From d94d0c02c95ef5bb8aec1c1795a7785c3286a65f Mon Sep 17 00:00:00 2001 From: Artem Bilan Date: Mon, 23 Oct 2023 14:56:03 -0400 Subject: [PATCH] Extract reusable GHA workflows --- .github/release-files-spec.json | 2 +- .github/workflows/ci-snapshot.yml | 44 +--------- .github/workflows/pr-build.yml | 33 +------- .github/workflows/promote-ga-to-central.yml | 47 ++--------- .github/workflows/promote-milestone.yml | 20 ++--- .github/workflows/release-staging.yml | 66 ++------------- ...ing-artifactory-gradle-release-staging.yml | 82 +++++++++++++++++++ .../spring-artifactory-gradle-snapshot.yml | 52 ++++++++++++ .../spring-artifactory-promote-central.yml | 56 +++++++++++++ .../spring-artifactory-promote-milestone.yml | 29 +++++++ .../spring-gradle-pull-request-build.yml | 36 ++++++++ 11 files changed, 278 insertions(+), 189 deletions(-) create mode 100644 .github/workflows/spring-artifactory-gradle-release-staging.yml create mode 100644 .github/workflows/spring-artifactory-gradle-snapshot.yml create mode 100644 .github/workflows/spring-artifactory-promote-central.yml create mode 100644 .github/workflows/spring-artifactory-promote-milestone.yml create mode 100644 .github/workflows/spring-gradle-pull-request-build.yml diff --git a/.github/release-files-spec.json b/.github/release-files-spec.json index ee43685..c00e2f9 100644 --- a/.github/release-files-spec.json +++ b/.github/release-files-spec.json @@ -7,7 +7,7 @@ { "@build.name": "${buildname}", "@build.number": "${buildnumber}", - "path": {"$match": "org*"} + "path": {"$match": "org.springframework*"} }, { "$or": [ diff --git a/.github/workflows/ci-snapshot.yml b/.github/workflows/ci-snapshot.yml index 4f885b2..8a20704 100644 --- a/.github/workflows/ci-snapshot.yml +++ b/.github/workflows/ci-snapshot.yml @@ -2,51 +2,11 @@ name: CI SNAPSHOT on: workflow_dispatch: - workflow_call: push: branches: - main -env: - GRADLE_ENTERPRISE_CACHE_USERNAME: ${{ secrets.GRADLE_ENTERPRISE_CACHE_USER }} - GRADLE_ENTERPRISE_CACHE_PASSWORD: ${{ secrets.GRADLE_ENTERPRISE_CACHE_PASSWORD }} - GRADLE_ENTERPRISE_ACCESS_KEY: ${{ secrets.GRADLE_ENTERPRISE_SECRET_ACCESS_KEY }} - jobs: build_snapshot: - runs-on: ubuntu-latest - if: github.repository_owner == 'spring-projects' - name: CI Build SNAPSHOT for ${{ github.ref_name }} - steps: - - - uses: actions/checkout@v3 - with: - token: ${{ secrets.GH_ACTIONS_REPO_TOKEN }} - - - name: Set up Gradle - uses: spring-io/spring-gradle-build-action@v2 - - - uses: jfrog/setup-jfrog-cli@v3 - with: - version: 2.50.2 - env: - JF_ENV_SPRING: ${{ secrets.JF_ARTIFACTORY_SPRING }} - - - name: Configure JFrog Cli - run: | - jf gradlec \ - --use-wrapper \ - --uses-plugin \ - --deploy-ivy-desc=false \ - --server-id-resolve repo.spring.io \ - --server-id-deploy repo.spring.io \ - --repo-resolve snapshot \ - --repo-deploy libs-snapshot-local - echo JFROG_CLI_BUILD_NAME=${{ github.event.repository.name }}-${{ github.ref_name }} >> $GITHUB_ENV - echo JFROG_CLI_BUILD_NUMBER=$GITHUB_RUN_NUMBER >> $GITHUB_ENV - - - name: Build and Publish - run: | - jf gradle build dist artifactoryPublish - jf rt build-publish - + uses: .github/workflows/spring-artifactory-gradle-snapshot.yml + secrets: inherit \ No newline at end of file diff --git a/.github/workflows/pr-build.yml b/.github/workflows/pr-build.yml index d17c6d8..c24951b 100644 --- a/.github/workflows/pr-build.yml +++ b/.github/workflows/pr-build.yml @@ -2,36 +2,9 @@ name: Pull Request Build on: pull_request: - branches: [ main ] + branches: + - main jobs: build: - - runs-on: ubuntu-latest - - steps: - - - uses: actions/checkout@v3 - - - name: Set up JDK - uses: actions/setup-java@v3 - with: - distribution: adopt - java-version: 17 - cache: gradle - - - name: Run Gradle - uses: burrunan/gradle-cache-action@v1 - with: - debug: false - concurrent: true - gradle-build-scan-report: false - arguments: check - - - name: Capture Test Results - if: failure() - uses: actions/upload-artifact@v3 - with: - name: test-results - path: '*/build/reports/tests/**/*.*' - retention-days: 3 + uses: .github/workflows/spring-gradle-pull-request-build.yml diff --git a/.github/workflows/promote-ga-to-central.yml b/.github/workflows/promote-ga-to-central.yml index fa1321b..e1a44c7 100644 --- a/.github/workflows/promote-ga-to-central.yml +++ b/.github/workflows/promote-ga-to-central.yml @@ -12,45 +12,8 @@ on: jobs: release_to_central: - runs-on: ubuntu-latest - if: github.repository_owner == 'spring-projects' - steps: - - - uses: actions/checkout@v3 - with: - token: ${{ secrets.GH_ACTIONS_REPO_TOKEN }} - - - uses: jfrog/setup-jfrog-cli@v3 - with: - version: 2.50.2 - env: - JF_ENV_SPRING: ${{ secrets.JF_ARTIFACTORY_SPRING }} - - - name: Promote Build - run: | - jfrog rt build-promote ${{ inputs.buildName }} ${{ inputs.buildNumber }} libs-release-local - - # Download released files - - name: Download Release Files - run: | - jfrog rt download \ - --spec .github/release-files-spec.json \ - --spec-vars "buildname=${{ inputs.buildName }};buildnumber=${{ inputs.buildNumber }}" - - # Create checksums, signatures and create staging repo on central and upload - - uses: jvalkeal/nexus-sync@v0.0.2 - id: nexus - with: - url: ${{ secrets.OSSRH_URL }} - username: ${{ secrets.OSSRH_S01_TOKEN_USERNAME }} - password: ${{ secrets.OSSRH_S01_TOKEN_PASSWORD }} - staging-profile-name: ${{ secrets.OSSRH_STAGING_PROFILE_NAME }} - create: true - upload: true - generate-checksums: true - pgp-sign: true - upload-parallel: 10 - pgp-sign-passphrase: ${{ secrets.GPG_PASSPHRASE }} - pgp-sign-private-key: ${{ secrets.GPG_PRIVATE_KEY }} - close: true - release: true \ No newline at end of file + uses: .github/workflows/spring-artifactory-promote-central.yml + with: + buildName: ${{ inputs.buildName }} + buildNumber: ${{ inputs.buildNumber }} + secrets: inherit \ No newline at end of file diff --git a/.github/workflows/promote-milestone.yml b/.github/workflows/promote-milestone.yml index 47c278e..3eeca74 100644 --- a/.github/workflows/promote-milestone.yml +++ b/.github/workflows/promote-milestone.yml @@ -6,22 +6,16 @@ on: buildName: description: 'The Artifactory Build Name' required: true + type: string buildNumber: description: 'The Artifactory Build' required: true + type: number jobs: promote_milestone: - runs-on: ubuntu-latest - if: github.repository_owner == 'spring-projects' - steps: - - - uses: jfrog/setup-jfrog-cli@v3 - with: - version: 2.50.2 - env: - JF_ENV_SPRING: ${{ secrets.JF_ARTIFACTORY_SPRING }} - - - name: Promote Build - run: | - jfrog rt build-promote ${{ inputs.buildName }} ${{ inputs.buildNumber }} libs-milestone-local \ No newline at end of file + uses: .github/workflows/spring-artifactory-promote-milestone.yml + with: + buildName: ${{ inputs.buildName }} + buildNumber: ${{ inputs.buildNumber }} + secrets: inherit \ No newline at end of file diff --git a/.github/workflows/release-staging.yml b/.github/workflows/release-staging.yml index 260a23b..8388145 100644 --- a/.github/workflows/release-staging.yml +++ b/.github/workflows/release-staging.yml @@ -10,66 +10,10 @@ on: description: 'Next development version like 3.1.1-SNAPSHOT' required: true -run-name: Release version ${{ inputs.releaseVersion }} - -env: - GRADLE_ENTERPRISE_CACHE_USERNAME: ${{ secrets.GRADLE_ENTERPRISE_CACHE_USER }} - GRADLE_ENTERPRISE_CACHE_PASSWORD: ${{ secrets.GRADLE_ENTERPRISE_CACHE_PASSWORD }} - GRADLE_ENTERPRISE_ACCESS_KEY: ${{ secrets.GRADLE_ENTERPRISE_SECRET_ACCESS_KEY }} - jobs: staging: - runs-on: ubuntu-latest - if: github.repository_owner == 'spring-projects' - steps: - - - uses: actions/checkout@v3 - with: - token: ${{ secrets.GH_ACTIONS_REPO_TOKEN }} - - - name: Set up Gradle - uses: spring-io/spring-gradle-build-action@v2 - - - uses: jfrog/setup-jfrog-cli@v3 - with: - version: 2.50.2 - env: - JF_ENV_SPRING: ${{ secrets.JF_ARTIFACTORY_SPRING }} - - - name: Configure JFrog Cli - run: | - jf gradlec \ - --use-wrapper \ - --uses-plugin \ - --deploy-ivy-desc=false \ - --server-id-resolve repo.spring.io \ - --server-id-deploy repo.spring.io \ - --repo-resolve ${{ (contains(inputs.releaseVersion, 'M') || contains(inputs.releaseVersion, 'RC')) && 'milestone' || 'release' }} \ - --repo-deploy libs-staging-local - echo JFROG_CLI_BUILD_NAME=${{ github.event.repository.name }}-${{ inputs.releaseVersion }} >> $GITHUB_ENV - echo JFROG_CLI_BUILD_NUMBER=$GITHUB_RUN_NUMBER >> $GITHUB_ENV - - - name: Set Release Version - run: | - sed -i "s/version=.*/version=${{ inputs.releaseVersion }}/" gradle.properties - - - name: Build and Publish - run: | - jf gradle build dist artifactoryPublish - jf rt build-publish - - - name: Tag Release and Next Development Version - run: | - git config --global user.name 'Spring Builds' - git config --global user.email 'builds@springframework.org' - git commit -a -m "[artifactory-release] Release version ${{ inputs.releaseVersion }}" - git tag "v${{ inputs.releaseVersion }}" - git push --tags origin - sed -i "s/version=.*/version=${{ inputs.nextDevelopmentVersion }}/" gradle.properties - git commit -a -m "[artifactory-release] Next development version" - git push origin - - - name: Print Build Info - run: | - echo "::notice ::Artifactory Build Name=$JFROG_CLI_BUILD_NAME" - echo "::notice ::Artifactory Build Number=$JFROG_CLI_BUILD_NUMBER" \ No newline at end of file + uses: .github/workflows/spring-artifactory-gradle-release-staging.yml + with: + releaseVersion: ${{ inputs.releaseVersion }} + nextDevelopmentVersion: ${{ inputs.nextDevelopmentVersion }} + secrets: inherit \ No newline at end of file diff --git a/.github/workflows/spring-artifactory-gradle-release-staging.yml b/.github/workflows/spring-artifactory-gradle-release-staging.yml new file mode 100644 index 0000000..9ce2e1e --- /dev/null +++ b/.github/workflows/spring-artifactory-gradle-release-staging.yml @@ -0,0 +1,82 @@ +name: Build with Gradle and Stage Release to Artifactory + +on: + workflow_call: + inputs: + releaseVersion: + description: 'Release version like 3.0.0-M1, 3.1.0-RC1, 3.2.0 etc' + required: true + type: string + nextDevelopmentVersion: + description: 'Next development version like 3.1.1-SNAPSHOT' + required: true + type: string + gradleTasks: + description: 'Additional Gradle tasks. The `build` and `artifactoryPublish` are included.' + required: false + default: 'dist' + type: string + +run-name: Release version ${{ inputs.releaseVersion }} + +env: + GRADLE_ENTERPRISE_CACHE_USERNAME: ${{ secrets.GRADLE_ENTERPRISE_CACHE_USER }} + GRADLE_ENTERPRISE_CACHE_PASSWORD: ${{ secrets.GRADLE_ENTERPRISE_CACHE_PASSWORD }} + GRADLE_ENTERPRISE_ACCESS_KEY: ${{ secrets.GRADLE_ENTERPRISE_SECRET_ACCESS_KEY }} + +jobs: + staging: + runs-on: ubuntu-latest + if: github.repository_owner == 'spring-projects' + steps: + + - uses: actions/checkout@v3 + with: + token: ${{ secrets.GH_ACTIONS_REPO_TOKEN }} + + - name: Set up Gradle + uses: spring-io/spring-gradle-build-action@v2 + + - uses: jfrog/setup-jfrog-cli@v3 + with: + version: 2.50.4 + env: + JF_ENV_SPRING: ${{ secrets.JF_ARTIFACTORY_SPRING }} + + - name: Configure JFrog Cli + run: | + jf gradlec \ + --use-wrapper \ + --uses-plugin \ + --deploy-ivy-desc=false \ + --server-id-resolve repo.spring.io \ + --server-id-deploy repo.spring.io \ + --repo-resolve ${{ (contains(inputs.releaseVersion, 'M') || contains(inputs.releaseVersion, 'RC')) && 'milestone' || 'release' }} \ + --repo-deploy libs-staging-local + echo JFROG_CLI_BUILD_NAME=${{ github.event.repository.name }}-${{ inputs.releaseVersion }} >> $GITHUB_ENV + echo JFROG_CLI_BUILD_NUMBER=$GITHUB_RUN_NUMBER >> $GITHUB_ENV + + - name: Set Release Version + run: | + sed -i "s/version=.*/version=${{ inputs.releaseVersion }}/" gradle.properties + + - name: Build and Publish + run: | + jf gradle build ${{ inputs.gradleTasks }} artifactoryPublish + jf rt build-publish + + - name: Tag Release and Next Development Version + run: | + git config --global user.name 'Spring Builds' + git config --global user.email 'builds@springframework.org' + git commit -a -m "[artifactory-release] Release version ${{ inputs.releaseVersion }}" + git tag "v${{ inputs.releaseVersion }}" + git push --tags origin + sed -i "s/version=.*/version=${{ inputs.nextDevelopmentVersion }}/" gradle.properties + git commit -a -m "[artifactory-release] Next development version" + git push origin + + - name: Print Build Info + run: | + echo "::notice ::Artifactory Build Name=$JFROG_CLI_BUILD_NAME" + echo "::notice ::Artifactory Build Number=$JFROG_CLI_BUILD_NUMBER" \ No newline at end of file diff --git a/.github/workflows/spring-artifactory-gradle-snapshot.yml b/.github/workflows/spring-artifactory-gradle-snapshot.yml new file mode 100644 index 0000000..969f9e1 --- /dev/null +++ b/.github/workflows/spring-artifactory-gradle-snapshot.yml @@ -0,0 +1,52 @@ +name: CI Artifactory SNAPSHOT Build for Gradle + +on: + workflow_call: + inputs: + gradleTasks: + description: 'Additional Gradle tasks. The `build` and `artifactoryPublish` are included.' + required: false + default: 'dist' + type: string + +env: + GRADLE_ENTERPRISE_CACHE_USERNAME: ${{ secrets.GRADLE_ENTERPRISE_CACHE_USER }} + GRADLE_ENTERPRISE_CACHE_PASSWORD: ${{ secrets.GRADLE_ENTERPRISE_CACHE_PASSWORD }} + GRADLE_ENTERPRISE_ACCESS_KEY: ${{ secrets.GRADLE_ENTERPRISE_SECRET_ACCESS_KEY }} + +jobs: + build_snapshot: + runs-on: ubuntu-latest + if: github.repository_owner == 'spring-projects' + name: CI Build SNAPSHOT for ${{ github.ref_name }} + steps: + + - uses: actions/checkout@v3 + + - name: Set up Gradle + uses: spring-io/spring-gradle-build-action@v2 + + - uses: jfrog/setup-jfrog-cli@v3 + with: + version: 2.50.4 + env: + JF_ENV_SPRING: ${{ secrets.JF_ARTIFACTORY_SPRING }} + + - name: Configure JFrog Cli + run: | + jf gradlec \ + --use-wrapper \ + --uses-plugin \ + --deploy-ivy-desc=false \ + --server-id-resolve repo.spring.io \ + --server-id-deploy repo.spring.io \ + --repo-resolve snapshot \ + --repo-deploy libs-snapshot-local + echo JFROG_CLI_BUILD_NAME=${{ github.event.repository.name }}-${{ github.ref_name }} >> $GITHUB_ENV + echo JFROG_CLI_BUILD_NUMBER=$GITHUB_RUN_NUMBER >> $GITHUB_ENV + + - name: Build and Publish + run: | + jf gradle build ${{ inputs.gradleTasks }} artifactoryPublish + jf rt build-publish + diff --git a/.github/workflows/spring-artifactory-promote-central.yml b/.github/workflows/spring-artifactory-promote-central.yml new file mode 100644 index 0000000..5aa15a7 --- /dev/null +++ b/.github/workflows/spring-artifactory-promote-central.yml @@ -0,0 +1,56 @@ +name: Promote Staged GA release from Artifactory to Maven Central + +on: + workflow_call: + inputs: + buildName: + description: 'The Artifactory Build Name' + required: true + type: string + buildNumber: + description: 'The Artifactory Build' + required: true + type: number + +jobs: + release_to_central: + runs-on: ubuntu-latest + if: github.repository_owner == 'spring-projects' + steps: + + - uses: actions/checkout@v3 + + - uses: jfrog/setup-jfrog-cli@v3 + with: + version: 2.50.4 + env: + JF_ENV_SPRING: ${{ secrets.JF_ARTIFACTORY_SPRING }} + + - name: Promote Build + run: | + jfrog rt build-promote ${{ inputs.buildName }} ${{ inputs.buildNumber }} libs-release-local + + # Download released files + - name: Download Release Files + run: | + jfrog rt download \ + --spec .github/release-files-spec.json \ + --spec-vars "buildname=${{ inputs.buildName }};buildnumber=${{ inputs.buildNumber }}" + + # Create checksums, signatures and create staging repo on central and upload + - uses: jvalkeal/nexus-sync@v0.0.2 + id: nexus + with: + url: ${{ secrets.OSSRH_URL }} + username: ${{ secrets.OSSRH_S01_TOKEN_USERNAME }} + password: ${{ secrets.OSSRH_S01_TOKEN_PASSWORD }} + staging-profile-name: ${{ secrets.OSSRH_STAGING_PROFILE_NAME }} + create: true + upload: true + generate-checksums: true + pgp-sign: true + upload-parallel: 10 + pgp-sign-passphrase: ${{ secrets.GPG_PASSPHRASE }} + pgp-sign-private-key: ${{ secrets.GPG_PRIVATE_KEY }} + close: true + release: true \ No newline at end of file diff --git a/.github/workflows/spring-artifactory-promote-milestone.yml b/.github/workflows/spring-artifactory-promote-milestone.yml new file mode 100644 index 0000000..a318806 --- /dev/null +++ b/.github/workflows/spring-artifactory-promote-milestone.yml @@ -0,0 +1,29 @@ +name: Promote Staged Milestone in Artifactory + +on: + workflow_call: + inputs: + buildName: + description: 'The Artifactory Build Name' + required: true + type: string + buildNumber: + description: 'The Artifactory Build' + required: true + type: number + +jobs: + promote_milestone: + runs-on: ubuntu-latest + if: github.repository_owner == 'spring-projects' + steps: + + - uses: jfrog/setup-jfrog-cli@v3 + with: + version: 2.50.4 + env: + JF_ENV_SPRING: ${{ secrets.JF_ARTIFACTORY_SPRING }} + + - name: Promote Build + run: | + jfrog rt build-promote ${{ inputs.buildName }} ${{ inputs.buildNumber }} libs-milestone-local \ No newline at end of file diff --git a/.github/workflows/spring-gradle-pull-request-build.yml b/.github/workflows/spring-gradle-pull-request-build.yml new file mode 100644 index 0000000..0e821dc --- /dev/null +++ b/.github/workflows/spring-gradle-pull-request-build.yml @@ -0,0 +1,36 @@ +name: Pull Request Build with Gradle + +on: + workflow_call: + +jobs: + build: + + runs-on: ubuntu-latest + + steps: + + - uses: actions/checkout@v3 + + - name: Set up JDK + uses: actions/setup-java@v3 + with: + distribution: adopt + java-version: 17 + cache: gradle + + - name: Run Gradle + uses: burrunan/gradle-cache-action@v1 + with: + debug: false + concurrent: true + gradle-build-scan-report: false + arguments: check + + - name: Capture Test Results + if: failure() + uses: actions/upload-artifact@v3 + with: + name: test-results + path: '*/build/reports/tests/**/*.*' + retention-days: 3