-
Notifications
You must be signed in to change notification settings - Fork 41
79 lines (76 loc) · 3.38 KB
/
proto-registry.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
name: Third Party Proto Registry
# Protobuf runs buf (https://buf.build/) push updated proto files to https://buf.build/provenance-io
# This workflow pushes the third party protos to buf.build whenever any of them are updated in `main`.
on:
push:
branches:
- main
paths:
- "third_party/**.proto"
- ".github/workflows/proto-registry.yml"
workflow_dispatch:
# Concurrency is not defined in here because this job usually doesn't run
# long enough to need cancelling, and it's okay for it to run multiple times.
# Provenance publishes Protobuf content (including third_party dependencies) to buf.build.
# Because of third_party dependencies declared in buf.yml, a buf.lock will be generated
# containing the dependency manifest. Among other things, the buf.lock contains the
# latest buf.build commit hash of the third_party library in the https://buf.build/provenance-io.
# When new files are added to the third_party library we need:
# 1. publish the third_party library
# 2. update buf.lock to point to the new commit hash
# 3. sign and create a PR to commit buf.lock changes back to main
# This helps avoid a buf push failure due to a new third party proto reference.
jobs:
push_third_party:
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Buf setup action
uses: bufbuild/buf-setup-action@v1.33.0
- name: Buf push 'third_party/proto'
uses: bufbuild/buf-push-action@v1
with:
input: 'third_party/proto'
buf_token: ${{ secrets.BUF_TOKEN }}
- name: Import GPG key
id: import_gpg
uses: crazy-max/ghaction-import-gpg@v6
with:
# Use a key associated with the provenanceio-bot github account.
gpg_private_key: ${{ secrets.BOT_GPG_PRIVATE_KEY }}
passphrase: ${{ secrets.BOT_GPG_PRIVATE_KEY_PW }}
git_user_signingkey: true
git_commit_gpgsign: true
- name: Update buf.lock
run: |
cd proto
buf mod update
cd ..
git add .
git commit -S -m "Update buf.lock to latest commit hash"
- name: Create Pull Request
id: cpr
uses: peter-evans/create-pull-request@v6.0.5
with:
base: main
branch: provenanceio-bot/patch-buf-lock
delete-branch: true
# GitHub Personal Access Token (from the same account where the GPG key is stored)
# When this expires, you'll need to log into the provenanceio-bot github account,
# regenerate a new one, and update the secret to have the new value.
token: ${{ secrets.BOT_CPR_PAT }}
committer: ${{ steps.import_gpg.outputs.name }} <${{ steps.import_gpg.outputs.email }}>
author: ${{ steps.import_gpg.outputs.name }} <${{ steps.import_gpg.outputs.email }}>
signoff: true
title: 'Update buf.lock'
body: |
Updates `third_party/proto/buf.lock` with latest commit hash.
- Auto-generated by [create-pull-request][1]
[1]: https://github.com/peter-evans/create-pull-request
- name: Check outputs
if: ${{ steps.cpr.outputs.pull-request-number }}
run: |
echo "Pull Request Number - ${{ steps.cpr.outputs.pull-request-number }}"
echo "Pull Request URL - ${{ steps.cpr.outputs.pull-request-url }}"