Skip to content

e2e harness: write report+rsync on Ctrl-C, exclude heavy caches from … #30

e2e harness: write report+rsync on Ctrl-C, exclude heavy caches from …

e2e harness: write report+rsync on Ctrl-C, exclude heavy caches from … #30

Workflow file for this run

# This workflow is autogenerated by xcookie.
# File kind: release
# For more information see: https://help.github.com/actions/language-and-framework-guides/using-python-with-github-actions
# Based on ~/code/xcookie/xcookie/builders/github_actions.py
# See: https://github.com/Erotemic/xcookie
name: PurePyRelease
on:
push:
workflow_dispatch:
jobs:
build_sdist:
##
# Build the sdist artifact used by the release workflow.
# This workflow intentionally builds artifacts but does not run the
# full test matrix.
##
name: Build sdist
runs-on: ubuntu-latest
steps:
- name: Checkout source
uses: actions/checkout@v6.0.2
- name: Set up Python 3.14
uses: actions/setup-python@v6.2.0
with:
python-version: '3.14'
- name: Build sdist
shell: bash
run: |-
python -m pip install pip uv -U
python -m uv pip install setuptools>=0.8 wheel build twine
python -m build --sdist --outdir wheelhouse
python -m twine check ./wheelhouse/infer_stack*.tar.gz
- name: Show built files
shell: bash
run: ls -la wheelhouse
- uses: actions/upload-artifact@v6.0.0
name: Upload sdist artifact
with:
name: sdist_wheels
path: ./wheelhouse/infer_stack*.tar.gz
build_purepy_wheels:
##
# Build the pure-python wheels used by the release workflow.
##
name: ${{ matrix.python-version }} on ${{ matrix.os }}, arch=${{ matrix.arch }} with ${{ matrix.install-extras }}
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os:
- ubuntu-latest
python-version:
- '3.14'
arch:
- auto
steps:
- name: Checkout source
uses: actions/checkout@v6.0.2
- name: Setup Python
uses: actions/setup-python@v6.2.0
with:
python-version: ${{ matrix.python-version }}
- name: Build pure wheel
shell: bash
run: |-
python -m pip install pip uv -U
python -m uv pip install setuptools>=0.8 wheel build twine
python -m build --wheel --outdir wheelhouse
python -m twine check ./wheelhouse/infer_stack*.whl
- name: Show built files
shell: bash
run: ls -la wheelhouse
- uses: actions/upload-artifact@v6.0.0
name: Upload wheels artifact
with:
name: wheels-${{ matrix.os }}-${{ matrix.arch }}
path: ./wheelhouse/infer_stack*.whl
test_deploy:
name: Deploy Test
runs-on: ubuntu-latest
if: github.event_name == 'push' && github.event.ref == 'refs/heads/main'
needs:
- build_purepy_wheels
- build_sdist
steps:
- name: Checkout source
uses: actions/checkout@v6.0.2
- uses: actions/download-artifact@v7.0.0
name: Download wheels
with:
pattern: wheels-*
merge-multiple: true
path: wheelhouse
- uses: actions/download-artifact@v7.0.0
name: Download sdist
with:
name: sdist_wheels
path: wheelhouse
- name: Show files to upload
shell: bash
run: ls -la wheelhouse
- name: Prepare publish directory
shell: bash
run: |-
mkdir -p publish_wheelhouse
shopt -s nullglob
for FPATH in wheelhouse/*.whl wheelhouse/*.tar.gz wheelhouse/*.zip
do
cp "$FPATH" publish_wheelhouse/
done
ls -la publish_wheelhouse
- name: Publish test artifacts to TestPyPI
uses: pypa/gh-action-pypi-publish@release/v1
with:
packages-dir: publish_wheelhouse
skip-existing: true
repository-url: https://test.pypi.org/legacy/
- uses: actions/upload-artifact@v6.0.0
name: Upload deploy artifacts
with:
name: deploy_artifacts
path: |-
wheelhouse/*.whl
wheelhouse/*.zip
wheelhouse/*.tar.gz
permissions:
contents: read
id-token: write
environment: testpypi
live_deploy:
name: Deploy Live
runs-on: ubuntu-latest
if: github.event_name == 'push' && (startsWith(github.event.ref, 'refs/tags') || startsWith(github.event.ref, 'refs/heads/release'))
needs:
- build_purepy_wheels
- build_sdist
steps:
- name: Checkout source
uses: actions/checkout@v6.0.2
- uses: actions/download-artifact@v7.0.0
name: Download wheels
with:
pattern: wheels-*
merge-multiple: true
path: wheelhouse
- uses: actions/download-artifact@v7.0.0
name: Download sdist
with:
name: sdist_wheels
path: wheelhouse
- name: Show files to upload
shell: bash
run: ls -la wheelhouse
- name: Prepare publish directory
shell: bash
run: |-
mkdir -p publish_wheelhouse
shopt -s nullglob
for FPATH in wheelhouse/*.whl wheelhouse/*.tar.gz wheelhouse/*.zip
do
cp "$FPATH" publish_wheelhouse/
done
ls -la publish_wheelhouse
- name: Publish live artifacts to PyPI
uses: pypa/gh-action-pypi-publish@release/v1
with:
packages-dir: publish_wheelhouse
skip-existing: true
- uses: actions/upload-artifact@v6.0.0
name: Upload deploy artifacts
with:
name: deploy_artifacts
path: |-
wheelhouse/*.whl
wheelhouse/*.zip
wheelhouse/*.tar.gz
permissions:
contents: read
id-token: write
environment: pypi
release:
name: Create Github Release
if: github.event_name == 'push' && (startsWith(github.event.ref, 'refs/tags') || startsWith(github.event.ref, 'refs/heads/release'))
runs-on: ubuntu-latest
permissions:
contents: write
needs:
- live_deploy
steps:
- name: Checkout source
uses: actions/checkout@v6.0.2
- uses: actions/download-artifact@v7.0.0
name: Download artifacts
with:
name: deploy_artifacts
path: wheelhouse
- name: Show files to release
shell: bash
run: ls -la wheelhouse
- run: 'echo "Automatic Release Notes. TODO: improve" > ${{ github.workspace }}-CHANGELOG.txt'
- name: Tag Release Commit
if: (startsWith(github.event.ref, 'refs/heads/release'))
run: |-
export VERSION=$(python -c 'import ast, pathlib; tree = ast.parse(pathlib.Path('"'"'infer_stack/__init__.py'"'"').read_text()); print(next(ast.literal_eval(n.value) for n in tree.body if isinstance(n, ast.Assign) and any(getattr(t, "id", None) == "__version__" for t in n.targets)))')
git tag "v$VERSION"
git push origin "v$VERSION"
- uses: softprops/action-gh-release@v1
name: Create Release
id: create_release
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
body_path: ${{ github.workspace }}-CHANGELOG.txt
tag_name: ${{ github.ref }}
name: Release ${{ github.ref }}
body: Automatic Release
generate_release_notes: true
draft: true
prerelease: false
files: |-
wheelhouse/*.whl
wheelhouse/*.asc
wheelhouse/*.ots
wheelhouse/*.zip
wheelhouse/*.tar.gz
###
# Trusted publishing setup checklist
#
# This release workflow file:
# .github/workflows/release.yml
# Workflow page:
# github.com/AIQ-Kitware/infer_stack/actions/workflows/release.yml
# Workflow source:
# github.com/AIQ-Kitware/infer_stack/blob/main/.github/workflows/release.yml
# GitHub environments:
# github.com/AIQ-Kitware/infer_stack/settings/environments
#
# Official references:
# https://docs.pypi.org/trusted-publishers/
# https://docs.pypi.org/trusted-publishers/using-a-publisher/
# https://docs.pypi.org/trusted-publishers/security-model/
# https://docs.github.com/actions/deployment/security-hardening-your-deployments/about-security-hardening-with-openid-connect
# https://docs.github.com/actions/deployment/targeting-different-environments/using-environments-for-deployment
#
# If trusted publishing is not configured yet:
#
# 1. In GitHub, create or review these protected environments:
# - testpypi
# - pypi
# URL:
# github.com/AIQ-Kitware/infer_stack/settings/environments
#
# Some xcookie setups will expect a setup like:
#
# - testpypi:
# * environment name: testpypi
# * use for non-release pushes that publish to TestPyPI
# * usually no manual approval is needed
# * optionally restrict deployment branches if you only want
# TestPyPI publishes from selected branches
#
# - pypi:
# * environment name: pypi
# * use for real releases only
# * require manual approval / required reviewers
# * prevent self-review if your org supports it
# * restrict deployments to release branches / version tags
#
# - do not put TWINE_* secrets in these environments when using
# trusted publishing
#
# - if enable_gpg=true and ci_gpg_secret_transport=encrypted_repo:
# store CI_SECRET as an environment secret (not repo-wide)
# - if enable_gpg=true and ci_gpg_secret_transport=direct_ci:
# store GPG_SECRET_SIGNING_SUBKEY_B64, GPG_PUBLIC_KEY_B64, and
# GPG_OWNER_TRUST_B64 as environment secrets; no CI_SECRET needed
#
# 2. In PyPI, add a trusted publisher for this project:
# owner: AIQ-Kitware
# repository: infer_stack
# workflow filename: release.yml
# environment: pypi
# Project publishing page:
# https://pypi.org/manage/project/infer-stack/settings/publishing/
# Account publishing page:
# https://pypi.org/manage/account/publishing/
#
# 3. In TestPyPI, add a trusted publisher for this project:
# owner: AIQ-Kitware
# repository: infer_stack
# workflow filename: release.yml
# environment: testpypi
# Project publishing page:
# https://test.pypi.org/manage/project/infer-stack/settings/publishing/
# Account publishing page:
# https://test.pypi.org/manage/account/publishing/
#
# Notes:
# - Keep the workflow filename stable after registration.
# - The PyPI/TestPyPI project pages may not exist until the project
# exists there; use the account publishing pages for pending publishers.
# - Trusted publishing removes TWINE_* secrets.
# - When enable_gpg=true and ci_gpg_secret_transport="encrypted_repo":
# CI_SECRET is still required (environment-scoped to pypi/testpypi).
# - When enable_gpg=true and ci_gpg_secret_transport="direct_ci":
# GPG_SECRET_SIGNING_SUBKEY_B64, GPG_PUBLIC_KEY_B64, and GPG_OWNER_TRUST_B64
# are required (environment-scoped to pypi/testpypi). No CI_SECRET.