Skip to content

Tag and Release · minor on main #34

Tag and Release · minor on main

Tag and Release · minor on main #34

name: Tag and Release
run-name: "Tag and Release · ${{ inputs.bump }} on ${{ inputs.base_branch }}"
# Manually triggered release workflow.
# Version bump logic is documented in tag-and-release/calculate.js inside ci-core.
#
# Requires a GitHub Environment named "release-gate" configured with
# required reviewers to serve as the confirmation gate.
#
# Flow:
# trigger ─→ calculate → build → confirm → tag → publish → trigger-odigos-update
concurrency:
group: tag-and-release
cancel-in-progress: false
permissions: read-all
on:
workflow_dispatch:
inputs:
bump:
description: "Version bump type"
required: true
type: choice
options: [patch, minor, major, pre-minor, pre-major, rc-minor, rc-major]
base_branch:
description: "Base branch to tag (e.g. main, releases/v1.9.x)"
required: true
default: main
type: string
env:
DOCKER_REPOSITORY_NAME: nodejs-community
DEPOT_REPOSITORY_NAME: 'agents/nodejs-community'
ECR_REGISTRY: public.ecr.aws/odigos/agents
DEPOT_REGISTRY: p0xd21zf5r.registry.depot.dev
jobs:
# ── 1. Calculate the next version ─────────────────────────────────────────
calculate:
runs-on: depot-ubuntu-latest
permissions:
contents: read
outputs:
new_version: ${{ steps.calc.outputs.new_version }}
create_branch: ${{ steps.calc.outputs.create_branch }}
release_branch: ${{ steps.calc.outputs.release_branch }}
is_prerelease: ${{ steps.meta.outputs.is_prerelease }}
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.base_branch }}
fetch-depth: 0
fetch-tags: true
- id: calc
uses: odigos-io/ci-core/tag-and-release@main
with:
operation: calculate
bump: ${{ inputs.bump }}
base_branch: ${{ inputs.base_branch }}
- name: Derive release metadata
id: meta
env:
NEW_VERSION: ${{ steps.calc.outputs.new_version }}
run: |
if [[ "${NEW_VERSION}" == *"-pre."* || "${NEW_VERSION}" == *"-rc."* ]]; then
echo "is_prerelease=true" >> "$GITHUB_OUTPUT"
else
echo "is_prerelease=false" >> "$GITHUB_OUTPUT"
fi
- name: Notify Slack (start)
if: always()
uses: odigos-io/ci-core/.github/actions/slack-release-notification@main
with:
webhook-url: ${{ secrets.ODIGOS_RELEASE_STATUS_WEBHOOK_URL }}
success-description: "Starting release of OpenTelemetry Node.js Community Agent ${{ steps.calc.outputs.new_version }} for bump type ${{ inputs.bump }}"
failure-description: "ERROR: Failed to start release of OpenTelemetry Node.js Community Agent ${{ steps.calc.outputs.new_version }} for bump type ${{ inputs.bump }}"
tag: ${{ steps.calc.outputs.new_version }}
# ── 2. Build images (no push, parallel with calculate) ───────────────────
build:
runs-on: depot-ubuntu-24.04-4
permissions:
contents: read
id-token: write
needs: calculate
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.base_branch }}
- uses: depot/setup-action@v1
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
- name: Set up QEMU
uses: docker/setup-qemu-action@v4
- name: Build NodeJS Community Docker image
uses: depot/build-push-action@v1
with:
platforms: linux/amd64,linux/arm64
push: false
context: .
file: Dockerfile
build-args: AGENT_VERSION=${{ needs.calculate.outputs.new_version }}
- name: Notify Slack (build)
if: always()
uses: odigos-io/ci-core/.github/actions/slack-release-notification@main
with:
webhook-url: ${{ secrets.ODIGOS_RELEASE_STATUS_WEBHOOK_URL }}
success-description: "Built OpenTelemetry Node.js Community Agent completed successfully, approve the deployment"
failure-description: "ERROR: Failed to build OpenTelemetry Node.js Community Agent"
tag: ${{ needs.calculate.outputs.new_version }}
# ── 3. Human approval (after calculate + build both pass) ────────────────
confirm:
needs: [calculate, build]
runs-on: depot-ubuntu-latest
environment: release-gate
steps:
- name: Release approved
run: echo "Releasing ${{ needs.calculate.outputs.new_version }} from ${{ inputs.base_branch }}"
- name: Notify Slack (confirm)
if: always()
uses: odigos-io/ci-core/.github/actions/slack-release-notification@main
with:
webhook-url: ${{ secrets.ODIGOS_RELEASE_STATUS_WEBHOOK_URL }}
success-description: "Release of OpenTelemetry Node.js Community Agent after being approved"
failure-description: "ERROR: Failed to approve release of OpenTelemetry Node.js Community Agent"
tag: ${{ needs.calculate.outputs.new_version }}
# ── 4. Create tags + GitHub release (only if builds passed) ──────────────
tag:
needs: [calculate, confirm]
runs-on: depot-ubuntu-latest
permissions:
id-token: write
contents: read
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.base_branch }}
fetch-depth: 0
fetch-tags: true
persist-credentials: false
- uses: odigos-io/ci-core/tag-and-release@main
with:
operation: tag
bump: ${{ inputs.bump }}
base_branch: ${{ inputs.base_branch }}
sts_identity: tag-releaser
new_version: ${{ needs.calculate.outputs.new_version }}
create_branch: ${{ needs.calculate.outputs.create_branch }}
release_branch: ${{ needs.calculate.outputs.release_branch }}
actor: ${{ github.actor }}
run_url: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
# ── 5. Push images ─────────────────────────────────────────────────────────
publish:
needs: [calculate, tag]
runs-on: depot-ubuntu-24.04-4
permissions:
id-token: write
contents: read
steps:
- name: Notify Slack (publish)
if: always()
uses: odigos-io/ci-core/.github/actions/slack-release-notification@main
with:
webhook-url: ${{ secrets.ODIGOS_RELEASE_STATUS_WEBHOOK_URL }}
success-description: "Start publishing OpenTelemetry Node.js Community Agent"
failure-description: "ERROR: Failed to start publishing OpenTelemetry Node.js Community Agent"
tag: ${{ needs.calculate.outputs.new_version }}
- uses: actions/checkout@v7
with:
ref: ${{ needs.calculate.outputs.new_version }}
- uses: depot/setup-action@v1
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
- name: Set up QEMU
uses: docker/setup-qemu-action@v4
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: arn:aws:iam::${{ secrets.AWS_ACCOUNT_ID }}:role/github-actions-ecr-upload
aws-region: 'us-east-1'
- name: Log in to Amazon ECR
run: |
aws ecr-public get-login-password --region us-east-1 \
| docker login --username AWS --password-stdin public.ecr.aws
- name: Login to Depot Registry
run: echo "${{ secrets.DEPOT_DEV_AGENT_PUBLISH_TOKEN }}" | docker login ${DEPOT_REGISTRY} -u x-token --password-stdin
- name: Compute Docker tags
id: docker-tags
env:
NEW_VERSION: ${{ needs.calculate.outputs.new_version }}
IS_PRERELEASE: ${{ needs.calculate.outputs.is_prerelease }}
run: |
COMMUNITY="${ECR_REGISTRY}/${DOCKER_REPOSITORY_NAME}:${NEW_VERSION},${DEPOT_REGISTRY}/${DEPOT_REPOSITORY_NAME}:${NEW_VERSION}"
if [[ "${IS_PRERELEASE}" == "false" ]]; then
COMMUNITY="${COMMUNITY},${ECR_REGISTRY}/${DOCKER_REPOSITORY_NAME}:latest,${DEPOT_REGISTRY}/${DEPOT_REPOSITORY_NAME}:latest"
fi
echo "community=${COMMUNITY}" >> "$GITHUB_OUTPUT"
- name: Build and push NodeJS Community Docker image
uses: depot/build-push-action@v1
with:
platforms: linux/amd64,linux/arm64
push: true
context: .
file: Dockerfile
tags: ${{ steps.docker-tags.outputs.community }}
build-args: AGENT_VERSION=${{ needs.calculate.outputs.new_version }}
- name: Notify Slack (publish)
if: always()
uses: odigos-io/ci-core/.github/actions/slack-release-notification@main
with:
webhook-url: ${{ secrets.ODIGOS_RELEASE_STATUS_WEBHOOK_URL }}
success-description: "Published OpenTelemetry Node.js Community Agent"
failure-description: "ERROR: Failed to publish OpenTelemetry Node.js Community Agent"
tag: ${{ needs.calculate.outputs.new_version }}
# ── 6. Trigger consumer version updates (runs only if publish succeeded)
trigger-odigos-update:
needs: [calculate, publish]
runs-on: depot-ubuntu-latest
permissions:
id-token: write
contents: read
steps:
- name: Trigger agents version update in odigos
uses: odigos-io/ci-core/dispatch-agent-version-update@main
with:
instrumentation_agent: nodejs-community
version: ${{ needs.calculate.outputs.new_version }}
consumers: odigos
- name: Build ebpf-nodejs-instrumentation payload
id: payload-ebpf-nodejs
env:
AGENT_VERSION: ${{ needs.calculate.outputs.new_version }}
run: |
# Payload shape expected by ebpf-nodejs-instrumentation's
# update-nodejs-community-version repository_dispatch handler.
json="$(jq -nc --arg version "$AGENT_VERSION" \
'{nodejs_community_version: $version}')"
echo "json=$json" >> "$GITHUB_OUTPUT"
- name: Get sts token for ebpf-nodejs-instrumentation
id: sts-ebpf-nodejs
uses: odigos-io/ci-core/sts@main
with:
scope: odigos-io/ebpf-nodejs-instrumentation
identity: trigger-nodejs-community-version-updater
output-git-config: "false"
- name: Trigger update in ebpf-nodejs-instrumentation
uses: peter-evans/repository-dispatch@v4
with:
token: ${{ steps.sts-ebpf-nodejs.outputs.GH_TOKEN }}
repository: odigos-io/ebpf-nodejs-instrumentation
event-type: update-nodejs-community-version
client-payload: ${{ steps.payload-ebpf-nodejs.outputs.json }}