diff --git a/flake.nix b/flake.nix index ace814c..a4e5e1f 100644 --- a/flake.nix +++ b/flake.nix @@ -109,15 +109,17 @@ name = "bunshin"; }; - # Builds packages.static and uploads it to this repo owner's - # Forgejo generic package registry, tagged by short commit hash. - # Needs FORGEJO_TOKEN (a token with write:package scope) in the - # environment; run from a checkout so `git rev-parse` and the `.` - # flake ref resolve to the right place. + # Builds packages.static and publishes it as a Forgejo release on + # this repo, tagged by short commit hash (creating the release if + # it doesn't exist yet, replacing the asset if it does — safe to + # rerun for the same commit). Needs FORGEJO_TOKEN (a token with + # write:repository scope) in the environment; run from a checkout + # so `git rev-parse` and the `.` flake ref resolve to the right + # place. apps.release-static = flake-utils.lib.mkApp { drv = pkgs.writeShellApplication { name = "bunshin-release-static"; - runtimeInputs = [ pkgs.nix pkgs.curl pkgs.git ]; + runtimeInputs = [ pkgs.nix pkgs.curl pkgs.git pkgs.jq ]; text = '' if [ -f .env ]; then set -a @@ -125,12 +127,31 @@ . ./.env set +a fi + : "''${FORGEJO_TOKEN:?set FORGEJO_TOKEN (env or .env) to a Forgejo token with write:repository scope}" + rev=$(git rev-parse --short HEAD) + sha=$(git rev-parse HEAD) out=$(nix build .#static --no-link --print-out-paths) - : "''${FORGEJO_TOKEN:?set FORGEJO_TOKEN (env or .env) to a Forgejo token with write:package scope}" - url="https://code.randogoth.com/api/packages/randogoth/generic/bunshin/$rev/bunshin" - curl -sSf -H "Authorization: token ''${FORGEJO_TOKEN}" --upload-file "$out/bin/bunshin" "$url" - echo "uploaded: $url" + bin="$out/bin/bunshin" + + api="https://code.randogoth.com/api/v1/repos/randogoth/bunshin" + auth=(-H "Authorization: token ''${FORGEJO_TOKEN}") + + release_id=$(curl -sS "''${auth[@]}" "$api/releases/tags/$rev" | jq -r '.id // empty') + if [ -z "$release_id" ]; then + release_id=$(curl -sSf "''${auth[@]}" -H "Content-Type: application/json" \ + -d "$(jq -n --arg tag "$rev" --arg sha "$sha" \ + '{tag_name:$tag, target_commitish:$sha, name:$tag, body:"Static musl build.", draft:false, prerelease:false}')" \ + "$api/releases" | jq -r '.id') + fi + + asset_id=$(curl -sSf "''${auth[@]}" "$api/releases/$release_id/assets" | jq -r '.[] | select(.name=="bunshin") | .id' | head -1) + if [ -n "$asset_id" ]; then + curl -sSf -X DELETE "''${auth[@]}" "$api/releases/$release_id/assets/$asset_id" >/dev/null + fi + curl -sSf "''${auth[@]}" -F "attachment=@$bin;filename=bunshin" "$api/releases/$release_id/assets?name=bunshin" >/dev/null + + echo "released: https://code.randogoth.com/randogoth/bunshin/releases/tag/$rev" ''; }; }; @@ -151,7 +172,7 @@ package = mkOption { type = types.package; - default = self.packages.${pkgs.system}.default; + default = self.packages.${pkgs.stdenv.hostPlatform.system}.default; description = '' bunshin package to run. Use `packages.rns` when the RNS carrier is enabled: the default package is built without it.