mirror of
https://github.com/apache/superset.git
synced 2026-08-04 04:52:32 +00:00
194 lines
6.8 KiB
YAML
194 lines
6.8 KiB
YAML
# This workflow automates the release process for Helm charts.
|
|
# Each run force-recreates a single 'helm-publish' branch from the tip of 'gh-pages' and
|
|
# opens (or reuses) one pull request against 'gh-pages', allowing the changes to be
|
|
# reviewed and merged manually. Because chart-releaser rebuilds index.yaml from all
|
|
# published GitHub releases, the branch always contains every chart released since the
|
|
# last merge, and the PR can never go stale or conflict with gh-pages.
|
|
|
|
name: "Helm: release charts"
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- "master"
|
|
- "[0-9].[0-9]*"
|
|
paths:
|
|
- "helm/**"
|
|
workflow_dispatch:
|
|
inputs:
|
|
ref:
|
|
description: "The branch, tag, or commit SHA to check out"
|
|
required: false
|
|
default: "master"
|
|
|
|
# Serialize runs: concurrent runs would race on force-pushing the shared
|
|
# helm-publish branch while chart-releaser is mid-release.
|
|
concurrency:
|
|
group: helm-release
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
release:
|
|
runs-on: ubuntu-26.04
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
ref: ${{ inputs.ref || github.ref_name }}
|
|
persist-credentials: true
|
|
submodules: recursive
|
|
fetch-depth: 0
|
|
|
|
- name: Configure Git
|
|
run: |
|
|
git config user.name "$GITHUB_ACTOR"
|
|
git config user.email "$GITHUB_ACTOR@users.noreply.github.com"
|
|
|
|
- name: Install Helm
|
|
uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
|
|
with:
|
|
version: v3.5.4
|
|
|
|
- name: Add bitnami repo dependency
|
|
run: helm repo add bitnami https://charts.bitnami.com/bitnami
|
|
|
|
- name: Fetch/list all tags
|
|
run: |
|
|
# Debugging tags
|
|
git fetch --tags --force
|
|
git tag -d superset-helm-chart-0.13.4 || true
|
|
echo "DEBUG TAGS"
|
|
git show-ref --tags
|
|
|
|
- name: Set pages branch name
|
|
id: vars
|
|
run: echo "branch_name=helm-publish" >> $GITHUB_ENV
|
|
|
|
- name: Force recreate branch from gh-pages
|
|
env:
|
|
BRANCH_NAME: ${{ env.branch_name }}
|
|
run: |
|
|
# Ensure a clean working directory
|
|
git reset --hard
|
|
git clean -fdx
|
|
git checkout -b local_gha_temp
|
|
git submodule update
|
|
|
|
# Fetch the latest gh-pages branch
|
|
git fetch origin gh-pages
|
|
|
|
# Check out and reset the target branch based on gh-pages
|
|
git checkout -B "$BRANCH_NAME" origin/gh-pages
|
|
|
|
# Remove submodules from the branch
|
|
git submodule deinit -f --all
|
|
|
|
# Force push to the remote branch
|
|
git push origin "$BRANCH_NAME" --force
|
|
|
|
# Return to the original branch
|
|
git checkout local_gha_temp
|
|
|
|
- name: Run chart-releaser
|
|
uses: helm/chart-releaser-action@cae68fefc6b5f367a0275617c9f83181ba54714f # v1.7.0
|
|
with:
|
|
version: v1.6.0
|
|
charts_dir: helm
|
|
mark_as_latest: false
|
|
# A helm/** change without a Chart.yaml version bump repackages the
|
|
# already-released version; without this, cr aborts on the existing
|
|
# release tag (422 already_exists) instead of proceeding to rebuild
|
|
# the index, and the whole run fails.
|
|
skip_existing: true
|
|
pages_branch: ${{ env.branch_name }}
|
|
env:
|
|
CR_TOKEN: "${{ github.token }}"
|
|
CR_RELEASE_NAME_TEMPLATE: "superset-helm-chart-{{ .Version }}"
|
|
|
|
- name: Open or reuse Pull Request
|
|
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
|
|
with:
|
|
script: |
|
|
const branchName = process.env.BRANCH_NAME;
|
|
const [owner, repo] = process.env.GITHUB_REPOSITORY.split('/');
|
|
|
|
if (!branchName) {
|
|
throw new Error("Branch name is not defined.");
|
|
}
|
|
|
|
// The branch is force-recreated from gh-pages on every run, so an
|
|
// already-open PR for it now reflects this run's charts; opening
|
|
// another would both fail (422) and recreate the stale-PR pileup
|
|
// this fixed branch exists to avoid.
|
|
const { data: existing } = await github.rest.pulls.list({
|
|
owner,
|
|
repo,
|
|
state: "open",
|
|
head: `${owner}:${branchName}`,
|
|
base: "gh-pages",
|
|
});
|
|
|
|
let current;
|
|
if (existing.length > 0) {
|
|
current = existing[0];
|
|
core.info(`Reusing existing pull request: ${current.html_url}`);
|
|
} else {
|
|
const { data: pr } = await github.rest.pulls.create({
|
|
owner,
|
|
repo,
|
|
title: "Helm chart release",
|
|
head: branchName,
|
|
base: "gh-pages", // Adjust if the target branch is different
|
|
body: [
|
|
"This PR releases Helm charts to the gh-pages branch.",
|
|
"",
|
|
"It is force-updated from the tip of `gh-pages` by every release run,",
|
|
"so it always contains every chart released since the last merge and",
|
|
"never needs to be closed as superseded.",
|
|
].join("\n"),
|
|
});
|
|
current = pr;
|
|
core.info(`Pull request created: ${current.html_url}`);
|
|
}
|
|
|
|
// Sweep release PRs left open by older runs (per-SHA helm-publish-*
|
|
// branches from the previous scheme). Their content is a subset of
|
|
// the evergreen PR, so close them with a pointer to it.
|
|
const { data: openPrs } = await github.rest.pulls.list({
|
|
owner,
|
|
repo,
|
|
state: "open",
|
|
base: "gh-pages",
|
|
per_page: 100,
|
|
});
|
|
|
|
for (const stale of openPrs) {
|
|
if (
|
|
stale.number !== current.number &&
|
|
stale.head.repo?.full_name === process.env.GITHUB_REPOSITORY &&
|
|
stale.head.ref.startsWith("helm-publish")
|
|
) {
|
|
await github.rest.issues.createComment({
|
|
owner,
|
|
repo,
|
|
issue_number: stale.number,
|
|
body: `Superseded by #${current.number}, which now carries all unreleased charts. Closing.`,
|
|
});
|
|
await github.rest.pulls.update({
|
|
owner,
|
|
repo,
|
|
pull_number: stale.number,
|
|
state: "closed",
|
|
});
|
|
core.info(`Closed superseded release PR #${stale.number}`);
|
|
}
|
|
}
|
|
env:
|
|
BRANCH_NAME: ${{ env.branch_name }}
|