From b7b00fd702ded8c8390755fe21f5d96a160158d8 Mon Sep 17 00:00:00 2001 From: Ian Lewis Date: Fri, 30 Jan 2026 08:15:46 +0000 Subject: [PATCH 1/7] ci: add Docker build workflows Signed-off-by: Ian Lewis --- .github/workflows/pull_request.build.yml | 68 +++++++++++++++++++++++ .github/workflows/release.publish.yml | 71 ++++++++++++++++++++++++ Dockerfile | 2 +- 3 files changed, 140 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/pull_request.build.yml create mode 100644 .github/workflows/release.publish.yml diff --git a/.github/workflows/pull_request.build.yml b/.github/workflows/pull_request.build.yml new file mode 100644 index 0000000..caff8ab --- /dev/null +++ b/.github/workflows/pull_request.build.yml @@ -0,0 +1,68 @@ +# Copyright 2026 Preferred Networks, Inc. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +name: Docker Build + +on: + push: + branches: ["main"] + pull_request: + branches: ["main"] + workflow_call: + workflow_dispatch: + +permissions: {} + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +env: + IMAGE_REGISTRY: ghcr.io + IMAGE_NAME: ${{ github.repository }} + +jobs: + # This step builds our image. + docker-build: + name: Build Docker Image + permissions: + contents: read # for checking out the repo. + packages: write # for pushing the image to the registry. + runs-on: ubuntu-latest + steps: + - name: Checkout the repository + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 + with: + persist-credentials: false + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1 + + - name: Extract metadata (tags, labels) for Docker + id: meta + uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0 + with: + images: ${{ env.IMAGE_REGISTRY }}/${{ env.IMAGE_NAME }} + + - name: Build and push Docker image + uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0 + id: build + with: + # Use the existing directory as the build context + # (default is to re-check out the git repo). + context: . + push: false + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + platforms: linux/amd64 diff --git a/.github/workflows/release.publish.yml b/.github/workflows/release.publish.yml new file mode 100644 index 0000000..5c97481 --- /dev/null +++ b/.github/workflows/release.publish.yml @@ -0,0 +1,71 @@ +# Copyright 2026 Preferred Networks, Inc. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +name: Release + +on: + release: + types: [published] + +permissions: {} + +concurrency: + group: production + cancel-in-progress: true + +env: + IMAGE_REGISTRY: ghcr.io + IMAGE_NAME: ${{ github.repository }} + +jobs: + # This step builds our image and pushes it. + docker-build: + name: Build and Push Docker Image + permissions: + contents: read # for checking out the repo. + packages: write # for pushing the image to the registry. + runs-on: ubuntu-latest + steps: + - name: Checkout the repository + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 + with: + persist-credentials: false + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1 + + - name: Authenticate Docker + uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0 + with: + registry: ${{ env.IMAGE_REGISTRY }} + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Extract metadata (tags, labels) for Docker + id: meta + uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0 + with: + images: ${{ env.IMAGE_REGISTRY }}/${{ env.IMAGE_NAME }} + + - name: Build and push Docker image + uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0 + id: build + with: + # Use the existing directory as the build context + # (default is to re-check out the git repo). + context: . + push: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + platforms: linux/amd64 diff --git a/Dockerfile b/Dockerfile index 76b584e..569f3d9 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM golang:1.24 AS builder +FROM golang:1.25 AS builder ARG BUILD_VERSION=dev ARG BUILD_COMMIT=unknown From fbb1c01cb135d2b4be20ee1ff2640e6df5fd6ca3 Mon Sep 17 00:00:00 2001 From: Ian Lewis Date: Fri, 30 Jan 2026 08:32:05 +0000 Subject: [PATCH 2/7] docs: add release workflow docs Signed-off-by: Ian Lewis --- .github/workflows/release.publish.yml | 33 +++++++++++++++++++++++++-- RELEASE.md | 31 +++++++++++++++++++++++++ 2 files changed, 62 insertions(+), 2 deletions(-) create mode 100644 RELEASE.md diff --git a/.github/workflows/release.publish.yml b/.github/workflows/release.publish.yml index 5c97481..b94ee8c 100644 --- a/.github/workflows/release.publish.yml +++ b/.github/workflows/release.publish.yml @@ -15,8 +15,9 @@ name: Release on: - release: - types: [published] + push: + tags: + - "v*.*.*" # Semver tags like v1.2.3 permissions: {} @@ -69,3 +70,31 @@ jobs: tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} platforms: linux/amd64 + + build-binaries: + name: Build Release Binaries + runs-on: ubuntu-latest + steps: + - name: Checkout the repository + uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 + with: + persist-credentials: false + + - uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0 + with: + go-version-file: "go.mod" + + - name: run tests + run: make test + + - name: Build binary + run: make build + + - name: Upload binary + uses: softprops/action-gh-release@a06a81a03ee405af7f2048a818ed3f03bbf83c7b # v2.5.0 + with: + # Create a draft release to allow uploading assets and editing of + # release notes before publishing. + draft: true + files: | + ns-reloader-linux-amd64 diff --git a/RELEASE.md b/RELEASE.md new file mode 100644 index 0000000..4c2e17c --- /dev/null +++ b/RELEASE.md @@ -0,0 +1,31 @@ +# Release workflow + +To use GitHub's [immutable +releases](https://docs.github.com/en/code-security/concepts/supply-chain-security/immutable-releases) +the following release workflow is used. + +## Update `CHANGELOG.md` + +Before the release, ensure that `CHANGELOG.md` is updated with and relevant +changes for the new version. + +## Create and push a new tag + +```shell +git tag vX.Y.Z +git push origin vX.Y.Z +``` + +This will trigger a release workflow that builds the binaries and Docker images, +and creates a new draft GitHub Release with the built artifacts attached. + +## Edit the draft release + +Update the description of the created release. Reference the `CHANGELOG.md` for +user facing changes. + +## Publish the release + +**Warning:** the release is immutable and cannot be changed after publishing!! + +Once the draft release is ready, publish it to make it publicly available. From b55c3485c4a7c05ff2b91f0da08b5c48c67d788c Mon Sep 17 00:00:00 2001 From: Ian Lewis Date: Mon, 2 Feb 2026 04:43:38 +0000 Subject: [PATCH 3/7] chore: build as a static binary Signed-off-by: Ian Lewis --- Makefile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Makefile b/Makefile index 9384c02..83da445 100644 --- a/Makefile +++ b/Makefile @@ -50,7 +50,7 @@ all: test build docker-build ## Run tests and build. .PHONY: build build: ## Build binary. - @go build -o build/ns-reloader . + @CGO_ENABLED=0 GOOS=linux go build -o build/ns-reloader-$(kernel)-$(arch) . .PHONY: test test: lint unit-test ## Run tests. From 5d27f9fe495b3dce5be1366120a205f68fd38b0a Mon Sep 17 00:00:00 2001 From: Ian Lewis Date: Mon, 2 Feb 2026 04:52:51 +0000 Subject: [PATCH 4/7] fix: upload correct binary path Signed-off-by: Ian Lewis --- .github/workflows/release.publish.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release.publish.yml b/.github/workflows/release.publish.yml index b94ee8c..9199a4e 100644 --- a/.github/workflows/release.publish.yml +++ b/.github/workflows/release.publish.yml @@ -97,4 +97,4 @@ jobs: # release notes before publishing. draft: true files: | - ns-reloader-linux-amd64 + build/ns-reloader-linux-amd64 From 478613a479af68d44fe9c3cb2ded4343fd0ebc2d Mon Sep 17 00:00:00 2001 From: Ian Lewis Date: Mon, 2 Feb 2026 04:59:10 +0000 Subject: [PATCH 5/7] chore: typo Signed-off-by: Ian Lewis --- RELEASE.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/RELEASE.md b/RELEASE.md index 4c2e17c..8f74837 100644 --- a/RELEASE.md +++ b/RELEASE.md @@ -6,7 +6,7 @@ the following release workflow is used. ## Update `CHANGELOG.md` -Before the release, ensure that `CHANGELOG.md` is updated with and relevant +Before the release, ensure that `CHANGELOG.md` is updated with all relevant changes for the new version. ## Create and push a new tag From a869aafa838a2e373e2f7a50b92e323cc9b5985a Mon Sep 17 00:00:00 2001 From: Ian Lewis Date: Tue, 3 Feb 2026 08:28:19 +0000 Subject: [PATCH 6/7] chore: remove release binaries Signed-off-by: Ian Lewis --- .github/workflows/release.publish.yml | 33 ++------------------------- RELEASE.md | 31 ------------------------- 2 files changed, 2 insertions(+), 62 deletions(-) delete mode 100644 RELEASE.md diff --git a/.github/workflows/release.publish.yml b/.github/workflows/release.publish.yml index 9199a4e..5c97481 100644 --- a/.github/workflows/release.publish.yml +++ b/.github/workflows/release.publish.yml @@ -15,9 +15,8 @@ name: Release on: - push: - tags: - - "v*.*.*" # Semver tags like v1.2.3 + release: + types: [published] permissions: {} @@ -70,31 +69,3 @@ jobs: tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} platforms: linux/amd64 - - build-binaries: - name: Build Release Binaries - runs-on: ubuntu-latest - steps: - - name: Checkout the repository - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 - with: - persist-credentials: false - - - uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0 - with: - go-version-file: "go.mod" - - - name: run tests - run: make test - - - name: Build binary - run: make build - - - name: Upload binary - uses: softprops/action-gh-release@a06a81a03ee405af7f2048a818ed3f03bbf83c7b # v2.5.0 - with: - # Create a draft release to allow uploading assets and editing of - # release notes before publishing. - draft: true - files: | - build/ns-reloader-linux-amd64 diff --git a/RELEASE.md b/RELEASE.md deleted file mode 100644 index 8f74837..0000000 --- a/RELEASE.md +++ /dev/null @@ -1,31 +0,0 @@ -# Release workflow - -To use GitHub's [immutable -releases](https://docs.github.com/en/code-security/concepts/supply-chain-security/immutable-releases) -the following release workflow is used. - -## Update `CHANGELOG.md` - -Before the release, ensure that `CHANGELOG.md` is updated with all relevant -changes for the new version. - -## Create and push a new tag - -```shell -git tag vX.Y.Z -git push origin vX.Y.Z -``` - -This will trigger a release workflow that builds the binaries and Docker images, -and creates a new draft GitHub Release with the built artifacts attached. - -## Edit the draft release - -Update the description of the created release. Reference the `CHANGELOG.md` for -user facing changes. - -## Publish the release - -**Warning:** the release is immutable and cannot be changed after publishing!! - -Once the draft release is ready, publish it to make it publicly available. From 4d615081503149a00131d8da32ecef2ac63c1ef3 Mon Sep 17 00:00:00 2001 From: Ian Lewis Date: Tue, 3 Feb 2026 08:31:04 +0000 Subject: [PATCH 7/7] chore: remove package permissions for test Signed-off-by: Ian Lewis --- .github/workflows/pull_request.build.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/pull_request.build.yml b/.github/workflows/pull_request.build.yml index caff8ab..df25d3d 100644 --- a/.github/workflows/pull_request.build.yml +++ b/.github/workflows/pull_request.build.yml @@ -38,7 +38,6 @@ jobs: name: Build Docker Image permissions: contents: read # for checking out the repo. - packages: write # for pushing the image to the registry. runs-on: ubuntu-latest steps: - name: Checkout the repository