CI: Build pre-release artifacts in GhA on merge to release branches and main. (#106779)
* Add grafana-build action and workflow * Fix the --verify flag stalling on tar.gz builds * Add event sources for main / release branches * Update CODEOWNERS
This commit is contained in:
@@ -763,6 +763,7 @@ embed.go @grafana/grafana-as-code
|
||||
/.github/renovate.json5 @grafana/frontend-ops
|
||||
/.github/actions/setup-enterprise/action.yml @grafana/grafana-backend-group
|
||||
/.github/actions/setup-grafana-bench/ @Proximyst
|
||||
/.github/actions/build-package @grafana/grafana-developer-enablement-squad
|
||||
/.github/workflows/actionlint-format.txt @grafana/grafana-developer-enablement-squad
|
||||
/.github/workflows/actionlint.yml @grafana/grafana-developer-enablement-squad
|
||||
/.github/workflows/add-to-whats-new.yml @grafana/docs-tooling
|
||||
@@ -831,6 +832,7 @@ embed.go @grafana/grafana-as-code
|
||||
/.github/workflows/trivy-scan.yml @grafana/grafana-backend-services-squad
|
||||
/.github/workflows/trufflehog.yml @Proximyst
|
||||
/.github/workflows/changelog.yml @zserge
|
||||
/.github/workflows/release-build.yml @grafana/grafana-developer-enablement-squad
|
||||
/.github/actions/changelog @zserge
|
||||
/.github/workflows/pr-frontend-unit-tests.yml @grafana/grafana-frontend-platform
|
||||
/.github/workflows/frontend-lint.yml @grafana/grafana-frontend-platform
|
||||
@@ -839,6 +841,7 @@ embed.go @grafana/grafana-as-code
|
||||
/.github/workflows/skye-add-to-project.yml @grafana/grafana-frontend-platform
|
||||
/.github/zizmor.yml @grafana/grafana-developer-enablement-squad
|
||||
/.github/license_finder.yaml @bergquist
|
||||
/.github/actionlint.yaml @grafana/grafana-developer-enablement-squad
|
||||
|
||||
# Generated files not requiring owner approval
|
||||
/packages/grafana-data/src/types/featureToggles.gen.ts @grafanabot
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
# These are just aliases to github-hosted runners
|
||||
self-hosted-runner:
|
||||
labels:
|
||||
- github-hosted-ubuntu-arm64
|
||||
- github-hosted-ubuntu-arm64-large
|
||||
- github-hosted-ubuntu-x64-small
|
||||
- github-hosted-ubuntu-x64-large
|
||||
- github-hosted-windows-x64-large
|
||||
@@ -0,0 +1,152 @@
|
||||
name: Build and Package Grafana Enterprise / Pro
|
||||
description: Creates Grafana artifacts using Dagger & `pkg/build/daggerbuild`
|
||||
inputs:
|
||||
artifacts:
|
||||
description: |
|
||||
Comma-delimited list of artifacts to build and package.
|
||||
Artifacts follow a specific format of `{package-type}:{grafana-edition}:{architecture}`.
|
||||
Not every combination of `package-type`, `grafana-edition`, and `architecture` are supported.
|
||||
Examples:
|
||||
* `grafana:linux/amd64:targz`, `grafana:linux/amd64:deb`
|
||||
* `enterprise:linux/arm64:rpm, enterprise:linux/amd64:docker`
|
||||
* `pro:docker:llinux/amd64`
|
||||
required: true
|
||||
type: string
|
||||
grafana-path:
|
||||
description: Path to a clone of the 'grafana' repo
|
||||
default: grafana
|
||||
type: string
|
||||
grafana-enterprise-path:
|
||||
description: Path to a clone of the 'grafana-enterprise' repo
|
||||
default: grafana-enterprise
|
||||
type: string
|
||||
github-token:
|
||||
type: string
|
||||
required: true
|
||||
version:
|
||||
type: string
|
||||
description: The version to embed in the grafana binary, example `v1.2.3`. If not provided, then the value in Grafana's package.json will be used
|
||||
required: true
|
||||
build-id:
|
||||
type: string
|
||||
description: an identifier number which can be traced back to the workflow run.
|
||||
default: ${{github.run_number}}
|
||||
required: false
|
||||
patches-repo:
|
||||
type: string
|
||||
description: Repository to load for patches repo. If empty, patches won't be applied. Must be an HTTPS git URL.
|
||||
required: false
|
||||
default: ""
|
||||
patches-ref:
|
||||
type: string
|
||||
description: git ref in the patches repo to check out.
|
||||
required: false
|
||||
default: main
|
||||
patches-path:
|
||||
type: string
|
||||
description: Path in the repository where `.patch` files can be found.
|
||||
required: false
|
||||
default: main
|
||||
checksum:
|
||||
type: boolean
|
||||
description: If true, then checksums will be produced for each file (with a '.sha256' extension)
|
||||
required: false
|
||||
default: false
|
||||
verify:
|
||||
type: boolean
|
||||
description: If true, then the e2e smoke tests will run to verify the produced artifacts (--verify)
|
||||
required: false
|
||||
default: false
|
||||
output:
|
||||
type: string
|
||||
description: Filename to redirect stdout to. Contains list of packages that were produced
|
||||
default: packages.txt
|
||||
required: false
|
||||
docker-tag-format:
|
||||
type: string
|
||||
default: "{{ .version }}-{{ .arch }}"
|
||||
description: Go template of Docker image tag
|
||||
required: false
|
||||
docker-tag-format-ubuntu:
|
||||
type: string
|
||||
default: "{{ .version }}-ubuntu-{{ .arch }}"
|
||||
description: Go template of Docker image tag
|
||||
required: false
|
||||
docker-org:
|
||||
type: string
|
||||
description: Docker org of produced images
|
||||
default: grafana
|
||||
required: false
|
||||
docker-registry:
|
||||
type: string
|
||||
description: Docker registry of produced images
|
||||
default: docker.io
|
||||
required: false
|
||||
ubuntu-base:
|
||||
type: string
|
||||
default: 'ubuntu:22.04'
|
||||
required: false
|
||||
alpine-base:
|
||||
type: string
|
||||
default: 'alpine:3.22'
|
||||
required: false
|
||||
outputs:
|
||||
dist-dir:
|
||||
description: Directory where artifacts are placed
|
||||
value: ${{ steps.output.outputs.dist_dir }}
|
||||
file:
|
||||
description: Path to file containing list of artifacts produced
|
||||
value: ${{ steps.output.outputs.file }}
|
||||
grafana-commit:
|
||||
description: Commit hash of the HEAD of the grafana repository used to build grafana.
|
||||
value: ${{ steps.output.outputs.grafana_commit }}
|
||||
enterprise-commit:
|
||||
description: Commit hash of the HEAD of the grafana-enterprise repository used to build grafana.
|
||||
value: ${{ steps.output.outputs.enterprise_commit }}
|
||||
version:
|
||||
description: The `grafana` version that was embedded in the binary
|
||||
value: ${{ steps.output.outputs.version }}
|
||||
runs:
|
||||
using: "composite"
|
||||
steps:
|
||||
- shell: bash
|
||||
run: | # zizmor: ignore[github-env]
|
||||
echo "GRAFANA_PATH=${{ github.workspace }}/${GRAFANA_DIR}" >> "$GITHUB_ENV"
|
||||
echo "ENTERPRISE_PATH=${{ github.workspace }}/${ENTERPRISE_DIR}" >> "$GITHUB_ENV"
|
||||
env:
|
||||
GB_PATH: ${{ inputs.path }}
|
||||
GRAFANA_DIR: ${{ inputs.grafana-path }}
|
||||
ENTERPRISE_DIR: ${{ inputs.enterprise-path }}
|
||||
- name: Build Grafana Enterprise packages
|
||||
uses: dagger/dagger-for-github@e47aba410ef9bb9ed81a4d2a97df31061e5e842e
|
||||
env:
|
||||
VERSION: ${{ inputs.version }}
|
||||
ARTIFACTS: ${{ inputs.artifacts }}
|
||||
GITHUB_TOKEN: ${{ inputs.github-token }}
|
||||
PATCHES_REPO: ${{ inputs.patches-repo }}
|
||||
PATCHES_REF: ${{ inputs.patches-ref }}
|
||||
PATCHES_PATH: ${{ inputs.patches-path }}
|
||||
BUILD_ID: ${{ inputs.build-id }}
|
||||
OUTFILE: ${{ inputs.output }}
|
||||
DOCKER_ORG: ${{ inputs.docker-org }}
|
||||
DOCKER_REGISTRY: ${{ inputs.docker-registry }}
|
||||
TAG_FORMAT: ${{ inputs.docker-tag-format }}
|
||||
UBUNTU_TAG_FORMAT: ${{ inputs.docker-tag-format-ubuntu }}
|
||||
CHECKSUM: ${{ inputs.checksum }}
|
||||
VERIFY: ${{ inputs.verify }}
|
||||
ALPINE_BASE: ${{ inputs.alpine-base }}
|
||||
UBUNTU_BASE: ${{ inputs.ubuntu-base }}
|
||||
with:
|
||||
verb: run
|
||||
dagger-flags: --verbose=0
|
||||
args: go run -C ${GRAFANA_PATH} ./pkg/build/cmd artifacts --artifacts ${ARTIFACTS} --grafana-dir=${GRAFANA_PATH} --alpine-base=${ALPINE_BASE} --ubuntu-base=${UBUNTU_BASE} --enterprise-dir=${ENTERPRISE_PATH} --version=${VERSION} --patches-repo=${PATCHES_REPO} --patches-ref=${PATCHES_REF} --patches-path=${PATCHES_PATH} --build-id=${BUILD_ID} --tag-format="${TAG_FORMAT}" --ubuntu-tag-format="${UBUNTU_TAG_FORMAT}" --org=${DOCKER_ORG} --registry=${DOCKER_REGISTRY} --checksum=${CHECKSUM} --verify=${VERIFY} > $OUTFILE
|
||||
- id: output
|
||||
shell: bash
|
||||
env:
|
||||
OUTFILE: ${{ inputs.output }}
|
||||
run: |
|
||||
echo "dist_dir=dist" | tee -a $GITHUB_OUTPUT
|
||||
echo "file=${OUTFILE}" | tee -a $GITHUB_OUTPUT
|
||||
echo "grafana_commit=$(git -C ${GRAFANA_PATH} rev-parse HEAD)" | tee -a $GITHUB_OUTPUT
|
||||
echo "enterprise_commit=$(git -C ${ENTERPRISE_PATH} rev-parse HEAD)" | tee -a $GITHUB_OUTPUT
|
||||
echo "version=$(cat ${GRAFANA_BUILD_PATH}/dist/VERSION)" | tee -a $GITHUB_OUTPUT
|
||||
@@ -116,7 +116,9 @@ jobs:
|
||||
service_account: github-junit-uploader@grafanalabs-workload-identity.iam.gserviceaccount.com
|
||||
bucket: grafana-test-results
|
||||
- if: github.repository == 'grafana/grafana' && (success() || failure())
|
||||
run: echo "BUCKET_PATH=go-unit-tests/$(echo ${REF_NAME} | sed 's/\//-/g')" >> "$GITHUB_ENV"
|
||||
run: |
|
||||
BUCKET_PATH="go-unit-tests/$(echo "${REF_NAME}" | sed 's/\//-/g')"
|
||||
echo "BUCKET_PATH=$BUCKET_PATH" >> "$GITHUB_ENV"
|
||||
env:
|
||||
REF_NAME: ${{ github.ref_name }}
|
||||
- name: Upload test results
|
||||
|
||||
@@ -0,0 +1,135 @@
|
||||
name: Build Release Packages
|
||||
on:
|
||||
workflow_dispatch:
|
||||
push:
|
||||
branches:
|
||||
- release-*.*.*
|
||||
- main
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
# Builds the following artifacts:
|
||||
#
|
||||
# npm:grafana
|
||||
# storybook
|
||||
# targz:grafana:linux/amd64
|
||||
# targz:grafana:linux/arm64
|
||||
# targz:grafana:linux/arm/v6
|
||||
# targz:grafana:linux/arm/v7
|
||||
# deb:grafana:linux/amd64
|
||||
# deb:grafana:linux/arm64
|
||||
# deb:grafana:linux/arm/v6
|
||||
# deb:grafana:linux/arm/v7
|
||||
# rpm:grafana:linux/amd64:sign
|
||||
# rpm:grafana:linux/arm64:sign
|
||||
# docker:grafana:linux/amd64
|
||||
# docker:grafana:linux/arm64
|
||||
# docker:grafana:linux/arm/v7
|
||||
# docker:grafana:linux/amd64:ubuntu
|
||||
# docker:grafana:linux/arm64:ubuntu
|
||||
# docker:grafana:linux/arm/v7:ubuntu
|
||||
# targz:grafana:windows/amd64
|
||||
# targz:grafana:windows/arm64
|
||||
# targz:grafana:darwin/amd64
|
||||
# targz:grafana:darwin/arm64
|
||||
# zip:grafana:windows/amd64
|
||||
# msi:grafana:windows/amd64
|
||||
jobs:
|
||||
setup:
|
||||
name: setup
|
||||
runs-on: github-hosted-ubuntu-x64-small
|
||||
outputs:
|
||||
version: ${{ steps.output.outputs.version }}
|
||||
permissions:
|
||||
contents: read
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Set up version (Release Branches)
|
||||
if: startsWith(github.ref_name, 'release-')
|
||||
run: echo "${REF_NAME#release-}" > VERSION
|
||||
env:
|
||||
REF_NAME: ${{ github.ref_name }}
|
||||
- name: Set up version (Non-release branches)
|
||||
if: ${{ !startsWith(github.ref_name, 'release-') }}
|
||||
run: jq -r .version package.json | sed -s "s/pre/${BUILD_ID}/g" > VERSION
|
||||
env:
|
||||
REF_NAME: ${{ github.ref_name }}
|
||||
BUILD_ID: ${{ github.run_number }}
|
||||
- id: output
|
||||
run: echo "version=$(cat VERSION)" >> "$GITHUB_OUTPUT"
|
||||
build:
|
||||
runs-on: github-hosted-ubuntu-x64-large
|
||||
needs: [setup]
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
name: ${{ needs.setup.outputs.version }} / ${{ matrix.name }}
|
||||
strategy:
|
||||
matrix:
|
||||
# The artifacts in these lists are grouped by their os+arch because the
|
||||
# build process can reuse the binaries for each artifact.
|
||||
# The downside to this is that the frontend will be built for each one when it could be reused for all of them.
|
||||
# This could be a future improvement.
|
||||
include:
|
||||
- name: linux-amd64
|
||||
artifacts: targz:grafana:linux/amd64,deb:grafana:linux/amd64,rpm:grafana:linux/amd64,docker:grafana:linux/amd64,docker:grafana:linux/amd64:ubuntu,npm:grafana,storybook
|
||||
- name: linux-arm64
|
||||
artifacts: targz:grafana:linux/arm64,deb:grafana:linux/arm64,rpm:grafana:linux/arm64,docker:grafana:linux/arm64,docker:grafana:linux/arm64:ubuntu
|
||||
- name: linux-s390x
|
||||
artifacts: targz:grafana:linux/s390x,deb:grafana:linux/s390x,rpm:grafana:linux/s390x,docker:grafana:linux/s390x,docker:grafana:linux/s390x:ubuntu
|
||||
- name: linux-armv7
|
||||
artifacts: targz:grafana:linux/arm/v7,deb:grafana:linux/arm/v7,docker:grafana:linux/arm/v7,docker:grafana:linux/arm/v7:ubuntu
|
||||
- name: linux-armv6
|
||||
artifacts: targz:grafana:linux/arm/v6,deb:grafana:linux/arm/v6
|
||||
- name: windows-amd64
|
||||
artifacts: targz:grafana:windows/amd64,zip:grafana:windows/amd64,msi:grafana:windows/amd64
|
||||
- name: windows-arm64
|
||||
artifacts: targz:grafana:windows/arm64,zip:grafana:windows/arm64
|
||||
- name: darwin-amd64
|
||||
artifacts: targz:grafana:darwin/amd64
|
||||
- name: darwin-arm64
|
||||
artifacts: targz:grafana:darwin/arm64
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392
|
||||
- uses: ./.github/actions/build-package
|
||||
id: build
|
||||
with:
|
||||
artifacts: ${{ matrix.artifacts }}
|
||||
checksum: true
|
||||
grafana-path: .
|
||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
||||
version: ${{ needs.setup.outputs.version }}
|
||||
output: artifacts-${{ matrix.name }}.txt
|
||||
verify: true
|
||||
build-id: ${{ github.run_number }}
|
||||
- name: Log in to GCS
|
||||
id: login-to-gcs
|
||||
uses: grafana/shared-workflows/actions/login-to-gcs@login-to-gcs/v0.2.1
|
||||
with:
|
||||
environment: prod
|
||||
- name: Upload artifacts
|
||||
uses: grafana/shared-workflows/actions/push-to-gcs@push-to-gcs-v0.2.0
|
||||
with:
|
||||
bucket: ${{ steps.login-to-gcs.outputs.bucket }}
|
||||
environment: prod
|
||||
parent: false
|
||||
path: ${{ steps.build.outputs.dist-dir }}
|
||||
bucket_path: ${{ needs.setup.outputs.version }}
|
||||
- name: Upload manifest
|
||||
uses: grafana/shared-workflows/actions/push-to-gcs@push-to-gcs-v0.2.0
|
||||
with:
|
||||
bucket: ${{ steps.login-to-gcs.outputs.bucket }}
|
||||
environment: prod
|
||||
path: ${{ steps.build.outputs.file }}
|
||||
bucket_path: ${{ needs.setup.outputs.version }}
|
||||
Reference in New Issue
Block a user