chore: improve release pipeline (#451)

* chore: improve release pipeline

* fix pipelines

* fix sccache

* update workflows

* fix workflow

* update workflow

* remove sccache and cross

* bring back sccache

* fix pipelines

* fix nodejs build

* fix pipelines

* move python to abi3 for future proofing

* fix workflow ordering bug

* gate releases via environment - configure go via release

* set release as 1.0.0-beta
This commit is contained in:
stefan-gorules
2026-06-24 20:44:35 +02:00
committed by GitHub
parent 6c0ca51354
commit 7f31af809d
34 changed files with 431 additions and 40575 deletions
+71 -287
View File
@@ -24,14 +24,18 @@ on:
- 'core/**'
- 'test-data/**'
- '.github/workflows/node.yaml'
# Stable publish is driven by the GitHub Release that release-please creates
# for the `nodejs` component (tag `nodejs-v<version>`).
release:
types: [ published ]
permissions:
contents: write
jobs:
build:
if: "!contains(github.event.head_commit.message, 'skip ci')"
# On release events, only build for this component's tag.
if: "(github.event_name != 'release' || startsWith(github.event.release.tag_name, 'nodejs-v')) && !contains(github.event.head_commit.message, 'skip ci')"
strategy:
fail-fast: false
matrix:
@@ -59,56 +63,45 @@ jobs:
yarn build --target aarch64-apple-darwin
strip -x ./*.node
- host: ubuntu-22.04
- host: ubuntu-latest
target: 'x86_64-unknown-linux-gnu'
zig: true
build: |
set -e
rustup install 1.88.0
rustup default 1.88.0
rustup target add x86_64-unknown-linux-gnu
yarn build --target x86_64-unknown-linux-gnu
strip ./*.node
mkdir -p ../../target
ln -sfn x86_64-unknown-linux-gnu ../../target/x86_64-unknown-linux-gnu.$GLIBC_VERSION
yarn build --target x86_64-unknown-linux-gnu.$GLIBC_VERSION --cross-compile
mv -f zen-engine.linux-x64-gnu.$GLIBC_VERSION.node zen-engine.linux-x64-gnu.node
strip zen-engine.linux-x64-gnu.node
- host: ubuntu-22.04-arm
- host: ubuntu-latest
target: 'aarch64-unknown-linux-gnu'
zig: true
build: |
set -e
rustup install 1.88.0
rustup default 1.88.0
rustup target add aarch64-unknown-linux-gnu
yarn build --target aarch64-unknown-linux-gnu
strip ./*.node
mkdir -p ../../target
ln -sfn aarch64-unknown-linux-gnu ../../target/aarch64-unknown-linux-gnu.$GLIBC_VERSION
yarn build --target aarch64-unknown-linux-gnu.$GLIBC_VERSION --cross-compile
mv -f zen-engine.linux-arm64-gnu.$GLIBC_VERSION.node zen-engine.linux-arm64-gnu.node
- host: ubuntu-latest
target: 'x86_64-unknown-linux-musl'
docker: ghcr.io/napi-rs/napi-rs/nodejs-rust:lts-alpine
zig: true
build: |
set -e
apk add --no-cache gcc musl-dev libgcc linux-headers
cd bindings/nodejs
export CC_x86_64_unknown_linux_musl=gcc
export CARGO_TARGET_X86_64_UNKNOWN_LINUX_MUSL_LINKER=gcc
rustup install 1.88.0
rustup default 1.88.0
rustup target add x86_64-unknown-linux-musl
yarn build --target x86_64-unknown-linux-musl
yarn build --target x86_64-unknown-linux-musl --cross-compile
strip ./*.node
- host: ubuntu-latest
target: 'aarch64-unknown-linux-musl'
docker: ghcr.io/napi-rs/napi-rs/nodejs-rust:lts-alpine
zig: true
build: |
set -e
apk add --no-cache gcc musl-dev libgcc linux-headers
cd bindings/nodejs
# Set environment variables for the Rust toolchain
export CC_aarch64_unknown_linux_musl=aarch64-linux-musl-gcc
export CARGO_TARGET_AARCH64_UNKNOWN_LINUX_MUSL_LINKER=aarch64-linux-musl-gcc
rustup install 1.88.0
rustup default 1.88.0
rustup target add aarch64-unknown-linux-musl
yarn build --target aarch64-unknown-linux-musl
/aarch64-linux-musl-cross/bin/aarch64-linux-musl-strip *.node
yarn build --target aarch64-unknown-linux-musl --cross-compile
- host: ubuntu-latest
target: 'wasm32-wasip1-threads'
@@ -117,9 +110,6 @@ jobs:
tar -xvf wasi-sdk-27.0-x86_64-linux.tar.gz
build: |
set -e
rustup install 1.88.0
rustup default 1.88.0
rustup target add wasm32-wasip1-threads
export WASI_SDK_PATH="$(pwd)/wasi-sdk-27.0-x86_64-linux"
export CMAKE_BUILD_PARALLEL_LEVEL=2
export TARGET_CXXFLAGS="--target=wasm32-wasi-threads --sysroot=$(pwd)/wasi-sdk-27.0-x86_64-linux/share/wasi-sysroot -pthread -mllvm -wasm-enable-sjlj -lsetjmp"
@@ -137,7 +127,6 @@ jobs:
- name: Setup node
uses: actions/setup-node@v3
if: ${{ !matrix.settings.docker }}
with:
node-version: 22
check-latest: true
@@ -146,20 +135,16 @@ jobs:
- name: Install
uses: dtolnay/rust-toolchain@stable
if: ${{ !matrix.settings.docker }}
with:
toolchain: stable
targets: ${{ matrix.settings.target }}
- name: Cache cargo registry
uses: actions/cache@v3
- name: Rust cache + sccache (+ zig for linux legs)
uses: ./.github/actions/setup-rust
with:
path: |
~/.cargo/registry
~/.cargo/git
target
.cargo-cache
key: ${{ matrix.settings.host }}-${{ matrix.settings.target }}-cargo-registry-v2
shared-key: nodejs-${{ matrix.settings.target }}
key: ${{ matrix.settings.target }}
zig: ${{ matrix.settings.zig }}
- name: Setup toolchain
run: ${{ matrix.settings.setup }}
@@ -169,22 +154,13 @@ jobs:
- name: 'Install dependencies'
run: yarn install --immutable --mode=skip-build
- name: Build in docker
uses: stefan-gorules/docker-run-action@v1
if: ${{ matrix.settings.docker }}
with:
image: ${{ matrix.settings.docker }}
options: --user 0:0 -v ${{ github.workspace }}/.cargo-cache/.cargo/git:/usr/local/cargo/git -v ${{ github.workspace }}/.cargo-cache/.cargo/registry:/usr/local/cargo/registry -v ${{ github.workspace }}:/build -w /build
run: ${{ matrix.settings.build }}
- name: 'Build'
run: ${{ matrix.settings.build }}
if: ${{ !matrix.settings.docker }}
shell: bash
- name: 'Check'
if: ${{ matrix.settings.target != 'x86_64-pc-windows-msvc' }}
run: ls -la
shell: bash
- name: Upload artifact ${{ matrix.settings.target }}
if: ${{ matrix.settings.target != 'wasm32-wasip1-threads' }}
@@ -205,8 +181,8 @@ jobs:
bindings/nodejs/zen-engine.wasi*
bindings/nodejs/wasi-worker*
test-macOS-windows-binding:
name: Test bindings on ${{ matrix.settings.target }} - node@${{ matrix.node }}
test:
name: Test ${{ matrix.settings.target }} - node@${{ matrix.node }}
needs:
- build
defaults:
@@ -215,14 +191,26 @@ jobs:
strategy:
fail-fast: false
matrix:
node: [ '20', '22' ]
settings:
# Native runners
- host: macos-15-intel
target: 'x86_64-apple-darwin'
- host: macos-latest
target: 'aarch64-apple-darwin'
- host: windows-latest
target: 'x86_64-pc-windows-msvc'
node: [ '20', '22' ]
# Linux: run inside the matching libc container; arm adds QEMU
- host: ubuntu-latest
target: 'x86_64-unknown-linux-gnu'
image: 'node:{0}-slim'
- host: ubuntu-latest
target: 'x86_64-unknown-linux-musl'
image: 'node:{0}-alpine'
- host: ubuntu-latest
target: 'aarch64-unknown-linux-musl'
image: 'node:{0}-alpine'
arm: true
runs-on: ${{ matrix.settings.host }}
steps:
@@ -238,7 +226,22 @@ jobs:
cache: yarn
cache-dependency-path: 'bindings/nodejs/yarn.lock'
- name: Set up QEMU
if: ${{ matrix.settings.arm }}
uses: docker/setup-qemu-action@v3
with:
platforms: arm64
- if: ${{ matrix.settings.arm }}
run: docker run --rm --privileged multiarch/qemu-user-static --reset -p yes
- name: Install dependencies (arm64/musl)
if: ${{ matrix.settings.arm }}
run: |
yarn config set supportedArchitectures.cpu "arm64"
yarn config set supportedArchitectures.libc "musl"
yarn install --immutable --mode=skip-build
- name: Install dependencies
if: ${{ !matrix.settings.arm }}
run: yarn install --immutable --mode=skip-build
- name: Download artifacts
@@ -255,254 +258,35 @@ jobs:
run: yarn artifacts
shell: bash
- name: Test bindings
- name: Test bindings (native)
if: ${{ !matrix.settings.image }}
run: |
yarn install
yarn link
yarn test
test-linux-x64-gnu-binding:
name: Test bindings on Linux-x64-gnu - node@${{ matrix.node }}
needs:
- build
defaults:
run:
working-directory: ${{ env.WORKING_DIRECTORY }}
strategy:
fail-fast: false
matrix:
node: [ '20', '22' ]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Setup node
uses: actions/setup-node@v3
with:
node-version: ${{ matrix.node }}
check-latest: true
cache: yarn
cache-dependency-path: 'bindings/nodejs/yarn.lock'
- name: Install dependencies
run: yarn install --immutable --mode=skip-build
- name: Download artifacts
uses: actions/download-artifact@v4
with:
name: bindings-x86_64-unknown-linux-gnu
path: artifacts
- name: List artifacts
run: |
ls -la ../../artifacts
shell: bash
- name: Create dirs
run: yarn createNpmDirs
shell: bash
- name: Move artifacts
run: yarn artifacts
shell: bash
- name: List folder
run: ls ./
shell: bash
- name: Test bindings
- name: Test bindings (docker)
if: ${{ matrix.settings.image }}
uses: stefan-gorules/docker-run-action@v1
with:
image: node:${{ matrix.node }}-slim
options: -v ${{ github.workspace }}:/workspace
image: ${{ format(matrix.settings.image, matrix.node) }}
options: ${{ matrix.settings.arm && format('--platform linux/arm64 -v {0}:/workspace', github.workspace) || format('-v {0}:/workspace', github.workspace) }}
run: |
cd workspace/bindings/nodejs
yarn install
yarn link
yarn test
test-linux-x64-musl-binding:
name: Test bindings on Linux-x64-musl - node@${{ matrix.node }}
needs:
- build
defaults:
run:
working-directory: ${{ env.WORKING_DIRECTORY }}
strategy:
fail-fast: false
matrix:
node: [ '20', '22' ]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Setup node
uses: actions/setup-node@v3
with:
node-version: ${{ matrix.node }}
check-latest: true
cache: yarn
cache-dependency-path: 'bindings/nodejs/yarn.lock'
- name: Install dependencies
run: yarn install --immutable --mode=skip-build
- name: Download artifacts
uses: actions/download-artifact@v4
with:
name: bindings-x86_64-unknown-linux-musl
path: artifacts
- name: Create dirs
run: yarn createNpmDirs
shell: bash
- name: Move artifacts
run: yarn artifacts
shell: bash
- name: List folder
run: ls ./
shell: bash
- name: Test bindings
uses: stefan-gorules/docker-run-action@v1
with:
image: node:${{ matrix.node }}-alpine
options: -v ${{ github.workspace }}:/workspace
run: |
cd workspace/bindings/nodejs
yarn install
yarn link
yarn test
test-linux-aarch64-musl-binding:
name: Test bindings on Linux-aarch64-musl - node@${{ matrix.node }}
needs:
- build
defaults:
run:
working-directory: ${{ env.WORKING_DIRECTORY }}
strategy:
fail-fast: false
matrix:
node: [ '20', '22' ]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Setup node
uses: actions/setup-node@v3
with:
node-version: ${{ matrix.node }}
check-latest: true
cache: yarn
cache-dependency-path: 'bindings/nodejs/yarn.lock'
- name: Install dependencies
run: |
yarn config set supportedArchitectures.cpu "arm64"
yarn config set supportedArchitectures.libc "musl"
yarn install --immutable --mode=skip-build
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
with:
platforms: arm64
- run: docker run --rm --privileged multiarch/qemu-user-static --reset -p yes
- name: Download artifacts
uses: actions/download-artifact@v4
with:
name: bindings-aarch64-unknown-linux-musl
path: artifacts
- name: Create dirs
run: yarn createNpmDirs
shell: bash
- name: Move artifacts
run: yarn artifacts
shell: bash
- name: List folder
run: ls ./
shell: bash
- name: Test bindings
uses: stefan-gorules/docker-run-action@v1
with:
options: --platform linux/arm64 -v ${{ github.workspace }}:/workspace
image: node:${{ matrix.node }}-alpine
run: |
cd workspace/bindings/nodejs
yarn install
yarn link
yarn test
# test-linux-aarch64-gnu-binding:
# name: Test bindings on aarch64-unknown-linux-gnu - node@${{ matrix.node }}
# needs:
# - build
# defaults:
# run:
# working-directory: ${{ env.WORKING_DIRECTORY }}
# strategy:
# fail-fast: false
# matrix:
# node: ['14', '16', '18']
# runs-on: ubuntu-latest
#
# steps:
# - uses: actions/checkout@v3
# - run: docker run --rm --privileged multiarch/qemu-user-static:register --reset
# - name: List directory
# run: |
# ls -la &&
# pwd
#
# - name: Download artifacts
# uses: actions/download-artifact@v4
# with:
# name: bindings-aarch64-unknown-linux-gnu
# path: artifacts
#
# - name: Install dependencies
# run: |
# yarn config set supportedArchitectures.cpu "arm64"
# yarn config set supportedArchitectures.libc "glibc"
# yarn install --immutable --mode=skip-build
# - name: Move artifacts
# run: yarn artifacts
# shell: bash
#
# - name: List folder
# run: ls ./
# shell: bash
#
# - name: Setup and run tests
# uses: stefan-gorules/docker-run-action@v1
# with:
# image: ghcr.io/napi-rs/napi-rs/nodejs:aarch64-${{ matrix.node }}
# options: -v ${{ github.workspace }}:/workspace -w /workspace
# run: |
# ls -la
# cd bindings/nodejs
# yarn install
# yarn link
# yarn test
release:
name: Release
runs-on: ubuntu-latest
environment: release
# Publishes only on the release-please GitHub Release for the nodejs component.
if: "github.event_name == 'release' && startsWith(github.event.release.tag_name, 'nodejs-v')"
defaults:
run:
working-directory: ${{ env.WORKING_DIRECTORY }}
needs:
- test-linux-x64-gnu-binding
# - test-linux-x64-centos-7
- test-linux-x64-musl-binding
# - test-linux-aarch64-gnu-binding
# - test-linux-arm-gnueabihf-binding
- test-macOS-windows-binding
- test-linux-aarch64-musl-binding
- test
steps:
- uses: actions/checkout@v3
@@ -543,8 +327,8 @@ jobs:
shell: bash
- name: Lerna publish
if: "startsWith(github.event.head_commit.message, 'chore(release): publish nodejs')"
run: yarn lerna publish from-package --no-verify-access --yes
# Prereleases (release-please beta window) go to the `next` dist-tag, not `latest`.
run: yarn lerna publish from-package --dist-tag ${{ github.event.release.prerelease && 'next' || 'latest' }} --no-verify-access --yes
env:
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}