-
Notifications
You must be signed in to change notification settings - Fork 3
133 lines (116 loc) · 4.64 KB
/
Copy pathgithub-actions.yml
File metadata and controls
133 lines (116 loc) · 4.64 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
# This workflow will build the project, run integration tests, and release.
# Secret-backed jobs fetch credentials from AWS Secrets Manager using GitHub OIDC.
name: Build, Check, Publish
on:
push:
branches: [ main ]
paths-ignore:
- '.github/workflows/**'
pull_request:
branches: [ main ]
jobs:
build:
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
steps:
- name: Checkout Repo
uses: actions/checkout@v3
- name: Configure AWS credentials for Docker Hub secrets (OIDC)
if: github.event_name != 'pull_request'
uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: arn:aws:iam::301904545275:role/oidc-github-hellosign-dropbox-sign-java-branch-main
aws-region: us-west-2
- name: Get Docker Hub secrets from AWS Secrets Manager
if: github.event_name != 'pull_request'
uses: aws-actions/aws-secretsmanager-get-secrets@v3
with:
secret-ids: |
DOCKER_USERNAME,github-actions/hellosign/shared/docker-username
DOCKER_TOKEN,github-actions/hellosign/shared/docker-token
parse-json-secrets: false
- name: Build SDK
run: ./run-build
- name: Ensure no changes in Generated Code
run: ./bin/check-clean-git-status
# This job runs on merging to "main" branch
# Builds and publishes package
publish-prod:
runs-on: ubuntu-latest
if: >-
github.repository == 'hellosign/dropbox-sign-java'
&& github.ref == 'refs/heads/main'
&& github.event_name != 'pull_request'
needs: [ build ]
permissions:
id-token: write
contents: read
steps:
- name: Checkout
uses: actions/checkout@v3
- name: Install JDK 11
uses: actions/setup-java@v3
with:
distribution: 'zulu'
java-version: 11
- name: Retrieve version
run: echo "PACKAGE_VERSION=$(cat VERSION)" >> $GITHUB_ENV
- name: Configure AWS credentials for Maven secrets (OIDC)
uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: arn:aws:iam::521590706193:role/oidc-github-hellosign-dropbox-sign-java-branch-main
aws-region: us-west-2
- name: Get Maven Central secrets from AWS Secrets Manager
uses: aws-actions/aws-secretsmanager-get-secrets@v3
with:
secret-ids: |
SONATYPE_USERNAME,sdk-release-maven-central-token-username
SONATYPE_PASSWORD,sdk-release-maven-central-token-password
SIGNING_KEY,sdk-release-signing-key
SIGNING_PASSWORD,sdk-release-signing-password
parse-json-secrets: false
- name: Publish to Maven Central
run: ./gradlew publishAndReleaseToMavenCentral --no-daemon --no-parallel --no-configuration-cache --stacktrace
if: "!endsWith(env.PACKAGE_VERSION, '-SNAPSHOT')"
env:
ORG_GRADLE_PROJECT_mavenCentralUsername: ${{ env.SONATYPE_USERNAME }}
ORG_GRADLE_PROJECT_mavenCentralPassword: ${{ env.SONATYPE_PASSWORD }}
ORG_GRADLE_PROJECT_signingInMemoryKey: ${{ env.SIGNING_KEY }}
ORG_GRADLE_PROJECT_signingInMemoryKeyPassword: ${{ env.SIGNING_PASSWORD }}
- name: Publish Snapshot
run: ./gradlew publishToMavenCentral --no-daemon --no-parallel --no-configuration-cache --stacktrace
if: "endsWith(env.PACKAGE_VERSION, '-SNAPSHOT')"
env:
ORG_GRADLE_PROJECT_mavenCentralUsername: ${{ env.SONATYPE_USERNAME }}
ORG_GRADLE_PROJECT_mavenCentralPassword: ${{ env.SONATYPE_PASSWORD }}
ORG_GRADLE_PROJECT_signingInMemoryKey: ${{ env.SIGNING_KEY }}
ORG_GRADLE_PROJECT_signingInMemoryKeyPassword: ${{ env.SIGNING_PASSWORD }}
# This job runs on merging to "main" branch
# Creates a new tag using the value in the VERSION file
cut-tag:
runs-on: ubuntu-latest
if: >-
github.repository == 'hellosign/dropbox-sign-java'
&& github.ref == 'refs/heads/main'
&& github.event_name != 'pull_request'
needs: [ publish-prod ]
steps:
- name: Checkout
uses: actions/checkout@v3
- name: Retrieve version
run: echo "PACKAGE_VERSION=$(cat VERSION)" >> $GITHUB_ENV
- name: Create tag
uses: actions/github-script@v6
if: "!endsWith(env.PACKAGE_VERSION, '-SNAPSHOT')"
env:
PACKAGE_VERSION: ${{ env.PACKAGE_VERSION }}
with:
script: |
github.rest.git.createRef({
owner: context.repo.owner,
repo: context.repo.repo,
ref: "refs/tags/" + process.env.PACKAGE_VERSION,
sha: context.sha
})