Files
StarterNG/.github/workflows/dotnet.yml
maj00r 5e4416c9cb Publish rolling pre-releases for main and staging
Workflow artifacts can only be downloaded by signed-in users with access to
the repository, so they are useless for handing a build to anyone else. After
the matrix publishes, a release job recreates a rolling pre-release from the
same packages; its assets are downloadable without an account:

  releases/download/latest/<file>    from main
  releases/download/staging/<file>   from staging

Each branch owns its tag, so a staging build never overwrites the main one.
The release is deleted and created again rather than edited, so the tag
follows its branch and assets from an older build do not linger. Write access
is granted to that job only, the workflow default stays read.
2026-08-25 23:38:26 +02:00

153 lines
4.0 KiB
YAML

name: Build NativeAOT
on:
push:
branches:
- main
- staging
pull_request:
branches:
- main
- staging
workflow_dispatch:
permissions:
contents: read
env:
DOTNET_CLI_TELEMETRY_OPTOUT: 1
DOTNET_NOLOGO: true
PROJECT_PATH: StarterNG/StarterNG.csproj
jobs:
publish:
name: ${{ matrix.name }}
strategy:
fail-fast: false
matrix:
include:
- name: Windows x64
os: windows-2022
rid: win-x64
artifact: StarterNG-windows-x64
package: artifacts/StarterNG-windows-x64.zip
- name: Linux x64
os: ubuntu-22.04
rid: linux-x64
artifact: StarterNG-linux-x64
package: artifacts/StarterNG-linux-x64.tar.gz
runs-on: ${{ matrix.os }}
steps:
- name: Checkout repository
uses: actions/checkout@v7
- name: Setup .NET 9
uses: actions/setup-dotnet@v6
with:
dotnet-version: 9.0.x
# NativeAOT on Linux needs a native compiler/linker toolchain.
- name: Install NativeAOT dependencies
if: runner.os == 'Linux'
shell: bash
run: |
sudo apt-get update
sudo apt-get install -y clang zlib1g-dev
- name: Restore
run: >
dotnet restore
"${{ env.PROJECT_PATH }}"
-r "${{ matrix.rid }}"
- name: Publish NativeAOT
run: >
dotnet publish
"${{ env.PROJECT_PATH }}"
-c Release
-r "${{ matrix.rid }}"
--self-contained true
--no-restore
-p:PublishAot=true
-p:PublishTrimmed=true
-o "publish/${{ matrix.rid }}"
- name: Package Windows build
if: runner.os == 'Windows'
shell: pwsh
run: |
New-Item -ItemType Directory -Force -Path "artifacts" | Out-Null
Compress-Archive `
-Path "publish/${{ matrix.rid }}/*" `
-DestinationPath "${{ matrix.package }}"
- name: Package Linux build
if: runner.os == 'Linux'
shell: bash
run: |
mkdir -p artifacts
tar \
-C "publish/${{ matrix.rid }}" \
-czf "${{ matrix.package }}" \
.
- name: Upload artifact
uses: actions/upload-artifact@v7
with:
name: ${{ matrix.artifact }}
path: ${{ matrix.package }}
if-no-files-found: error
archive: false
# Workflow artifacts are only reachable for signed-in users with repository
# access, so every build of a release branch also lands in a rolling
# pre-release, whose assets anyone can download:
# https://github.com/${{ github.repository }}/releases/download/<tag>/<file>
# main -> "latest", staging -> "staging"; the two never overwrite each other.
release:
name: Rolling pre-release
needs: publish
if: github.event_name == 'push'
runs-on: ubuntu-latest
permissions:
contents: write
env:
RELEASE_TAG: ${{ github.ref_name == 'main' && 'latest' || 'staging' }}
RELEASE_NAME: ${{ github.ref_name == 'main' && 'Latest build' || 'Staging build' }}
steps:
- name: Collect the packages
uses: actions/download-artifact@v7
with:
path: dist
merge-multiple: true
# Recreated rather than edited, so the tag follows its branch and no asset
# from an older build is left behind.
- name: Replace the rolling pre-release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
set -euo pipefail
ls -l dist
gh release delete "$RELEASE_TAG" --repo "$GITHUB_REPOSITORY" --yes --cleanup-tag || true
gh release create "$RELEASE_TAG" dist/* \
--repo "$GITHUB_REPOSITORY" \
--target "$GITHUB_SHA" \
--prerelease \
--title "$RELEASE_NAME" \
--notes "Automatic build of $GITHUB_REF_NAME (${GITHUB_SHA::7}), $(date -u '+%Y-%m-%d %H:%M UTC')."