Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 28 additions & 6 deletions .github/workflows/channel.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,8 @@ name: Update channel
# release's files; the statement key, in the KRYPTIK_LATEST_KEY secret. A
# dispatch publishes a release into a channel, or with no release signs the
# current statement again; the schedule signs it again daily, so a machine
# that hears nothing for 30 days knows something is wrong.
# that hears nothing for 30 days knows something is wrong. Before the first
# release there is no key and no statement, and a scheduled run ends quietly.

on:
workflow_dispatch:
Expand Down Expand Up @@ -45,18 +46,36 @@ jobs:
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0

- name: The statement key
id: key
if: ${{ !inputs.dry_run }}
env:
KEY: ${{ secrets.KRYPTIK_LATEST_KEY }}
GH_TOKEN: ${{ github.token }}
RELEASE: ${{ inputs.release }}
CHANNEL: ${{ inputs.channel || 'stable' }}
run: |
if [ -z "$KEY" ]; then
if [ -n "$KEY" ]; then
umask 077
printf '%s\n' "$KEY" > "$RUNNER_TEMP/kryptik-latest"
exit 0
fi
# Without the key a publish cannot sign, and a statement the site
# already serves would go stale; a channel that serves none yet has
# nothing to sign again.
if [ -n "$RELEASE" ]; then
echo "no KRYPTIK_LATEST_KEY secret: the statement key the ceremony made (docs/release-keys.md), without a passphrase"
exit 1
fi
umask 077
printf '%s\n' "$KEY" > "$RUNNER_TEMP/kryptik-latest"
site="$(gh api "repos/${GITHUB_REPOSITORY}/pages" --jq .html_url 2>/dev/null || true)"
if [ -n "$site" ] && curl -fsSL -o /dev/null "${site%/}/${CHANNEL}/latest" 2>/dev/null; then
echo "no KRYPTIK_LATEST_KEY secret, and ${site%/}/${CHANNEL}/latest is served: it will go stale. Put the statement key in the secret (docs/release-keys.md)"
exit 1
fi
echo "no KRYPTIK_LATEST_KEY secret and no statement served for ${CHANNEL}: nothing to sign again yet"
echo "skip=true" >> "$GITHUB_OUTPUT"

- name: The channel
if: ${{ steps.key.outputs.skip != 'true' }}
env:
GH_TOKEN: ${{ github.token }}
RELEASE: ${{ inputs.release }}
Expand All @@ -72,9 +91,12 @@ jobs:
rm -f "$RUNNER_TEMP/kryptik-latest"
find site -type f | sort

- uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
- uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
- if: ${{ steps.key.outputs.skip != 'true' }}
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
- if: ${{ steps.key.outputs.skip != 'true' }}
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
with:
path: site
- id: deploy
if: ${{ steps.key.outputs.skip != 'true' }}
uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1
Loading