penpot/.github/workflows/build-bundle.yml
David Barragán Merino 86fc3dd765 👷 Pass explicit secrets to reusable workflows
Replace secrets: inherit with the secrets each reusable workflow
actually uses, and declare them under on.workflow_call.secrets in the
called workflow. Declared as required: false so behaviour is unchanged
if a secret is missing.

Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
2026-09-30 17:01:58 +02:00

205 lines
7.4 KiB
YAML

name: Bundles Builder
on:
# Create bundle from manual action
workflow_dispatch:
inputs:
gh_ref:
description: 'Name of the branch or ref'
type: string
required: true
default: 'develop'
force:
description: 'Rebuild and overwrite even if this version already exists in S3'
type: boolean
required: false
default: false
workflow_call:
inputs:
gh_ref:
description: 'Name of the branch or ref'
type: string
required: true
force:
description: 'Rebuild and overwrite even if this version already exists in S3'
type: boolean
required: false
default: false
outputs:
sha:
description: 'Bundled commit, full 40-char SHA.'
value: ${{ jobs.check.outputs.sha }}
secrets:
AWS_ACCESS_KEY_ID:
required: false
AWS_REGION:
required: false
AWS_SECRET_ACCESS_KEY:
required: false
MATTERMOST_WEBHOOK:
required: false
S3_BUCKET:
required: false
# Literal group name: under `workflow_call`, `github.workflow` resolves to the
# caller's workflow, which put this workflow and the other reusable one called
# by the same caller into a single shared group, and left a manual dispatch of
# the same ref in a group of its own, free to race on the same artifacts.
concurrency:
group: build-bundle-${{ inputs.gh_ref }}
cancel-in-progress: true
jobs:
# ── 1. Decide whether there is anything to build ───────────────────────
check:
name: Check current bundle
runs-on: penpot-standar-runner
timeout-minutes: 10
outputs:
gh_ref: ${{ steps.vars.outputs.gh_ref }}
bundle_version: ${{ steps.vars.outputs.bundle_version }}
short_sha: ${{ steps.vars.outputs.short_sha }}
sha: ${{ steps.vars.outputs.sha }}
commit_title: ${{ steps.vars.outputs.commit_title }}
exists: ${{ steps.check.outputs.exists }}
steps:
- name: Checkout repository
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
persist-credentials: false
fetch-depth: 0
ref: ${{ inputs.gh_ref }}
- name: Extract some useful variables
id: vars
env:
GH_REF: ${{ inputs.gh_ref || github.ref_name }}
run: |
echo "gh_ref=$GH_REF" >> $GITHUB_OUTPUT
echo "bundle_version=$(git describe --tags --always)" >> $GITHUB_OUTPUT
echo "short_sha=$(git rev-parse --short=12 HEAD)" >> $GITHUB_OUTPUT
echo "sha=$(git rev-parse HEAD)" >> $GITHUB_OUTPUT
echo "commit_title=$(git log -1 --pretty=%s)" >> $GITHUB_OUTPUT
# Keyed by commit sha, same as build-docker.yml's marker check, so
# both pipelines agree on what "already built" means: any ref that
# points at an already-bundled commit skips the build, regardless of
# which ref built it first. `force` bypasses this check entirely.
- name: Check if this bundle is already built
id: check
env:
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: ${{ secrets.AWS_REGION }}
S3_BUCKET: ${{ secrets.S3_BUCKET }}
FORCE: ${{ inputs.force }}
SHORT_SHA: ${{ steps.vars.outputs.short_sha }}
BUNDLE_VERSION: ${{ steps.vars.outputs.bundle_version }}
run: |
if [ "$FORCE" = "true" ]; then
echo "exists=false" >> $GITHUB_OUTPUT
{
echo "### 🔁 Bundle build forced"
echo ""
echo "\`force: true\` — skipping the S3 sha check."
} >> "$GITHUB_STEP_SUMMARY"
exit 0
fi
BUNDLE_EXISTS=$(aws s3api head-object \
--bucket "$S3_BUCKET" \
--key "penpot-sha-${SHORT_SHA}.zip" \
> /dev/null 2>&1 && echo "true" || echo "false")
if [ "$BUNDLE_EXISTS" = "true" ]; then
echo "exists=true" >> $GITHUB_OUTPUT
{
echo "### ⏭️ Bundle build skipped"
echo ""
echo "The bundle in S3 was already built from \`sha-${SHORT_SHA}\` (\`${BUNDLE_VERSION}\`)."
} >> "$GITHUB_STEP_SUMMARY"
else
echo "exists=false" >> $GITHUB_OUTPUT
fi
# ── 2. Build and upload, only when needed ──────────────────────────────
build:
name: Build and Upload Penpot Bundle
runs-on: penpot-standar-runner
timeout-minutes: 90
needs: check
if: needs.check.outputs.exists == 'false'
steps:
- name: Checkout repository
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
persist-credentials: false
fetch-depth: 0
ref: ${{ inputs.gh_ref }}
- name: Build bundle
env:
BUILD_WASM: 'yes'
BUILD_STORYBOOK: 'yes'
run: ./manage.sh build-bundle
- name: Prepare directories for zipping
run: |
mkdir zips
mv bundles penpot
- name: Create zip bundle
run: |
echo "📦 Packaging Penpot bundle..."
zip -r zips/penpot.zip penpot
- name: Upload Penpot bundle to S3
env:
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: ${{ secrets.AWS_REGION }}
S3_BUCKET: ${{ secrets.S3_BUCKET }}
SHORT_SHA: ${{ needs.check.outputs.short_sha }}
BUNDLE_VERSION: ${{ needs.check.outputs.bundle_version }}
run: |
aws s3 cp zips/penpot.zip \
"s3://${S3_BUCKET}/penpot-sha-${SHORT_SHA}.zip" \
--metadata "bundle-version=${BUNDLE_VERSION}"
- name: Write step summary
env:
SHORT_SHA: ${{ needs.check.outputs.short_sha }}
BUNDLE_VERSION: ${{ needs.check.outputs.bundle_version }}
COMMIT_TITLE: ${{ needs.check.outputs.commit_title }}
run: |
{
echo "### ✅ Bundle built"
echo ""
echo "- Version: \`${BUNDLE_VERSION}\` (\`git describe --tags --always\`)"
echo "- Commit: [\`${SHORT_SHA}\`](${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/commit/${SHORT_SHA}) — ${COMMIT_TITLE}"
echo "- Built at: $(date -u +'%Y-%m-%d %H:%M:%S UTC')"
} >> "$GITHUB_STEP_SUMMARY"
# ── 3. Single failure notification for the whole workflow ─────────────
notify:
name: Notify failure
runs-on: penpot-standar-runner
timeout-minutes: 5
needs: [check, build]
if: failure()
steps:
- name: Notify Mattermost
uses: mattermost/action-mattermost-notify@ae31bb6f9e26a54336e79696f108a2c91cf55b4e # v2.1.0
with:
MATTERMOST_WEBHOOK_URL: ${{ secrets.MATTERMOST_WEBHOOK }}
MATTERMOST_CHANNEL: bot-alerts-cicd
TEXT: |
❌ 📦 *[PENPOT] Error building penpot bundles.*
📄 Triggered from ref: `${{ needs.check.outputs.gh_ref || inputs.gh_ref }}`
Bundle version: `${{ needs.check.outputs.bundle_version || 'n/a' }}`
🔗 Run: https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}
@infra