Skip to content

Commit 8316cb0

Browse files
committed
ci: split release preparation and publishing
Signed-off-by: Karthik Bekal Pattathana <133984042+karthikbekalp@users.noreply.github.com>
1 parent 5b6db61 commit 8316cb0

2 files changed

Lines changed: 222 additions & 117 deletions

File tree

Lines changed: 105 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,105 @@
1+
name: "Release: Prepare"
2+
run-name: "Release: Prepare ${{ github.event.head_commit.message || inputs.tag }}"
3+
4+
on:
5+
push:
6+
branches:
7+
- mainline
8+
paths:
9+
- CHANGELOG.md
10+
workflow_dispatch:
11+
inputs:
12+
tag:
13+
required: true
14+
type: string
15+
description: Specify a tag to re-run a release.
16+
17+
concurrency:
18+
group: release
19+
20+
permissions:
21+
contents: read
22+
23+
jobs:
24+
TagRelease:
25+
if: >-
26+
github.repository == 'aws-deadline/deadline-cloud-for-cinema-4d' &&
27+
github.ref == 'refs/heads/mainline'
28+
uses: aws-deadline/.github/.github/workflows/reusable_tag_release.yml@mainline
29+
secrets: inherit
30+
with:
31+
tag: ${{ github.event_name == 'workflow_dispatch' && inputs.tag || '' }}
32+
33+
UnitTests:
34+
needs: [TagRelease]
35+
name: Unit Tests
36+
uses: ./.github/workflows/code_quality.yml
37+
with:
38+
tag: ${{ needs.TagRelease.outputs.tag }}
39+
40+
Xa11yWindows:
41+
needs: [TagRelease, UnitTests]
42+
name: xa11y Integration Tests (Windows, Cinema 4D ${{ matrix.c4d_version }})
43+
strategy:
44+
fail-fast: false
45+
matrix:
46+
c4d_version: ["2024", "2025", "2026"]
47+
uses: ./.github/workflows/integ_windows.yml
48+
with:
49+
c4d_version: ${{ matrix.c4d_version }}
50+
secrets:
51+
AWS_OIDC_ROLE_ARN: ${{ secrets.AWS_OIDC_ROLE_ARN }}
52+
AWS_REGION: ${{ secrets.AWS_REGION }}
53+
RLM_PORT: ${{ secrets.RLM_PORT }}
54+
INSTALLER_BUCKET: ${{ secrets.INSTALLER_BUCKET }}
55+
INSTALLER_BUCKET_EXPECTED_OWNER: ${{ secrets.INSTALLER_BUCKET_EXPECTED_OWNER }}
56+
LICENSE_ROLE_ARN: ${{ secrets.LICENSE_ROLE_ARN }}
57+
BASTION_INSTANCE_TAG: ${{ secrets.BASTION_INSTANCE_TAG }}
58+
permissions:
59+
id-token: write
60+
contents: read
61+
62+
Xa11yMacOS:
63+
needs: [TagRelease, UnitTests]
64+
name: xa11y Integration Tests (macOS, Cinema 4D ${{ matrix.c4d_version }})
65+
strategy:
66+
fail-fast: false
67+
matrix:
68+
c4d_version: ["2024", "2025", "2026"]
69+
uses: ./.github/workflows/integ_macos.yml
70+
with:
71+
c4d_version: ${{ matrix.c4d_version }}
72+
secrets:
73+
AWS_OIDC_ROLE_ARN: ${{ secrets.AWS_OIDC_ROLE_ARN }}
74+
AWS_REGION: ${{ secrets.AWS_REGION }}
75+
RLM_PORT: ${{ secrets.RLM_PORT }}
76+
INSTALLER_BUCKET: ${{ secrets.INSTALLER_BUCKET }}
77+
INSTALLER_BUCKET_EXPECTED_OWNER: ${{ secrets.INSTALLER_BUCKET_EXPECTED_OWNER }}
78+
LICENSE_ROLE_ARN: ${{ secrets.LICENSE_ROLE_ARN }}
79+
BASTION_INSTANCE_TAG: ${{ secrets.BASTION_INSTANCE_TAG }}
80+
permissions:
81+
id-token: write
82+
contents: read
83+
84+
BuildInstaller:
85+
needs: [TagRelease, UnitTests, Xa11yWindows, Xa11yMacOS]
86+
uses: aws-deadline/.github/.github/workflows/reusable_build_installers.yml@mainline
87+
secrets: inherit
88+
permissions:
89+
id-token: write
90+
contents: read
91+
with:
92+
ref_type: tags
93+
ref: ${{ needs.TagRelease.outputs.tag }}
94+
oses: "['Windows', 'MacOS']"
95+
environment: release
96+
project_name: ${{ github.event.repository.name }}
97+
98+
PublishToCodeArtifact:
99+
needs: [TagRelease, BuildInstaller]
100+
uses: aws-deadline/.github/.github/workflows/reusable_publish_python.yml@mainline
101+
permissions:
102+
id-token: write
103+
secrets: inherit
104+
with:
105+
tag: ${{ needs.TagRelease.outputs.tag }}
Lines changed: 117 additions & 117 deletions
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,21 @@
11
name: "Release: Publish"
2-
run-name: "Release: ${{ github.event.head_commit.message || inputs.tag }}"
2+
run-name: "Release: Publish ${{ inputs.tag || 'next pending release' }}"
33

44
on:
5-
push:
6-
branches:
7-
- mainline
8-
paths:
9-
- CHANGELOG.md
5+
schedule:
6+
# Check at 00:17, 06:17, 12:17, and 18:17 UTC.
7+
- cron: "17 */6 * * *"
108
workflow_dispatch:
119
inputs:
1210
tag:
13-
required: true
11+
description: Specific pending release tag to check
12+
required: false
1413
type: string
15-
description: Specify a tag to re-run a release.
14+
force_publish:
15+
description: Bypass Conda availability after release-gate approval (requires tag)
16+
required: false
17+
default: false
18+
type: boolean
1619

1720
concurrency:
1821
group: release
@@ -21,150 +24,147 @@ permissions:
2124
contents: read
2225

2326
jobs:
24-
TagRelease:
25-
uses: aws-deadline/.github/.github/workflows/reusable_tag_release.yml@mainline
26-
secrets: inherit
27-
with:
28-
tag: ${{ github.event_name == 'workflow_dispatch' && inputs.tag || '' }}
27+
CheckConda:
28+
if: github.repository == 'aws-deadline/deadline-cloud-for-cinema-4d'
29+
runs-on: ubuntu-latest
30+
outputs:
31+
ready: ${{ steps.readiness.outputs.ready }}
32+
tag: ${{ steps.readiness.outputs.tag }}
33+
steps:
34+
- name: Checkout
35+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
36+
with:
37+
fetch-depth: 0
38+
persist-credentials: false
2939

30-
UnitTests:
31-
needs: [TagRelease]
32-
name: Unit Tests
33-
uses: ./.github/workflows/code_quality.yml
34-
with:
35-
tag: ${{ needs.TagRelease.outputs.tag }}
36-
37-
Xa11yWindows:
38-
needs: [TagRelease, UnitTests]
39-
name: xa11y Integration Tests (Windows, Cinema 4D ${{ matrix.c4d_version }})
40-
strategy:
41-
fail-fast: false
42-
matrix:
43-
c4d_version: ["2024", "2025", "2026"]
44-
uses: ./.github/workflows/integ_windows.yml
45-
with:
46-
c4d_version: ${{ matrix.c4d_version }}
47-
secrets:
48-
AWS_OIDC_ROLE_ARN: ${{ secrets.AWS_OIDC_ROLE_ARN }}
49-
AWS_REGION: ${{ secrets.AWS_REGION }}
50-
RLM_PORT: ${{ secrets.RLM_PORT }}
51-
INSTALLER_BUCKET: ${{ secrets.INSTALLER_BUCKET }}
52-
INSTALLER_BUCKET_EXPECTED_OWNER: ${{ secrets.INSTALLER_BUCKET_EXPECTED_OWNER }}
53-
LICENSE_ROLE_ARN: ${{ secrets.LICENSE_ROLE_ARN }}
54-
BASTION_INSTANCE_TAG: ${{ secrets.BASTION_INSTANCE_TAG }}
55-
permissions:
56-
id-token: write
57-
contents: read
40+
- name: Check release readiness
41+
id: readiness
42+
uses: aws-deadline/.github/.github/actions/check-release-readiness@mainline
43+
with:
44+
github-token: ${{ github.token }}
45+
requested-tag: ${{ inputs.tag }}
46+
force-publish: ${{ inputs.force_publish }}
47+
package-name: cinema4d-openjd
48+
required-platforms: linux-64,win-64
49+
timeout-days: 4
5850

59-
Xa11yMacOS:
60-
needs: [TagRelease, UnitTests]
61-
name: xa11y Integration Tests (macOS, Cinema 4D ${{ matrix.c4d_version }})
62-
strategy:
63-
fail-fast: false
64-
matrix:
65-
c4d_version: ["2024", "2025", "2026"]
66-
uses: ./.github/workflows/integ_macos.yml
67-
with:
68-
c4d_version: ${{ matrix.c4d_version }}
69-
secrets:
70-
AWS_OIDC_ROLE_ARN: ${{ secrets.AWS_OIDC_ROLE_ARN }}
71-
AWS_REGION: ${{ secrets.AWS_REGION }}
72-
RLM_PORT: ${{ secrets.RLM_PORT }}
73-
INSTALLER_BUCKET: ${{ secrets.INSTALLER_BUCKET }}
74-
INSTALLER_BUCKET_EXPECTED_OWNER: ${{ secrets.INSTALLER_BUCKET_EXPECTED_OWNER }}
75-
LICENSE_ROLE_ARN: ${{ secrets.LICENSE_ROLE_ARN }}
76-
BASTION_INSTANCE_TAG: ${{ secrets.BASTION_INSTANCE_TAG }}
51+
ApproveManifestOverride:
52+
needs: CheckConda
53+
if: >-
54+
inputs.force_publish == true &&
55+
needs.CheckConda.outputs.tag != '' &&
56+
needs.CheckConda.outputs.ready != 'true'
57+
runs-on: ubuntu-latest
58+
environment: release-gate
59+
permissions: {}
60+
steps:
61+
- name: Record approved override
62+
env:
63+
TAG: ${{ needs.CheckConda.outputs.tag }}
64+
run: |
65+
echo "Conda manifest override approved for release $TAG."
66+
{
67+
echo "### Conda manifest override"
68+
echo
69+
printf 'Release `%s` was approved without a published Conda package.\n' "$TAG"
70+
} >> "$GITHUB_STEP_SUMMARY"
71+
72+
AuthorizePublish:
73+
needs: [CheckConda, ApproveManifestOverride]
74+
if: >-
75+
always() &&
76+
needs.CheckConda.result == 'success' &&
77+
needs.CheckConda.outputs.tag != '' &&
78+
(
79+
needs.CheckConda.outputs.ready == 'true' ||
80+
needs.ApproveManifestOverride.result == 'success'
81+
)
82+
runs-on: ubuntu-latest
83+
permissions: {}
84+
outputs:
85+
tag: ${{ steps.release.outputs.tag }}
86+
steps:
87+
- name: Authorize public release
88+
id: release
89+
env:
90+
TAG: ${{ needs.CheckConda.outputs.tag }}
91+
run: echo "tag=$TAG" >> "$GITHUB_OUTPUT"
92+
93+
ValidateRelease:
94+
needs: AuthorizePublish
95+
if: needs.AuthorizePublish.outputs.tag != ''
96+
uses: aws-deadline/.github/.github/workflows/reusable_tag_release.yml@mainline
7797
permissions:
78-
id-token: write
7998
contents: read
99+
secrets: inherit
100+
with:
101+
tag: ${{ needs.AuthorizePublish.outputs.tag }}
80102

81103
PreRelease:
82-
needs: [TagRelease, UnitTests, Xa11yWindows, Xa11yMacOS]
83-
uses: aws-deadline/.github/.github/workflows/reusable_prerelease.yml@mainline
84-
permissions:
85-
id-token: write
86-
contents: write
87-
secrets: inherit
88-
with:
89-
tag: ${{ needs.TagRelease.outputs.tag }}
90-
91-
BuildInstaller:
92-
needs: [TagRelease, PreRelease]
93-
uses: aws-deadline/.github/.github/workflows/reusable_build_installers.yml@mainline
94-
secrets: inherit
104+
needs: ValidateRelease
105+
if: needs.ValidateRelease.outputs.tag != ''
106+
uses: aws-deadline/.github/.github/workflows/reusable_prerelease.yml@mainline
95107
permissions:
96108
id-token: write
97-
contents: read
109+
contents: write
110+
secrets: inherit
98111
with:
99-
ref_type: tags
100-
ref: ${{ needs.TagRelease.outputs.tag }}
101-
oses: "['Windows', 'MacOS']"
102-
environment: release
103-
project_name: ${{ github.event.repository.name }}
112+
tag: ${{ needs.ValidateRelease.outputs.tag }}
104113

105-
Publish:
106-
needs: [TagRelease, BuildInstaller]
107-
uses: aws-deadline/.github/.github/workflows/reusable_publish_python.yml@mainline
108-
permissions:
109-
id-token: write
110-
secrets: inherit
111-
with:
112-
tag: ${{ needs.TagRelease.outputs.tag }}
113-
114-
IsCondaReady:
115-
needs: Publish
116-
runs-on: ubuntu-latest
117-
environment: release-gate
118-
name: “Is the Conda Package available in all ProdWaves and have you ran any required manual tests?”
119-
steps:
120-
- run: |
121-
:
122-
123114
ReleaseInstaller:
124-
needs: [TagRelease, IsCondaReady]
115+
needs: [ValidateRelease, PreRelease]
116+
if: needs.ValidateRelease.outputs.tag != ''
125117
uses: aws-deadline/.github/.github/workflows/reusable_release_installers.yml@mainline
126118
secrets: inherit
127119
permissions:
128120
id-token: write
129121
contents: read
130122
with:
131-
tag: ${{ needs.TagRelease.outputs.tag }}
123+
tag: ${{ needs.ValidateRelease.outputs.tag }}
132124
oses: "['Windows', 'MacOS']"
133125
project_name: ${{ github.event.repository.name }}
134126

135-
Release:
136-
needs: [TagRelease, ReleaseInstaller]
137-
uses: aws-deadline/.github/.github/workflows/reusable_release.yml@mainline
138-
secrets: inherit
139-
permissions:
140-
id-token: write
141-
contents: write
142-
with:
143-
tag: ${{ needs.TagRelease.outputs.tag }}
144-
145-
# PyPI does not support reusable workflows yet
146-
# # See https://github.com/pypi/warehouse/issues/11096
127+
# PyPI does not support reusable workflows yet.
128+
# See https://github.com/pypi/warehouse/issues/11096
147129
PublishToPyPI:
148-
needs: [TagRelease, Release]
130+
needs: [ValidateRelease, ReleaseInstaller]
131+
if: needs.ValidateRelease.outputs.tag != ''
149132
runs-on: ubuntu-latest
150133
environment: release
151134
permissions:
152135
id-token: write
136+
contents: read
153137
steps:
154138
- name: Checkout
155139
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
156140
with:
157-
ref: ${{ needs.TagRelease.outputs.tag }}
141+
ref: ${{ needs.ValidateRelease.outputs.tag }}
158142
fetch-depth: 0
143+
persist-credentials: false
144+
159145
- name: Set up Python
160146
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
161147
with:
162-
python-version: ${{ needs.TagRelease.outputs.build-python-version }}
148+
python-version: ${{ needs.ValidateRelease.outputs.build-python-version }}
149+
163150
- name: Install dependencies
164-
run: |
165-
pip install --upgrade hatch
151+
run: pip install --upgrade hatch
152+
166153
- name: Build
167154
run: hatch -v build
168-
# # See https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-pypi
155+
169156
- name: Publish to PyPI
170157
uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2
158+
with:
159+
skip-existing: true
160+
161+
Release:
162+
needs: [ValidateRelease, PreRelease, PublishToPyPI]
163+
if: needs.ValidateRelease.outputs.tag != ''
164+
uses: aws-deadline/.github/.github/workflows/reusable_release.yml@mainline
165+
secrets: inherit
166+
permissions:
167+
id-token: write
168+
contents: write
169+
with:
170+
tag: ${{ needs.ValidateRelease.outputs.tag }}

0 commit comments

Comments
 (0)