mirror of
https://github.com/3proxy/3proxy.git
synced 2026-08-26 09:55:48 +08:00
Docker: single workflow, one job per image per platform instead of one workflow per registry. Platforms are built in parallel and pushed by digest, then combined into a manifest list pushed to Docker Hub and GHCR at once, so both registries get identical digests. arm64 and arm/v7 build on native arm runners, ppc64le is dropped. Registry provenance/sbom attestations are disabled (they were shown as unknown/unknown entries in the registries), build provenance is attested with actions/attest-build-provenance instead and is verifiable with 'gh attestation verify oci://...'. Release binaries (rpm, deb, zip) are attested the same way. cosign version is pinned and images are signed by digest.
126 lines
5.0 KiB
YAML
126 lines
5.0 KiB
YAML
name: RPM/DEB build armhf
|
|
|
|
on:
|
|
release:
|
|
types: [published]
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: write
|
|
id-token: write
|
|
attestations: write
|
|
|
|
jobs:
|
|
ci:
|
|
name: "${{ matrix.target }}"
|
|
strategy:
|
|
matrix:
|
|
target:
|
|
- ubuntu-latest
|
|
runs-on: ${{ matrix.target }}
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- name: env
|
|
run: |
|
|
pwd
|
|
echo "RELEASE=$(cat RELEASE)" >> $GITHUB_ENV
|
|
echo "VERSION=$(date +%y%m%d%H%M%S)" >> $GITHUB_ENV
|
|
- name: Linux libraries
|
|
run: |
|
|
sudo apt update
|
|
sudo dpkg --add-architecture armhf
|
|
echo "Types: deb" > ~/ubuntu.sources
|
|
echo "URIs: http://archive.ubuntu.com/ubuntu/" >> ~/ubuntu.sources
|
|
echo "Suites: noble noble-updates noble-backports" >> ~/ubuntu.sources
|
|
echo "Components: main restricted universe multiverse" >> ~/ubuntu.sources
|
|
echo "Signed-By: /usr/share/keyrings/ubuntu-archive-keyring.gpg" >> ~/ubuntu.sources
|
|
echo "Architectures: amd64" >> ~/ubuntu.sources
|
|
echo "" >> ~/ubuntu.sources
|
|
echo "Types: deb" >> ~/ubuntu.sources
|
|
echo "URIs: http://security.ubuntu.com/ubuntu/" >> ~/ubuntu.sources
|
|
echo "Suites: noble-security" >> ~/ubuntu.sources
|
|
echo "Components: main restricted universe multiverse" >> ~/ubuntu.sources
|
|
echo "Architectures: amd64" >> ~/ubuntu.sources
|
|
echo "Signed-By: /usr/share/keyrings/ubuntu-archive-keyring.gpg" >> ~/ubuntu.sources
|
|
echo "" >> ~/ubuntu.sources
|
|
echo "Types: deb" >>~/ubuntu.sources
|
|
echo "URIs: http://ports.ubuntu.com/ubuntu-ports/" >>~/ubuntu.sources
|
|
echo "Suites: noble noble-updates" >>~/ubuntu.sources
|
|
echo "Components: main restricted universe multiverse" >>~/ubuntu.sources
|
|
echo "Architectures: armhf" >>~/ubuntu.sources
|
|
echo "Signed-By: /usr/share/keyrings/ubuntu-archive-keyring.gpg" >>~/ubuntu.sources
|
|
sudo cp ~/ubuntu.sources /etc/apt/sources.list.d/ubuntu.sources
|
|
sudo apt update
|
|
sudo apt install libssl3t64:armhf openssl:armhf libssl-dev:armhf libpam0g:armhf libpam0g-dev:armhf libpcre2-dev:armhf rpm crossbuild-essential-armhf build-essential debhelper
|
|
- name: configure rpm env
|
|
run: |
|
|
mkdir ~/debian
|
|
mkdir -p ~/rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
|
|
tar -czf ~/rpmbuild/SOURCES/3proxy-$RELEASE.tar.gz --transform "s,^,3proxy-$RELEASE/," .
|
|
ln -s ~/rpmbuild/SOURCES/3proxy-$RELEASE.tar.gz ~/rpmbuild/SOURCES/$RELEASE.tar.gz
|
|
cp scripts/rh/3proxy.spec ~/rpmbuild/SPECS/3proxy-$RELEASE.spec
|
|
cp ~/rpmbuild/SOURCES/3proxy-$RELEASE.tar.gz ~/debian/3proxy_$RELEASE.orig.tar.gz
|
|
- name: rpmbuild
|
|
run: |
|
|
ret=`pwd`
|
|
cd ~/rpmbuild/SPECS
|
|
PATH=/usr/arm-linux-gnueabihf/bin:$PATH
|
|
export PATH=$PATH
|
|
CC=arm-linux-gnueabihf-gcc
|
|
export CC=$CC
|
|
export RPATH=/usr/arm-linux-gnueabihf/lib:$RPATH
|
|
export LD_LIBRARY_PATH=/usr/arm-linux-gnueabihf/lib:$LD_LIBRARY_PATH
|
|
rpmbuild -ba --define "PAMLIB pam0g" --define "_arch arm" --define "cross yes" --target=arm-linux-gnueabihf 3proxy-$RELEASE.spec
|
|
cd $ret
|
|
mv ~/rpmbuild/RPMS/arm/3proxy-$RELEASE-1.arm.rpm 3proxy-$RELEASE.arm.rpm
|
|
- name: Get artifact rpm
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: "3proxy-${{ env.RELEASE }}-arm.rpm"
|
|
path: "*.rpm"
|
|
- name: Upload rpm to release
|
|
if: github.event_name == 'release'
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
TAG: ${{ github.event.release.tag_name }}
|
|
run: gh release upload "$TAG" 3proxy-${{ env.RELEASE }}.arm.rpm
|
|
- name: debbuild
|
|
run: |
|
|
ret=`pwd`
|
|
cd ~/debian/
|
|
tar xzf 3proxy_$RELEASE.orig.tar.gz
|
|
cd 3proxy-$RELEASE
|
|
echo "3proxy ($RELEASE-$VERSION) buster; urgency=medium" >debian/changelog
|
|
echo " " >>debian/changelog
|
|
echo " *3proxy $RELEASE build" >>debian/changelog
|
|
echo " " >>debian/changelog
|
|
echo " -- z3APA3A <3apa3a@3proxy.org> "`date "+%a, %d %b %Y %H:%M:%S %z"` >>debian/changelog
|
|
echo "">>debian/changelog
|
|
PATH=/usr/arm-linux-gnueabihf/bin:$PATH
|
|
export PATH=$PATH
|
|
CC=arm-linux-gnueabihf-gcc
|
|
export CC=$CC
|
|
export RPATH=/usr/arm-linux-gnueabihf/lib:$RPATH
|
|
export LD_LIBRARY_PATH=/usr/arm-linux-gnueabihf/lib:$LD_LIBRARY_PATH
|
|
dpkg-buildpackage
|
|
cd $ret
|
|
cp ~/debian/3proxy_$RELEASE-"$VERSION"_armhf.deb ./3proxy-$RELEASE.arm.deb
|
|
- name: Get artifact deb
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: "3proxy-${{ env.RELEASE }}-arm.deb"
|
|
path: "*.deb"
|
|
- name: Upload deb to release
|
|
if: github.event_name == 'release'
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
TAG: ${{ github.event.release.tag_name }}
|
|
run: gh release upload "$TAG" 3proxy-${{ env.RELEASE }}.arm.deb
|
|
- name: Attest build provenance
|
|
if: github.event_name == 'release'
|
|
uses: actions/attest-build-provenance@v2
|
|
with:
|
|
subject-path: |
|
|
*.rpm
|
|
*.deb
|