Repository navigation
repo file, go for xmit #17
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build Flatpak | |
| on: | |
| push: | |
| branches: | |
| - main | |
| tags: | |
| - 'v*' | |
| pull_request: | |
| branches: | |
| - main | |
| workflow_dispatch: | |
| env: | |
| FLATPAK_ID: com.onclebob.Bob | |
| jobs: | |
| build: | |
| name: Build Flatpak (${{ matrix.arch }}) | |
| runs-on: ${{ matrix.arch == 'aarch64' && 'ubuntu-24.04-arm' || 'ubuntu-latest' }} | |
| strategy: | |
| matrix: | |
| arch: [x86_64, aarch64] | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Install flatpak-builder | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y flatpak flatpak-builder | |
| - name: Add Flathub repository | |
| run: | | |
| sudo flatpak remote-add --if-not-exists flathub https://flathub.org/repo/flathub.flatpakrepo | |
| - name: Install Flatpak SDK and runtime | |
| run: | | |
| sudo flatpak install -y flathub org.freedesktop.Platform//25.08 org.freedesktop.Sdk//25.08 | |
| sudo flatpak install -y flathub org.freedesktop.Sdk.Extension.llvm21//25.08 | |
| - name: Build Flatpak | |
| run: | | |
| flatpak-builder --arch=${{ matrix.arch }} \ | |
| --repo=repo \ | |
| --force-clean \ | |
| --ccache \ | |
| --install-deps-from=flathub \ | |
| build-dir \ | |
| ${{ env.FLATPAK_ID }}.yml | |
| - name: Create Flatpak bundle | |
| run: | | |
| flatpak build-bundle repo \ | |
| ${{ env.FLATPAK_ID }}-${{ matrix.arch }}.flatpak \ | |
| ${{ env.FLATPAK_ID }} \ | |
| --runtime-repo=https://flathub.org/repo/flathub.flatpakrepo | |
| - name: Import GPG key | |
| if: github.event_name == 'push' && (github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/')) | |
| env: | |
| GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} | |
| GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} | |
| run: | | |
| echo "$GPG_PRIVATE_KEY" | gpg --batch --import | |
| echo "allow-preset-passphrase" >> ~/.gnupg/gpg-agent.conf | |
| echo "pinentry-mode loopback" >> ~/.gnupg/gpg.conf | |
| gpg-connect-agent reloadagent /bye | |
| - name: Sign Flatpak bundle | |
| if: github.event_name == 'push' && (github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/')) | |
| env: | |
| GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} | |
| run: | | |
| GPG_KEY_ID=$(gpg --list-secret-keys --keyid-format LONG | grep sec | awk '{print $2}' | cut -d'/' -f2 | head -n1) | |
| echo "$GPG_PASSPHRASE" | gpg --batch --yes --pinentry-mode loopback --passphrase-fd 0 \ | |
| --detach-sign --armor \ | |
| --output ${{ env.FLATPAK_ID }}-${{ matrix.arch }}.flatpak.sig \ | |
| ${{ env.FLATPAK_ID }}-${{ matrix.arch }}.flatpak | |
| - name: Generate checksums | |
| run: | | |
| sha256sum ${{ env.FLATPAK_ID }}-${{ matrix.arch }}.flatpak > ${{ env.FLATPAK_ID }}-${{ matrix.arch }}.flatpak.sha256 | |
| - name: Upload build artifacts | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: flatpak-${{ matrix.arch }} | |
| path: | | |
| ${{ env.FLATPAK_ID }}-${{ matrix.arch }}.flatpak | |
| ${{ env.FLATPAK_ID }}-${{ matrix.arch }}.flatpak.sig | |
| ${{ env.FLATPAK_ID }}-${{ matrix.arch }}.flatpak.sha256 | |
| retention-days: 30 | |
| - name: Upload OSTree repository | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: ostree-repo-${{ matrix.arch }} | |
| path: repo/ | |
| retention-days: 7 | |
| release: | |
| name: Create Release | |
| needs: build | |
| runs-on: ubuntu-latest | |
| if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/') | |
| steps: | |
| - name: Download all artifacts | |
| uses: actions/download-artifact@v4 | |
| with: | |
| path: artifacts | |
| - name: Prepare release assets | |
| run: | | |
| mkdir -p release | |
| find artifacts -name "*.flatpak" -exec cp {} release/ \; | |
| find artifacts -name "*.flatpak.sig" -exec cp {} release/ \; | |
| find artifacts -name "*.flatpak.sha256" -exec cp {} release/ \; | |
| ls -lah release/ | |
| - name: Create GitHub Release | |
| uses: softprops/action-gh-release@v1 | |
| with: | |
| files: release/* | |
| draft: false | |
| prerelease: false | |
| generate_release_notes: true | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| publish-repo: | |
| name: Publish OSTree Repository | |
| needs: build | |
| runs-on: ubuntu-latest | |
| if: github.event_name == 'push' && github.ref == 'refs/heads/main' | |
| steps: | |
| - name: Download OSTree repositories | |
| uses: actions/download-artifact@v4 | |
| with: | |
| pattern: ostree-repo-* | |
| path: repos | |
| - name: Install OSTree | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y ostree | |
| - name: Merge OSTree repositories | |
| run: | | |
| ostree init --repo=dist --mode=archive-z2 | |
| # Find all downloaded repo directories | |
| for repo_dir in repos/ostree-repo-*/; do | |
| if [ -d "$repo_dir" ] && [ -f "$repo_dir/config" ]; then | |
| echo "Processing repository: $repo_dir" | |
| # Create refs/remotes directory if it doesn't exist to prevent errors | |
| mkdir -p "$repo_dir/refs/remotes" | |
| # List available refs in source repo | |
| echo "Available refs in source repo:" | |
| ostree refs --repo="$repo_dir" || echo "No refs found" | |
| # Pull all refs from the source repo | |
| for ref in $(ostree refs --repo="$repo_dir" 2>/dev/null || true); do | |
| echo "Pulling ref: $ref" | |
| ostree pull-local --repo=dist "$repo_dir" "$ref" || echo "Warning: Failed to pull $ref" | |
| done | |
| fi | |
| done | |
| # List what we have in the merged repo | |
| echo "Merged repository contents:" | |
| ostree refs --repo=dist || echo "No refs found in merged repo" | |
| - name: Import GPG key for repo signing | |
| env: | |
| GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} | |
| GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} | |
| run: | | |
| echo "$GPG_PRIVATE_KEY" | gpg --batch --import | |
| echo "allow-preset-passphrase" >> ~/.gnupg/gpg-agent.conf | |
| echo "pinentry-mode loopback" >> ~/.gnupg/gpg.conf | |
| gpg-connect-agent reloadagent /bye | |
| GPG_KEY_ID=$(gpg --list-secret-keys --keyid-format LONG | grep sec | awk '{print $2}' | cut -d'/' -f2 | head -n1) | |
| echo "GPG_KEY_ID=$GPG_KEY_ID" >> $GITHUB_ENV | |
| # Get the keygrip for the signing key | |
| KEYGRIP=$(gpg --with-keygrip --list-secret-keys "$GPG_KEY_ID" | grep "Keygrip" | head -n1 | awk '{print $3}') | |
| # Preset the passphrase in the gpg-agent cache | |
| echo "$GPG_PASSPHRASE" | /usr/lib/gnupg/gpg-preset-passphrase --preset "$KEYGRIP" | |
| - name: Sign OSTree repository | |
| run: | | |
| ostree summary --repo=dist --update --gpg-sign=${{ env.GPG_KEY_ID }} --gpg-homedir=$HOME/.gnupg | |
| - name: Export GPG public key and create repo files | |
| run: | | |
| # Export GPG public key in base64 format for flatpak files | |
| GPG_PUBLIC_KEY=$(gpg --export ${{ env.GPG_KEY_ID }} | base64 -w 0) | |
| # Create .flatpakrepo file | |
| printf '%s\n' \ | |
| "[Flatpak Repo]" \ | |
| "Title=OncleBob" \ | |
| "Url=https://flatpak.onclebob.com/" \ | |
| "Homepage=https://onclebob.com" \ | |
| "Description=OncleBob Flatpak Repository" \ | |
| "GPGKey=${GPG_PUBLIC_KEY}" \ | |
| > dist/onclebob.flatpakrepo | |
| - name: Set up Go | |
| uses: actions/setup-go@v5 | |
| with: | |
| go-version: 'stable' | |
| - name: Install xmit | |
| run: go install github.com/xmit-co/xmit@latest | |
| - name: Upload to xmit | |
| env: | |
| XMIT_KEY: ${{ secrets.XMIT_KEY }} | |
| run: xmit flatpak.onclebob.com |