Skip to content

Release

Release #91

Workflow file for this run

name: Release
on:
# Releases can only be triggered via the action tab
workflow_dispatch:
permissions:
contents: read
env:
MAVEN_OPTS: -Dhttp.keepAlive=false -Dmaven.wagon.http.pool=false -Dmaven.wagon.http.retryhandler.count=5 -Dmaven.wagon.httpconnectionManager.ttlSeconds=240
# Cancel running jobs when a new push happens to the same branch as otherwise it will
# tie up too many resources without providing much value.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
prepare-release:
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
ref: main
- name: Set up JDK 8
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
with:
java-version: 8
distribution: zulu
- name: Setup git configuration
run: |
git config --global user.email "netty-project-bot@users.noreply.github.com"
git config --global user.name "Netty Project Bot"
- name: Install SSH key
uses: shimataro/ssh-key-action@87a8f067114a8ce263df83e9ed5c849953548bc3 # v2.8.1
with:
key: ${{ secrets.SSH_PRIVATE_KEY_PEM }}
known_hosts: ${{ secrets.SSH_KNOWN_HOSTS }}
# Cache .m2/repository
- uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
continue-on-error: true
with:
path: ~/.m2/repository
key: prepare-release-cache-m2-repository-${{ hashFiles('**/pom.xml') }}
restore-keys: |
prepare-release-cache-m2-repository-
- name: Prepare release with Maven
run: |
./mvnw -B --file pom.xml release:prepare -DpreparationGoals=clean -DskipTests=true
./mvnw clean
- name: Checkout tag
run: ./.github/scripts/release_checkout_tag.sh release.properties
- name: Upload workspace
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: prepare-release-workspace
path: |
${{ github.workspace }}/**
!${{ github.workspace }}/.git/config
include-hidden-files: true
stage-release-linux:
runs-on: ubuntu-latest
needs: prepare-release
permissions:
contents: write
strategy:
matrix:
include:
- setup: centos6-x86_64
docker-compose-build: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml build"
docker-compose-run: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml run stage-release"
- setup: debian7-x86_64
docker-compose-build: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml build"
docker-compose-run: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml run stage-release"
- setup: centos7-aarch64
docker-compose-build: "-f docker/docker-compose.centos-7.yaml build"
docker-compose-run: "-f docker/docker-compose.centos-7.yaml run cross-compile-aarch64-stage-release"
name: stage-release-${{ matrix.setup }}
steps:
- name: Download release-workspace
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: prepare-release-workspace
path: ./prepare-release-workspace/
- name: Adjust mvnw permissions
run: chmod 755 ./prepare-release-workspace/mvnw
- name: Set up JDK 8
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
with:
java-version: 8
distribution: zulu
- name: Setup git configuration
run: |
git config --global user.email "netty-project-bot@users.noreply.github.com"
git config --global user.name "Netty Project Bot"
- name: Install SSH key
uses: shimataro/ssh-key-action@87a8f067114a8ce263df83e9ed5c849953548bc3 # v2.8.1
with:
key: ${{ secrets.SSH_PRIVATE_KEY_PEM }}
known_hosts: ${{ secrets.SSH_KNOWN_HOSTS }}
# Cache .m2/repository
- uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
continue-on-error: true
with:
path: ~/.m2/repository
key: stage-release-linux-${{ matrix.setup }}-m2-repository-cache-${{ hashFiles('**/pom.xml') }}
restore-keys: |
stage-release-linux-${{ matrix.setup }}-m2-repository-cache-
- uses: s4u/maven-settings-action@7802f6aec16c9098b4798ad1f1d8ac75198194bd # v3.0.0
with:
servers: |
[{
"id": "central",
"username": "${{ secrets.MAVEN_CENTRAL_USERNAME }}",
"password": "${{ secrets.MAVEN_CENTRAL_PASSWORD }}"
}]
- name: Create local staging directory
run: mkdir -p ~/local-staging
- name: Extract OpenSSL version from pom.xml
working-directory: ./prepare-release-workspace/
run: echo "OPENSSL_VERSION=$(./mvnw -q -Dexpression=opensslVersion -DforceStdout -N help:evaluate --no-transfer-progress)" >> $GITHUB_ENV
- name: Extract OpenSSL SHA256 from pom.xml
working-directory: ./prepare-release-workspace/
run: echo "OPENSSL_SHA256=$(./mvnw -q -Dexpression=opensslSha256 -DforceStdout -N help:evaluate --no-transfer-progress)" >> $GITHUB_ENV
# Release builds intentionally use docker compose (not buildx bake) for a clean,
# cache-free build. OPENSSL_VERSION is still extracted above so docker-compose can
# interpolate it as a build arg.
- name: Build docker image
working-directory: ./prepare-release-workspace/
run: docker compose ${{ matrix.docker-compose-build }}
- name: Stage release to local staging directory
working-directory: ./prepare-release-workspace/
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
GPG_KEYNAME: ${{ secrets.GPG_KEYNAME }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: docker compose ${{ matrix.docker-compose-run }}
- name: Upload local staging directory
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: ${{ matrix.setup }}-local-staging
path: ./prepare-release-workspace/target/central-staging
if-no-files-found: error
include-hidden-files: true
- name: Rollback release on failure
working-directory: ./prepare-release-workspace/
if: ${{ failure() }}
# Rollback the release in case of an failure
run: bash ./.github/scripts/release_rollback.sh release.properties netty/netty-tcnative main
stage-release-windows-x86_64:
runs-on: windows-2022
name: stage-release-windows-x86_64
needs: prepare-release
permissions:
contents: write
steps:
- name: Download release-workspace
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: prepare-release-workspace
path: prepare-release-workspace
- name: Setup git configuration
run: |
git config --global user.email "netty-project-bot@users.noreply.github.com"
git config --global user.name "Netty Project Bot"
- name: Install SSH key
uses: shimataro/ssh-key-action@87a8f067114a8ce263df83e9ed5c849953548bc3 # v2.8.1
with:
key: ${{ secrets.SSH_PRIVATE_KEY_PEM }}
known_hosts: ${{ secrets.SSH_KNOWN_HOSTS }}
- name: Set up JDK 8
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
with:
java-version: 8
distribution: zulu
- name: Add msbuild to PATH
uses: microsoft/setup-msbuild@6fb02220983dee41ce7ae257b6f4d8f9bf5ed4ce # v2.0.0
- name: Configuring Developer Command Prompt
uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0
with:
arch: x86_amd64
- name: Import GPG key
id: import_gpg
uses: crazy-max/ghaction-import-gpg@e89d40939c28e39f97cf32126055eeae86ba74ec # v6.3.0
with:
gpg_private_key: ${{ secrets.GPG_PRIVATE_KEY }}
passphrase: ${{ secrets.GPG_PASSPHRASE }}
- name: Install tools
uses: crazy-max/ghaction-chocolatey@2526f467ccbd337d307fe179959cabbeca0bc8c0 # v3.4.0
with:
args: install ninja nasm
# Cache .m2/repository
- uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
continue-on-error: true
with:
path: ~/.m2/repository
key: staging-release-cache-windows-m2-repository-${{ hashFiles('**/pom.xml') }}
restore-keys: |
staging-release-cache-windows-m2-repository-
- uses: s4u/maven-settings-action@7802f6aec16c9098b4798ad1f1d8ac75198194bd # v3.0.0
with:
servers: |
[{
"id": "central",
"username": "${{ secrets.MAVEN_CENTRAL_USERNAME }}",
"password": "${{ secrets.MAVEN_CENTRAL_PASSWORD }}"
}]
- name: Stage release to local staging directory
working-directory: prepare-release-workspace
run: ./mvnw --file pom.xml -Pstage -am -pl boringssl-static clean javadoc:jar package gpg:sign org.sonatype.central:central-publishing-maven-plugin:publish -DskipTests=true -D'checkstyle.skip=true'
- name: Upload local staging directory
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: windows-x86_64-local-staging
path: ./prepare-release-workspace/target/central-staging
if-no-files-found: error
include-hidden-files: true
- name: Rollback release on failure
working-directory: prepare-release-workspace
if: ${{ failure() }}
# Rollback the release in case of an failure
run: ./.github/scripts/release_rollback.ps1 release.properties netty/netty-tcnative main
stage-release-macos:
needs: prepare-release
permissions:
contents: write
strategy:
fail-fast: false
matrix:
include:
- setup: macos-x86_64
os: macos-15-intel
- setup: macos-aarch64
os: macos-15
runs-on: ${{ matrix.os }}
name: stage-release-${{ matrix.setup }}
steps:
- name: Download release-workspace
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: prepare-release-workspace
path: ./prepare-release-workspace/
- name: Adjust mvnw permissions
run: chmod 755 ./prepare-release-workspace/mvnw
- name: Set up JDK 8
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
with:
distribution: 'zulu'
java-version: '8'
- name: Import GPG key
id: import_gpg
uses: crazy-max/ghaction-import-gpg@e89d40939c28e39f97cf32126055eeae86ba74ec # v6.3.0
with:
gpg_private_key: ${{ secrets.GPG_PRIVATE_KEY }}
passphrase: ${{ secrets.GPG_PASSPHRASE }}
- name: Setup git configuration
run: |
git config --global user.email "netty-project-bot@users.noreply.github.com"
git config --global user.name "Netty Project Bot"
- name: Install SSH key
uses: shimataro/ssh-key-action@87a8f067114a8ce263df83e9ed5c849953548bc3 # v2.8.1
with:
key: ${{ secrets.SSH_PRIVATE_KEY_PEM }}
known_hosts: ${{ secrets.SSH_KNOWN_HOSTS }}
- uses: s4u/maven-settings-action@7802f6aec16c9098b4798ad1f1d8ac75198194bd # v3.0.0
with:
servers: |
[{
"id": "central",
"username": "${{ secrets.MAVEN_CENTRAL_USERNAME }}",
"password": "${{ secrets.MAVEN_CENTRAL_PASSWORD }}"
}]
# Cache .m2/repository
# Caching of maven dependencies
- uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
continue-on-error: true
with:
path: ~/.m2/repository
key: pr-${{ matrix.setup }}-maven-cache-${{ hashFiles('**/pom.xml') }}
restore-keys: |
pr-${{ matrix.setup }}-maven-cache-
- name: Install tools via brew
working-directory: ./prepare-release-workspace/
run: brew bundle
- name: Create local staging directory
run: mkdir -p ~/local-staging
- name: Stage snapshots to local staging directory
working-directory: ./prepare-release-workspace/
run: ./mvnw -B -ntp -am -pl openssl-dynamic,boringssl-static clean javadoc:jar package gpg:sign org.sonatype.central:central-publishing-maven-plugin:publish -DskipTests=true
- name: Upload local staging directory
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: ${{ matrix.setup }}-local-staging
path: ./prepare-release-workspace/target/central-staging
if-no-files-found: error
include-hidden-files: true
- name: Rollback release on failure
working-directory: ./prepare-release-workspace/
if: ${{ failure() }}
# Rollback the release in case of an failure
run: bash ./.github/scripts/release_rollback.sh release.properties netty/netty-tcnative main
deploy-staged-release:
runs-on: ubuntu-latest
# Wait until we have staged everything
needs: [stage-release-linux, stage-release-windows-x86_64, stage-release-macos]
permissions:
contents: write
steps:
- name: Download release-workspace
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: prepare-release-workspace
path: ./prepare-release-workspace/
- name: Adjust mvnw permissions
run: chmod 755 ./prepare-release-workspace/mvnw
- name: Set up JDK 8
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
with:
java-version: 8
distribution: zulu
- name: Import GPG key
id: import_gpg
uses: crazy-max/ghaction-import-gpg@e89d40939c28e39f97cf32126055eeae86ba74ec # v6.3.0
with:
gpg_private_key: ${{ secrets.GPG_PRIVATE_KEY }}
passphrase: ${{ secrets.GPG_PASSPHRASE }}
- name: Setup git configuration
run: |
git config --global user.email "netty-project-bot@users.noreply.github.com"
git config --global user.name "Netty Project Bot"
- name: Install SSH key
uses: shimataro/ssh-key-action@87a8f067114a8ce263df83e9ed5c849953548bc3 # v2.8.1
with:
key: ${{ secrets.SSH_PRIVATE_KEY_PEM }}
known_hosts: ${{ secrets.SSH_KNOWN_HOSTS }}
# Cache .m2/repository
- uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
continue-on-error: true
with:
path: ~/.m2/repository
key: deploy-staged-release-cache-m2-repository-${{ hashFiles('**/pom.xml') }}
restore-keys: |
deploy-staged-release-cache-m2-repository-
- uses: s4u/maven-settings-action@7802f6aec16c9098b4798ad1f1d8ac75198194bd # v3.0.0
with:
servers: |
[{
"id": "central",
"username": "${{ secrets.MAVEN_CENTRAL_USERNAME }}",
"password": "${{ secrets.MAVEN_CENTRAL_PASSWORD }}"
}]
# Hardcode the staging artifacts that need to be downloaded.
# These must match the matrix setups. There is currently no way to pull this out of the config.
- name: Download windows-x86_64 staging directory
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: windows-x86_64-local-staging
path: ~/windows-x86_64-local-staging
- name: Download macos-aarch64 staging directory
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: macos-aarch64-local-staging
path: ~/macos-aarch64-local-staging
- name: Download macos-x86_64 staging directory
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: macos-x86_64-local-staging
path: ~/macos-x86_64-local-staging
- name: Download centos7-aarch64 staging directory
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: centos7-aarch64-local-staging
path: ~/centos7-aarch64-local-staging
- name: Download debian7-x86_64 staging directory
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: debian7-x86_64-local-staging
path: ~/debian7-x86_64-local-staging
- name: Download centos6-x86_64 staging directory
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: centos6-x86_64-local-staging
path: ~/centos6-x86_64-local-staging
- name: Copy previous build artifacts to local maven repository
working-directory: ./prepare-release-workspace/
run: bash ./.github/scripts/local_staging_install_release.sh ~/.m2/repository ~/windows-x86_64-local-staging ~/macos-aarch64-local-staging ~/macos-x86_64-local-staging ~/centos7-aarch64-local-staging ~/debian7-x86_64-local-staging ~/centos6-x86_64-local-staging
- name: Generate uber jar and deploy to local staging.
working-directory: ./prepare-release-workspace/
run: ./mvnw -B --file pom.xml -Puber-staging -pl boringssl-static clean package gpg:sign org.sonatype.central:central-publishing-maven-plugin:publish -DskipTests=true
# This step takes care of merging all the previous staged repositories in a way that will allow us to deploy
# all together with one maven command.
- name: Merge staging repositories
working-directory: ./prepare-release-workspace/
run: bash ./.github/scripts/local_staging_merge_release.sh ~/local-staging ~/windows-x86_64-local-staging ~/macos-aarch64-local-staging ~/macos-x86_64-local-staging ~/centos7-aarch64-local-staging ~/debian7-x86_64-local-staging ~/centos6-x86_64-local-staging ./boringssl-static/target/central-staging
- name: Create bundle
working-directory: ./prepare-release-workspace/
run: bash ./.github/scripts/bundle_create.sh ~/central-bundle.zip ~/local-staging/
- name: Upload bundle to maven central
working-directory: ./prepare-release-workspace/
run: bash ./.github/scripts/bundle_upload.sh ~/central-bundle.zip ${{ secrets.MAVEN_CENTRAL_USERNAME }} ${{ secrets.MAVEN_CENTRAL_PASSWORD }}
- name: Rollback release on failure
working-directory: ./prepare-release-workspace/
if: ${{ failure() }}
# Rollback the release in case of an failure
run: bash ./.github/scripts/release_rollback.sh release.properties netty/netty-tcnative main