Install build dependencies + run: | + sudo apt-get update + sudo apt-get install -y \ + libgpgme-dev \ + libbtrfs-dev \ + libdevmapper-dev \ + pkg-config + + - name: Build and verify bink binary + env: + RELEASE_TAG: ${{ steps.version.outputs.version }} run: | - podman build --build-arg VERSION=${{ steps.version.outputs.version }} \ - --target builder -t localhost/bink-builder:latest -f Containerfile . - podman create --name bink-builder-tmp localhost/bink-builder:latest - podman cp bink-builder-tmp:/output/bink ./bink - podman rm bink-builder-tmp - chmod +x ./bink - podman run --rm localhost/bink-builder:latest /output/bink version + make build-bink VERSION="${RELEASE_TAG}" + ./bink version - name: Build and push bink image run: | From d2276d1f7eac73577073d06c4d0186a552997b6a Mon Sep 17 00:00:00 2001 From: HarshwardhanPatil07 Date: Thu, 1 Oct 2026 16:32:48 +0530 Subject: [PATCH 3/3] release: Reuse an existing draft release A draft for v0.1.2 already exists. Allow a manually dispatched release run to attach the built binary to that draft while preserving automatic draft creation for future tags. Assisted-by: AI Signed-off-by: HarshwardhanPatil07 --- .github/workflows/release.yaml | 35 +++++++++++++++++++++++++++++----- 1 file changed, 30 insertions(+), 5 deletions(-) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 6d977e3..4076b86 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -36,6 +36,21 @@ jobs: git rev-parse -q --verify "refs/tags/$RELEASE_TAG^{commit}" >/dev/null echo "version=$RELEASE_TAG" >> "$GITHUB_OUTPUT" + - name: Check GitHub Release + id: release_state + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + RELEASE_TAG: ${{ steps.version.outputs.version }} + run: | + is_draft=$(gh release list --limit 1000 --json tagName,isDraft \ + --jq ".[] | select(.tagName == \"$RELEASE_TAG\") | .isDraft") + case "$is_draft" in + true) echo "exists=true" >> "$GITHUB_OUTPUT" ;; + false) echo "Release $RELEASE_TAG is already published" >&2; exit 1 ;; + '') echo "exists=false" >> "$GITHUB_OUTPUT" ;; + *) echo "Unexpected release state: $is_draft" >&2; exit 1 ;; + esac + - name: Log in to GHCR run: podman login -u ${{ github.actor }} -p ${{ secrets.GITHUB_TOKEN }} ${{ env.REGISTRY }} @@ -85,11 +100,21 @@ jobs: podman push ${{ env.REGISTRY }}/${{ github.repository }}/dns:${{ steps.version.outputs.version }} podman push ${{ env.REGISTRY }}/${{ github.repository }}/dns:latest - - name: Create GitHub Release + - name: Create or update draft GitHub Release env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + RELEASE_TAG: ${{ steps.version.outputs.version }} + RELEASE_EXISTS: ${{ steps.release_state.outputs.exists }} run: | - gh release create ${{ steps.version.outputs.version }} \ - ./bink \ - --title "${{ steps.version.outputs.version }}" \ - --generate-notes --draft + if [[ "$RELEASE_EXISTS" == true ]]; then + [[ $(gh release view "$RELEASE_TAG" --json isDraft --jq .isDraft) == true ]] || { + echo "Release $RELEASE_TAG is no longer a draft" >&2 + exit 1 + } + gh release upload "$RELEASE_TAG" ./bink --clobber + else + gh release create "$RELEASE_TAG" \ + ./bink \ + --title "$RELEASE_TAG" \ + --generate-notes --draft + fi