From 6cb1de0f7bed1db2c4905211f66c761aba5a5c41 Mon Sep 17 00:00:00 2001 From: Dominion Date: Sat, 29 Apr 2023 11:12:40 -0400 Subject: [PATCH] CI Overhaul - Switched from `pull_request` to `pull_request_target`, explicitly checking out the PR code. - Added security-checkpoint job that will fail on pull requests from forks. - Added concurrency limiter. - Added missing live tests filter. - Fixed bad indentation. Fixes #1107 --- .github/workflows/ci-suite.yml | 642 ++++++++++++++++++++------------- 1 file changed, 390 insertions(+), 252 deletions(-) diff --git a/.github/workflows/ci-suite.yml b/.github/workflows/ci-suite.yml index 852d85dbfb..c68d96617e 100644 --- a/.github/workflows/ci-suite.yml +++ b/.github/workflows/ci-suite.yml @@ -5,7 +5,8 @@ on: branches: - dev - master - pull_request: + pull_request_target: + types: [opened, reopened, labeled, synchronize] branches: - dev - master @@ -19,9 +20,35 @@ env: TGS_TEST_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} TGS_RELEASE_NOTES_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} +concurrency: + group: "ci-${{ (github.event_name == 'push' ? github.head_ref : github.event.number) }}" + cancel-in-progress: true + jobs: + security-checkpoint: + name: Check CI Clearance + needs: security-checkpoint + runs-on: ubuntu-latest + steps: + - name: Comment on new Fork PR + if: github.event_name != 'push' && github.pull_request.head.repo.id != github.repository.id && github.event.action == 'opened' + uses: thollander/actions-comment-pull-request@v2 + with: + message: Thank you for contributing to tgstation-server! As this pull request is from a fork, we can't allow the CI actions which require repository secrets to run on it without approval. After a brief review to make sure you're not misusing those secrets, a maintainer will add the `CI Cleared` label to allow the CI suite to run. Maintainers, please note that any changes to workflow files will not be reflected in the CI run. + + - name: "Remove Stale 'CI Cleared' Label" + if: github.event_name != 'push' && github.pull_request.head.repo.id != github.repository.id && (github.event.action == 'synchronize' || github.event.action == 'reopened') + uses: actions-ecosystem/action-remove-labels@v1 + with: + labels: CI Cleared + + - name: Fail Clearance Check if PR has Unlabeled new Commits from Fork + if: github.event_name != 'push' && github.pull_request.head.repo.id != github.repository.id && (github.event.action != 'labeled' || !contains(github.event.pull_request.labels.*.name, 'CI Cleared')) + run: exit 1 + analyze: name: Code Scanning + needs: security-checkpoint runs-on: ubuntu-latest steps: - name: Install Node 12.X @@ -32,11 +59,19 @@ jobs: - name: Upgrade NPM run: npm install -g npm - - name: Checkout repository + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' with: fetch-depth: 2 + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + fetch-depth: 2 + ref: "refs/pull/${{ github.event.number }}/merge" + - name: Initialize CodeQL uses: github/codeql-action/init@v2 with: @@ -73,8 +108,15 @@ jobs: make here exit 0 - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Build DMAPI Test Project run: | @@ -100,58 +142,70 @@ jobs: name: Build Doxygen Site runs-on: ubuntu-latest steps: - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Patch Doxyfile - run: | - VERSION=$(cat "build/Version.props" | grep -oPm1 "(?<=)[^<]+") - echo -e "\nPROJECT_NUMBER = $VERSION\nINPUT = .\nOUTPUT_DIRECTORY = ./doxout\nPROJECT_LOGO = ./build/tgs.ico\nHAVE_DOT=YES" >> "docs/Doxyfile" + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - - name: Doxygen Build - uses: mattnotmitt/doxygen-action@v1 - with: - doxyfile-path: 'docs/Doxyfile' + - name: Patch Doxyfile + run: | + VERSION=$(cat "build/Version.props" | grep -oPm1 "(?<=)[^<]+") + echo -e "\nPROJECT_NUMBER = $VERSION\nINPUT = .\nOUTPUT_DIRECTORY = ./doxout\nPROJECT_LOGO = ./build/tgs.ico\nHAVE_DOT=YES" >> "docs/Doxyfile" - - name: gh-pages push - if: github.event_name == 'push' && github.event.ref == 'refs/heads/dev' - run: | - git clone -b gh-pages --single-branch "https://git@github.com/tgstation/tgstation-server" $HOME/tgsdox - pushd $HOME/tgsdox - rm -r * - popd - echo ./doxout/* | xargs -n 10 sudo mv -t $HOME/tgsdox - cd $HOME/tgsdox - git config --global push.default simple - git config user.name "tgstation-server" - git config user.email "tgstation-server@tgstation13.org" - echo '# THIS BRANCH IS AUTO GENERATED BY GITHUB ACTIONS' > README.md + - name: Doxygen Build + uses: mattnotmitt/doxygen-action@v1 + with: + doxyfile-path: 'docs/Doxyfile' - # Need to create a .nojekyll file to allow filenames starting with an underscore - # to be seen on the gh-pages site. Therefore creating an empty .nojekyll file. - echo "" > .nojekyll - echo "Adding files..." - git add --all - echo "Committing..." - git diff-index --quiet HEAD || git commit -m "Deploy code docs to GitHub Pages for workflow run ${{ github.run_number }}" -m "Commit: ${{ github.event.head_commit.id }}" - echo "Pushing..." - git push -f "https://${{ secrets.DEV_PUSH_TOKEN }}@github.com/tgstation/tgstation-server" 2>&1 + - name: gh-pages push + if: github.event_name == 'push' && github.event.ref == 'refs/heads/dev' + run: | + git clone -b gh-pages --single-branch "https://git@github.com/tgstation/tgstation-server" $HOME/tgsdox + pushd $HOME/tgsdox + rm -r * + popd + echo ./doxout/* | xargs -n 10 sudo mv -t $HOME/tgsdox + cd $HOME/tgsdox + git config --global push.default simple + git config user.name "tgstation-server" + git config user.email "tgstation-server@tgstation13.org" + echo '# THIS BRANCH IS AUTO GENERATED BY GITHUB ACTIONS' > README.md + + # Need to create a .nojekyll file to allow filenames starting with an underscore + # to be seen on the gh-pages site. Therefore creating an empty .nojekyll file. + echo "" > .nojekyll + echo "Adding files..." + git add --all + echo "Committing..." + git diff-index --quiet HEAD || git commit -m "Deploy code docs to GitHub Pages for workflow run ${{ github.run_number }}" -m "Commit: ${{ github.event.head_commit.id }}" + echo "Pushing..." + git push -f "https://${{ secrets.DEV_PUSH_TOKEN }}@github.com/tgstation/tgstation-server" 2>&1 docker-build: name: Build Docker Image runs-on: ubuntu-latest steps: - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Upgrade NPM - run: sudo npm install -g npm + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Build Docker Image run: docker build . -f build/Dockerfile linux-unit-tests: name: Linux Tests + needs: security-checkpoint strategy: fail-fast: false matrix: @@ -163,8 +217,15 @@ jobs: with: dotnet-version: ${{ env.TGS_DOTNET_VERSION }} - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Upgrade NPM run: sudo npm install -g npm @@ -183,6 +244,7 @@ jobs: windows-unit-tests: name: Windows Tests + needs: security-checkpoint strategy: fail-fast: false matrix: @@ -194,8 +256,15 @@ jobs: with: dotnet-version: ${{ env.TGS_DOTNET_VERSION }} - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Upgrade NPM run: npm install -g npm @@ -214,7 +283,7 @@ jobs: windows-integration-test: name: Windows Live Tests - needs: dmapi-build + needs: [security-checkpoint, dmapi-build] env: TGS_TEST_DATABASE_TYPE: SqlServer TGS_TEST_DUMP_API_SPEC: yes @@ -243,17 +312,24 @@ jobs: TGS_CONNSTRING_VALUE="Server=(localdb)\MSSQLLocalDB;Integrated Security=true;Initial Catalog=TGS_${{ matrix.watchdog-type }}_${{ matrix.configuration }};Application Name=tgstation-server" echo "TGS_TEST_CONNECTION_STRING=$(echo $TGS_CONNSTRING_VALUE)" >> $GITHUB_ENV - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Build run: dotnet build -c ${{ matrix.configuration }} tests/Tgstation.Server.Tests/Tgstation.Server.Tests.csproj - - name: Run Integration Test + - name: Run Live Tests run: | cd tests/Tgstation.Server.Tests Start-Sleep -Seconds 10 - dotnet test -c ${{ matrix.configuration }} --no-build --logger GitHubActions --collect:"XPlat Code Coverage" --settings ../../build/coverlet.runsettings --results-directory ../../TestResults + dotnet test -c ${{ matrix.configuration }} --no-build --filter FullyQualifiedName~TestLiveServer --logger GitHubActions --collect:"XPlat Code Coverage" --settings ../../build/coverlet.runsettings --results-directory ../../TestResults - name: Store Code Coverage uses: actions/upload-artifact@v3 @@ -286,7 +362,7 @@ jobs: linux-integration-tests: name: Linux Live Tests - needs: dmapi-build + needs: [security-checkpoint, dmapi-build] services: # We start all dbs here so we can just code the stuff once postgres: image: cyberboss/postgres-max-connections # Fork of _/postgres:latest with max_connections=500 becuase GitHub actions service containers have no way to set command lines. Rebuilds with updates. @@ -380,17 +456,24 @@ jobs: if: ${{ matrix.watchdog-type == 'Basic' }} run: echo "General__UseBasicWatchdog=true" >> $GITHUB_ENV - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Build run: dotnet build -c ${{ matrix.configuration }}NoService tests/Tgstation.Server.Tests/Tgstation.Server.Tests.csproj - - name: Run Integration Test + - name: Run Live Tests run: | cd tests/Tgstation.Server.Tests sleep 10 - dotnet test -c ${{ matrix.configuration }}NoService --logger GitHubActions --no-build --collect:"XPlat Code Coverage" --settings ../../build/coverlet.runsettings --results-directory ../../TestResults + dotnet test -c ${{ matrix.configuration }}NoService --filter FullyQualifiedName~TestLiveServer --logger GitHubActions --no-build --collect:"XPlat Code Coverage" --settings ../../build/coverlet.runsettings --results-directory ../../TestResults - name: Store Code Coverage uses: actions/upload-artifact@v3 @@ -441,8 +524,15 @@ jobs: - name: Install IBM OpenAPI Validator run: npm i -g ibm-openapi-validator@0.51.3 - - name: Checkout + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Retrieve OpenAPI Spec uses: actions/download-artifact@v3 @@ -458,8 +548,15 @@ jobs: needs: [linux-unit-tests, linux-integration-tests, windows-unit-tests, windows-integration-test] runs-on: ubuntu-latest steps: - - name: Checkout for .codecov.yml + - name: Checkout (Branch Push) uses: actions/checkout@v3 + if: github.event_name == 'push' + + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - name: Retrieve Linux Unit Test Coverage (Debug) uses: actions/download-artifact@v3 @@ -540,42 +637,49 @@ jobs: runs-on: windows-latest if: github.event_name == 'push' && contains(github.event.head_commit.message, '[APIDeploy]') steps: - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Parse API version - shell: powershell - run: | - [XML]$versionXML = Get-Content build/Version.props - $apiVersion = $versionXML.Project.PropertyGroup.TgsApiVersion - echo "TGS_API_VERSION=$apiVersion" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - - name: Retrieve OpenAPI Spec - uses: actions/download-artifact@v3 - with: - name: openapi-spec - path: swagger + - name: Parse API version + shell: powershell + run: | + [XML]$versionXML = Get-Content build/Version.props + $apiVersion = $versionXML.Project.PropertyGroup.TgsApiVersion + echo "TGS_API_VERSION=$apiVersion" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append - - name: Create GitHub Release - uses: juitnow/github-action-create-release@v1 - id: create_release - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - tag_name: api-v${{ env.TGS_API_VERSION }} - release_name: tgstation-server API v${{ env.TGS_API_VERSION }} - body: The TGS HTTP API - commitish: ${{ github.event.head_commit.id }} + - name: Retrieve OpenAPI Spec + uses: actions/download-artifact@v3 + with: + name: openapi-spec + path: swagger - - name: Upload OpenApi Spec - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./swagger/swagger.json - asset_name: swagger.json - asset_content_type: application/json + - name: Create GitHub Release + uses: juitnow/github-action-create-release@v1 + id: create_release + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + tag_name: api-v${{ env.TGS_API_VERSION }} + release_name: tgstation-server API v${{ env.TGS_API_VERSION }} + body: The TGS HTTP API + commitish: ${{ github.event.head_commit.id }} + + - name: Upload OpenApi Spec + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./swagger/swagger.json + asset_name: swagger.json + asset_content_type: application/json deploy-dm: name: Deploy DreamMaker API @@ -583,42 +687,48 @@ jobs: runs-on: windows-latest if: github.event_name == 'push' && contains(github.event.head_commit.message, '[DMDeploy]') steps: + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - - name: Parse DMAPI version - shell: powershell - run: | - [XML]$versionXML = Get-Content build/Version.props - $dmVersion = $versionXML.Project.PropertyGroup.TgsDmapiVersion - echo "TGS_DM_VERSION=$dmVersion" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append + - name: Parse DMAPI version + shell: powershell + run: | + [XML]$versionXML = Get-Content build/Version.props + $dmVersion = $versionXML.Project.PropertyGroup.TgsDmapiVersion + echo "TGS_DM_VERSION=$dmVersion" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append - - name: Zip DMAPI - shell: powershell - run: | - &"C:/Program Files/7-Zip/7z.exe" a DMAPI.zip ./src/DMAPI/* -tzip + - name: Zip DMAPI + shell: powershell + run: | + &"C:/Program Files/7-Zip/7z.exe" a DMAPI.zip ./src/DMAPI/* -tzip - - name: Create GitHub Release - uses: juitnow/github-action-create-release@v1 - id: create_release - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - tag_name: dmapi-v${{ env.TGS_DM_VERSION }} - release_name: tgstation-server DMAPI v${{ env.TGS_DM_VERSION }} - body: The TGS DMAPI \#tgs-dmapi-release - commitish: ${{ github.event.head_commit.id }} + - name: Create GitHub Release + uses: juitnow/github-action-create-release@v1 + id: create_release + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + tag_name: dmapi-v${{ env.TGS_DM_VERSION }} + release_name: tgstation-server DMAPI v${{ env.TGS_DM_VERSION }} + body: The TGS DMAPI \#tgs-dmapi-release + commitish: ${{ github.event.head_commit.id }} - - name: Upload DMAPI Artifact - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./DMAPI.zip - asset_name: DMAPI.zip - asset_content_type: application/zip + - name: Upload DMAPI Artifact + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./DMAPI.zip + asset_name: DMAPI.zip + asset_content_type: application/zip deploy-client: name: Deploy Nuget Packages @@ -626,29 +736,36 @@ jobs: runs-on: ubuntu-latest if: github.event_name == 'push' && contains(github.event.head_commit.message, '[NugetDeploy]') steps: - - name: Setup dotnet - uses: actions/setup-dotnet@v2 - with: - dotnet-version: ${{ env.TGS_DOTNET_VERSION }} + - name: Setup dotnet + uses: actions/setup-dotnet@v2 + with: + dotnet-version: ${{ env.TGS_DOTNET_VERSION }} - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Publish API to NuGet - uses: alirezanet/publish-nuget@v3.0.0 - with: - PROJECT_FILE_PATH: src/Tgstation.Server.Api/Tgstation.Server.Api.csproj - TAG_COMMIT: false - INCLUDE_SYMBOLS: true - NUGET_KEY: ${{ secrets.NUGET_API_KEY }} + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - - name: Publish Client to NuGet - uses: alirezanet/publish-nuget@v3.0.0 - with: - PROJECT_FILE_PATH: src/Tgstation.Server.Client/Tgstation.Server.Client.csproj - TAG_COMMIT: false - INCLUDE_SYMBOLS: true - NUGET_KEY: ${{ secrets.NUGET_API_KEY }} + - name: Publish API to NuGet + uses: alirezanet/publish-nuget@v3.0.0 + with: + PROJECT_FILE_PATH: src/Tgstation.Server.Api/Tgstation.Server.Api.csproj + TAG_COMMIT: false + INCLUDE_SYMBOLS: true + NUGET_KEY: ${{ secrets.NUGET_API_KEY }} + + - name: Publish Client to NuGet + uses: alirezanet/publish-nuget@v3.0.0 + with: + PROJECT_FILE_PATH: src/Tgstation.Server.Client/Tgstation.Server.Client.csproj + TAG_COMMIT: false + INCLUDE_SYMBOLS: true + NUGET_KEY: ${{ secrets.NUGET_API_KEY }} ensure-release: name: Ensure TGS Release is Latest GitHub Release @@ -656,16 +773,23 @@ jobs: runs-on: ubuntu-latest if: always() && github.event_name == 'push' && !contains(github.event.head_commit.message, '[TGSDeploy]') && (contains(github.event.head_commit.message, '[APIDeploy]') || contains(github.event.head_commit.message, '[DMDeploy]')) steps: - - name: Setup dotnet - uses: actions/setup-dotnet@v2 - with: - dotnet-version: ${{ env.TGS_DOTNET_VERSION }} + - name: Setup dotnet + uses: actions/setup-dotnet@v2 + with: + dotnet-version: ${{ env.TGS_DOTNET_VERSION }} - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Run ReleaseNotes with --ensure-release - run: dotnet run -c Release --project tools/ReleaseNotes --ensure-release + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" + + - name: Run ReleaseNotes with --ensure-release + run: dotnet run -c Release --project tools/ReleaseNotes --ensure-release deploy-tgs: name: Deploy TGS @@ -673,136 +797,150 @@ jobs: runs-on: windows-latest if: github.event_name == 'push' && github.event.ref == 'refs/heads/master' && contains(github.event.head_commit.message, '[TGSDeploy]') steps: - - name: Setup dotnet - uses: actions/setup-dotnet@v2 - with: - dotnet-version: ${{ env.TGS_DOTNET_VERSION }} + - name: Setup dotnet + uses: actions/setup-dotnet@v2 + with: + dotnet-version: ${{ env.TGS_DOTNET_VERSION }} - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Parse TGS version - shell: powershell - run: | - [XML]$versionXML = Get-Content build/Version.props - $tgsVersion = $versionXML.Project.PropertyGroup.TgsCoreVersion - echo "TGS_VERSION=$tgsVersion" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - - name: Retrieve Server Service - uses: actions/download-artifact@v3 - with: - name: ServerService - path: ServerService + - name: Parse TGS version + shell: powershell + run: | + [XML]$versionXML = Get-Content build/Version.props + $tgsVersion = $versionXML.Project.PropertyGroup.TgsCoreVersion + echo "TGS_VERSION=$tgsVersion" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append - - name: Retrieve Server Console - uses: actions/download-artifact@v3 - with: - name: ServerConsole - path: ServerConsole + - name: Retrieve Server Service + uses: actions/download-artifact@v3 + with: + name: ServerService + path: ServerService - - name: Retrieve Server Update Package - uses: actions/download-artifact@v3 - with: - name: ServerUpdatePackage - path: ServerUpdatePackage + - name: Retrieve Server Console + uses: actions/download-artifact@v3 + with: + name: ServerConsole + path: ServerConsole - - name: Retrieve OpenAPI Spec - uses: actions/download-artifact@v3 - with: - name: openapi-spec - path: swagger + - name: Retrieve Server Update Package + uses: actions/download-artifact@v3 + with: + name: ServerUpdatePackage + path: ServerUpdatePackage - - name: Zip Artifacts - shell: powershell - run: | - &"C:/Program Files/7-Zip/7z.exe" a DMAPI.zip ./src/DMAPI/* -tzip - &"C:/Program Files/7-Zip/7z.exe" a ServerService.zip ./ServerService/* -tzip - &"C:/Program Files/7-Zip/7z.exe" a ServerConsole.zip ./ServerConsole/* -tzip - &"C:/Program Files/7-Zip/7z.exe" a ServerUpdatePackage.zip ./ServerUpdatePackage/* -tzip + - name: Retrieve OpenAPI Spec + uses: actions/download-artifact@v3 + with: + name: openapi-spec + path: swagger - - name: Generate Release Notes - run: dotnet run -c Release --project tools/ReleaseNotes ${{ env.TGS_VERSION }} + - name: Zip Artifacts + shell: powershell + run: | + &"C:/Program Files/7-Zip/7z.exe" a DMAPI.zip ./src/DMAPI/* -tzip + &"C:/Program Files/7-Zip/7z.exe" a ServerService.zip ./ServerService/* -tzip + &"C:/Program Files/7-Zip/7z.exe" a ServerConsole.zip ./ServerConsole/* -tzip + &"C:/Program Files/7-Zip/7z.exe" a ServerUpdatePackage.zip ./ServerUpdatePackage/* -tzip - - name: Create GitHub Release - uses: actions/create-release@v1 - id: create_release - env: - GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} - with: - tag_name: tgstation-server-v${{ env.TGS_VERSION }} - release_name: tgstation-server-v${{ env.TGS_VERSION }} - body_path: release_notes.md - commitish: ${{ github.event.head_commit.id }} + - name: Generate Release Notes + run: dotnet run -c Release --project tools/ReleaseNotes ${{ env.TGS_VERSION }} - - name: Upload Server Console Artifact - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./ServerConsole.zip - asset_name: ServerConsole.zip - asset_content_type: application/zip + - name: Create GitHub Release + uses: actions/create-release@v1 + id: create_release + env: + GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} + with: + tag_name: tgstation-server-v${{ env.TGS_VERSION }} + release_name: tgstation-server-v${{ env.TGS_VERSION }} + body_path: release_notes.md + commitish: ${{ github.event.head_commit.id }} - - name: Upload Server Service Artifact - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./ServerService.zip - asset_name: ServerService.zip - asset_content_type: application/zip + - name: Upload Server Console Artifact + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./ServerConsole.zip + asset_name: ServerConsole.zip + asset_content_type: application/zip - - name: Upload DMAPI Artifact - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./DMAPI.zip - asset_name: DMAPI.zip - asset_content_type: application/zip + - name: Upload Server Service Artifact + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./ServerService.zip + asset_name: ServerService.zip + asset_content_type: application/zip - - name: Upload OpenApi Spec Artifact - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./swagger/swagger.json - asset_name: swagger.json - asset_content_type: application/json + - name: Upload DMAPI Artifact + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./DMAPI.zip + asset_name: DMAPI.zip + asset_content_type: application/zip - - name: Upload Server Update Package Artifact - uses: actions/upload-release-asset@v1 - env: - GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./ServerUpdatePackage.zip - asset_name: ServerUpdatePackage.zip - asset_content_type: application/zip + - name: Upload OpenApi Spec Artifact + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./swagger/swagger.json + asset_name: swagger.json + asset_content_type: application/json + + - name: Upload Server Update Package Artifact + uses: actions/upload-release-asset@v1 + env: + GITHUB_TOKEN: ${{ secrets.DEV_PUSH_TOKEN }} + with: + upload_url: ${{ steps.create_release.outputs.upload_url }} + asset_path: ./ServerUpdatePackage.zip + asset_name: ServerUpdatePackage.zip + asset_content_type: application/zip deploy-docker: name: Deploy TGS (Docker) needs: [deploy-tgs] runs-on: ubuntu-latest steps: - - name: Checkout - uses: actions/checkout@v3 + - name: Checkout (Branch Push) + uses: actions/checkout@v3 + if: github.event_name == 'push' - - name: Parse TGS version - run: | - sudo apt-get update - sudo apt-get install -y xmlstarlet - echo "TGS_VERSION=$(xmlstarlet sel -N X="http://schemas.microsoft.com/developer/msbuild/2003" --template --value-of /X:Project/X:PropertyGroup/X:TgsCoreVersion build/Version.props)" >> $GITHUB_ENV + - name: Checkout (PR Merge) + uses: actions/checkout@v3 + if: github.event_name != 'push' + with: + ref: "refs/pull/${{ github.event.number }}/merge" - - name: Docker Build and Push - uses: elgohr/Publish-Docker-Github-Action@v5 - with: - name: tgstation/server - username: ${{ secrets.DOCKER_USERNAME }} - password: ${{ secrets.DOCKER_PASSWORD }} - dockerfile: build/Dockerfile - tags: "latest,v${{ env.TGS_VERSION }}" + - name: Parse TGS version + run: | + sudo apt-get update + sudo apt-get install -y xmlstarlet + echo "TGS_VERSION=$(xmlstarlet sel -N X="http://schemas.microsoft.com/developer/msbuild/2003" --template --value-of /X:Project/X:PropertyGroup/X:TgsCoreVersion build/Version.props)" >> $GITHUB_ENV + + - name: Docker Build and Push + uses: elgohr/Publish-Docker-Github-Action@v5 + with: + name: tgstation/server + username: ${{ secrets.DOCKER_USERNAME }} + password: ${{ secrets.DOCKER_PASSWORD }} + dockerfile: build/Dockerfile + tags: "latest,v${{ env.TGS_VERSION }}"