When running in snapshot mode, the signing step skips cosign but does not create the expected .bundle file. The checksum step then fails because it cannot find the signature artifact. Touch the file so the pipeline can continue. Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
232 lines
4.9 KiB
YAML
232 lines
4.9 KiB
YAML
# yaml-language-server: $schema=https://goreleaser.com/static/schema.json
|
|
version: 2
|
|
|
|
project_name: probod
|
|
|
|
before:
|
|
hooks:
|
|
- make generate @probo/emails @probo/console @probo/trust
|
|
|
|
builds:
|
|
- id: probod
|
|
main: ./cmd/probod/main.go
|
|
binary: probod
|
|
ldflags:
|
|
- -s -w
|
|
- -X 'main.version={{.Version}}'
|
|
- -X 'main.env=prod'
|
|
gcflags:
|
|
- -e
|
|
env:
|
|
- CGO_ENABLED=0
|
|
goos:
|
|
- windows
|
|
- darwin
|
|
- freebsd
|
|
- openbsd
|
|
goarch:
|
|
- amd64
|
|
- arm64
|
|
ignore:
|
|
- goos: windows
|
|
goarch: arm64
|
|
- id: probod-bootstrap
|
|
main: ./cmd/probod-bootstrap/main.go
|
|
binary: probod-bootstrap
|
|
ldflags:
|
|
- -s -w
|
|
gcflags:
|
|
- -e
|
|
env:
|
|
- CGO_ENABLED=0
|
|
goos:
|
|
- windows
|
|
- darwin
|
|
- freebsd
|
|
- openbsd
|
|
goarch:
|
|
- amd64
|
|
- arm64
|
|
ignore:
|
|
- goos: windows
|
|
goarch: arm64
|
|
# Docker-specific builds for Linux only
|
|
- id: probod-docker
|
|
main: ./cmd/probod/main.go
|
|
binary: probod
|
|
ldflags:
|
|
- -s -w
|
|
- -X 'main.version={{.Version}}'
|
|
- -X 'main.env=prod'
|
|
gcflags:
|
|
- -e
|
|
env:
|
|
- CGO_ENABLED=0
|
|
goos:
|
|
- linux
|
|
goarch:
|
|
- amd64
|
|
- arm64
|
|
- id: probod-bootstrap-docker
|
|
main: ./cmd/probod-bootstrap/main.go
|
|
binary: probod-bootstrap
|
|
ldflags:
|
|
- -s -w
|
|
gcflags:
|
|
- -e
|
|
env:
|
|
- CGO_ENABLED=0
|
|
goos:
|
|
- linux
|
|
goarch:
|
|
- amd64
|
|
- arm64
|
|
- id: prb-docker
|
|
main: ./cmd/prb/main.go
|
|
binary: prb
|
|
ldflags:
|
|
- -s -w
|
|
- -X 'main.version={{.Version}}'
|
|
gcflags:
|
|
- -e
|
|
env:
|
|
- CGO_ENABLED=0
|
|
goos:
|
|
- linux
|
|
goarch:
|
|
- amd64
|
|
- arm64
|
|
|
|
archives:
|
|
- id: probod
|
|
builds:
|
|
- probod
|
|
- probod-bootstrap
|
|
- prb
|
|
name_template: >-
|
|
{{ .ProjectName }}_
|
|
{{- title .Os }}_
|
|
{{- if eq .Arch "amd64" }}x86_64
|
|
{{- else if eq .Arch "386" }}i386
|
|
{{- else }}{{ .Arch }}{{ end }}
|
|
{{- if .Arm }}v{{ .Arm }}{{ end }}
|
|
files:
|
|
- README.md
|
|
- LICENSE
|
|
- CHANGELOG.md
|
|
- id: prb
|
|
builds:
|
|
- prb
|
|
name_template: >-
|
|
prb_
|
|
{{- title .Os }}_
|
|
{{- if eq .Arch "amd64" }}x86_64
|
|
{{- else if eq .Arch "386" }}i386
|
|
{{- else }}{{ .Arch }}{{ end }}
|
|
{{- if .Arm }}v{{ .Arm }}{{ end }}
|
|
files:
|
|
- README.md
|
|
- LICENSE
|
|
- CHANGELOG.md
|
|
|
|
checksum:
|
|
name_template: "checksums.txt"
|
|
|
|
signs:
|
|
- cmd: sh
|
|
env:
|
|
- COSIGN_EXPERIMENTAL=1
|
|
signature: "${artifact}.bundle"
|
|
args:
|
|
- -c
|
|
- |
|
|
if [ "{{ .IsSnapshot }}" = "true" ]; then
|
|
echo "Skipping signing (snapshot: {{ .IsSnapshot }})"
|
|
touch "${signature}"
|
|
else
|
|
cosign sign-blob --bundle="${signature}" "${artifact}" --yes
|
|
fi
|
|
artifacts: checksum
|
|
output: true
|
|
|
|
dockers_v2:
|
|
- images:
|
|
- "ghcr.io/getprobo/probo"
|
|
tags:
|
|
- "{{ .Tag }}"
|
|
- latest
|
|
dockerfile: Dockerfile
|
|
ids:
|
|
- probod-docker
|
|
- probod-bootstrap-docker
|
|
extra_files:
|
|
- entrypoint.sh
|
|
labels:
|
|
"org.opencontainers.image.title": "{{.ProjectName}}"
|
|
"org.opencontainers.image.description": "Probo compliance management platform"
|
|
"org.opencontainers.image.url": "https://github.com/getprobo/probo"
|
|
"org.opencontainers.image.source": "https://github.com/getprobo/probo"
|
|
"org.opencontainers.image.version": "{{.Version}}"
|
|
"org.opencontainers.image.created": '{{time "2006-01-02T15:04:05Z07:00"}}'
|
|
"org.opencontainers.image.revision": "{{.FullCommit}}"
|
|
"org.opencontainers.image.licenses": "MIT"
|
|
platforms:
|
|
- linux/amd64
|
|
- linux/arm64
|
|
|
|
docker_signs:
|
|
- id: images
|
|
cmd: sh
|
|
env:
|
|
- COSIGN_EXPERIMENTAL=1
|
|
artifacts: images
|
|
output: true
|
|
args:
|
|
- -c
|
|
- |
|
|
if [ "{{ .IsSnapshot }}" = "true" ]; then
|
|
echo "Skipping Docker image signing (snapshot: {{ .IsSnapshot }})"
|
|
else
|
|
cosign sign "${artifact}@${digest}" --yes
|
|
fi
|
|
- id: manifests
|
|
cmd: sh
|
|
env:
|
|
- COSIGN_EXPERIMENTAL=1
|
|
artifacts: manifests
|
|
output: true
|
|
args:
|
|
- -c
|
|
- |
|
|
if [ "{{ .IsSnapshot }}" = "true" ]; then
|
|
echo "Skipping Docker manifest signing (snapshot: {{ .IsSnapshot }})"
|
|
else
|
|
cosign sign "${artifact}@${digest}" --yes
|
|
fi
|
|
|
|
changelog:
|
|
sort: asc
|
|
filters:
|
|
exclude:
|
|
- "^docs:"
|
|
- "^test:"
|
|
- "^chore:"
|
|
- "^style:"
|
|
- "^refactor:"
|
|
- "^ci:"
|
|
- "^build:"
|
|
- Merge pull request
|
|
- Merge branch
|
|
- go mod tidy
|
|
|
|
release:
|
|
draft: false
|
|
prerelease: auto
|
|
mode: replace
|
|
header: |
|
|
## Changes in {{ .Tag }}
|
|
footer: |
|
|
## Docker Images
|
|
- `ghcr.io/getprobo/probo:{{ .Tag }}` (multi-arch: linux/amd64, linux/arm64)
|
|
- `ghcr.io/getprobo/probo:latest` (multi-arch: linux/amd64, linux/arm64)
|