Skip to content

Tag and Release · patch on main #1

Tag and Release · patch on main

Tag and Release · patch on main #1

name: Tag and Release
run-name: "Tag and Release · ${{ inputs.bump }} on ${{ inputs.base_branch }}"
# Manually triggered release workflow.
# Version bump logic is documented in tag-and-release/calculate.js inside ci-core.
#
# Requires a GitHub Environment named "release-gate" configured with
# required reviewers to serve as the confirmation gate.
#
# Flow:
# calculate → build (validate) → confirm (release-gate) → tag → publish
#
# The build runs BEFORE the approval gate so that a broken build never
# produces a tag. After approval the publish job reuses the GHA cache
# and only pushes — no rebuild.
concurrency:
group: tag-and-release
cancel-in-progress: false
permissions: read-all
on:
workflow_dispatch:
inputs:
bump:
description: "Version bump type"
required: true
type: choice
options: [patch, minor, major, pre-minor, pre-major, rc-minor, rc-major]
base_branch:
description: "Base branch to tag (e.g. main, releases/v1.3.x)"
required: true
default: main
type: string
env:
ECR_REPO: public.ecr.aws/odigos/agents/php-community
jobs:
# ── 1. Calculate the next version ─────────────────────────────────────────
calculate:
runs-on: ubuntu-latest
permissions:
contents: read
outputs:
current_version: ${{ steps.calc.outputs.current_version }}
new_version: ${{ steps.calc.outputs.new_version }}
create_branch: ${{ steps.calc.outputs.create_branch }}
release_branch: ${{ steps.calc.outputs.release_branch }}
is_prerelease: ${{ steps.meta.outputs.is_prerelease }}
steps:
- uses: actions/checkout@v4
with:
ref: ${{ inputs.base_branch }}
fetch-depth: 0
fetch-tags: true
- id: calc
uses: odigos-io/ci-core/tag-and-release@main
with:
operation: calculate
bump: ${{ inputs.bump }}
base_branch: ${{ inputs.base_branch }}
- name: Derive release metadata
id: meta
env:
NEW_VERSION: ${{ steps.calc.outputs.new_version }}
run: |
if [[ "${NEW_VERSION}" == *"-pre."* || "${NEW_VERSION}" == *"-rc."* ]]; then
echo "is_prerelease=true" >> "$GITHUB_OUTPUT"
else
echo "is_prerelease=false" >> "$GITHUB_OUTPUT"
fi
# ── 2. Build image (no push) to validate before tagging ──────────────────
build:
needs: calculate
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@v4
with:
ref: ${{ inputs.base_branch }}
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Build Docker image (validation only)
uses: docker/build-push-action@v6
with:
context: .
platforms: linux/amd64,linux/arm64
file: release.Dockerfile
push: false
cache-to: type=gha,scope=php-community,mode=max
# ── 3. Human approval ────────────────────────────────────────────────────
confirm:
needs: [calculate, build]
runs-on: ubuntu-latest
environment: release-gate
steps:
- name: Release approved
run: echo "Releasing ${{ needs.calculate.outputs.new_version }} from ${{ inputs.base_branch }}"
# ── 4. Create tag + GitHub release ───────────────────────────────────────
tag:
needs: [calculate, confirm]
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
steps:
- uses: actions/checkout@v4
with:
ref: ${{ inputs.base_branch }}
fetch-depth: 0
fetch-tags: true
persist-credentials: false
- uses: odigos-io/ci-core/tag-and-release@main
with:
operation: tag
bump: ${{ inputs.bump }}
base_branch: ${{ inputs.base_branch }}
sts_identity: tag-releaser
new_version: ${{ needs.calculate.outputs.new_version }}
previous_version: ${{ needs.calculate.outputs.current_version }}
create_branch: ${{ needs.calculate.outputs.create_branch }}
release_branch: ${{ needs.calculate.outputs.release_branch }}
actor: ${{ github.actor }}
run_url: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
# ── 5. Push image + notify ──────────────────────────────────────────────
publish:
needs: [calculate, tag]
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
steps:
- uses: actions/checkout@v4
with:
ref: ${{ needs.calculate.outputs.new_version }}
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: arn:aws:iam::${{ secrets.AWS_ACCOUNT_ID }}:role/github-actions-ecr-upload
aws-region: 'us-east-1'
- name: Log in to Amazon ECR
run: |
aws ecr-public get-login-password --region us-east-1 \
| docker login --username AWS --password-stdin public.ecr.aws
- name: Compute Docker tags
id: docker-tags
env:
NEW_VERSION: ${{ needs.calculate.outputs.new_version }}
IS_PRERELEASE: ${{ needs.calculate.outputs.is_prerelease }}
run: |
TAGS="${ECR_REPO}:${NEW_VERSION}"
if [[ "${IS_PRERELEASE}" == "false" ]]; then
TAGS="${TAGS},${ECR_REPO}:latest"
fi
echo "tags=${TAGS}" >> "$GITHUB_OUTPUT"
- name: Build and push Docker image
uses: docker/build-push-action@v6
with:
context: .
platforms: linux/amd64,linux/arm64
file: release.Dockerfile
push: true
tags: ${{ steps.docker-tags.outputs.tags }}
cache-from: type=gha,scope=php-community
- name: Notify Slack
if: always()
uses: odigos-io/ci-core/.github/actions/slack-release-notification@main
with:
webhook-url: ${{ secrets.ODIGOS_RELEASE_STATUS_WEBHOOK_URL }}
success-description: "Published a new release of OpenTelemetry PHP Community Agent"
failure-description: "ERROR: Failed to publish a new release of OpenTelemetry PHP Community Agent"
tag: ${{ needs.calculate.outputs.new_version }}