Skip to content

Bump Helm Chart and Dagger Version => v1.115.0 (#3514) #18

Bump Helm Chart and Dagger Version => v1.115.0 (#3514)

Bump Helm Chart and Dagger Version => v1.115.0 (#3514) #18

name: Package Sandbox Kit
on:
# Only the specs, not the README beside them: the release bump PR rewrites each
# spec.yaml `version:`, and that is what should trigger a publish.
push:
branches:
- main
paths:
- devel/sandbox-kit/*/spec.yaml
permissions: read-all
jobs:
# Every directory under devel/sandbox-kit/ holding a spec.yaml is a kit, so
# adding one needs no change here.
discover:
name: Discover kits to publish
runs-on: ubuntu-latest
permissions:
contents: read
outputs:
kits: ${{ steps.find.outputs.kits }}
steps:
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
with:
persist-credentials: false
fetch-depth: 0 # needs the pushed range to diff each spec's version
- id: find
env:
BEFORE: ${{ github.event.before }}
AFTER: ${{ github.sha }}
run: |
# Publish a kit only when its `version:` actually changed in this push.
# Editing a comment in a spec must not republish a released tag under a
# version that already means something, and a re-run of a partly failed
# publish still selects the kit, so `latest` and the attestation get
# reconciled rather than skipped.
kits=()
for spec in devel/sandbox-kit/*/spec.yaml; do
[ -e "${spec}" ] || continue
kit=$(basename "$(dirname "${spec}")")
new=$(yq -r '.version // ""' "${spec}")
if [[ -z "${new}" || "${new}" == "null" ]]; then
echo "::error::${spec} declares no version:"
exit 1
fi
# An unknown or absent `before` (new branch, force push) counts as changed.
old=""
if git cat-file -e "${BEFORE}:${spec}" 2>/dev/null; then
old=$(git show "${BEFORE}:${spec}" | yq -r '.version // ""')
fi
if [[ "${new}" != "${old}" ]]; then
echo "${kit}: ${old:-<none>} -> ${new}"
kits+=("${kit}")
else
echo "${kit}: unchanged at ${new}, skipping"
fi
done
printf '%s\n' "${kits[@]+"${kits[@]}"}" | jq -Rsc 'split("\n") | map(select(length > 0))' \
| sed 's/^/kits=/' >> $GITHUB_OUTPUT
package:
name: Package and push ${{ matrix.kit }}
needs: discover
# An empty matrix vector is an error, not a skip, so guard the whole job.
if: needs.discover.outputs.kits != '[]'
runs-on: ubuntu-latest
strategy:
# One kit's failure must not cancel the others mid-publish.
fail-fast: false
matrix:
kit: ${{ fromJSON(needs.discover.outputs.kits) }}
permissions:
contents: read
id-token: write # Docker Hub OIDC login, SLSA provenance and keyless kit signing
env:
CHAINLOOP_WORKFLOW_NAME: "sandbox-kit-package"
CHAINLOOP_PROJECT: "chainloop"
# Docker Sandboxes ships Linux packages only on tagged releases, not on
# nightly, so this is pinned to a stable tag and bumped by hand.
SBX_VERSION: "v0.43.0"
KIT_DIR: "devel/sandbox-kit/${{ matrix.kit }}"
KIT_REPO: "docker.io/chainloop/sbx-kit-${{ matrix.kit }}"
steps:
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
with:
persist-credentials: false
- name: Read kit version
id: kit_version
run: |
# The kit's own spec.yaml is the source of truth; bump-chart-and-dagger-version.sh
# keeps it in step with the chart's appVersion on every release.
kit_version=$(yq -r '.version' "${KIT_DIR}/spec.yaml")
if [[ -z "${kit_version}" || "${kit_version}" == "null" ]]; then
echo "::error::${KIT_DIR}/spec.yaml declares no version:"
exit 1
fi
echo "kit_version=${kit_version}" >> $GITHUB_OUTPUT
- name: Install Chainloop
# Deliberately NOT `curl ... | bash`: this job holds an OIDC token that can
# mint Docker Hub credentials and sign artifacts, so the installer is
# fetched, pinned by digest and only then executed. The installer itself
# verifies the CLI's checksums (and cosign-verifies their signature), so
# this closes the remaining gap, which is the script in transit.
# If dl.chainloop.dev publishes a new installer this step fails with a
# digest mismatch; re-pin with:
# curl -sfL https://dl.chainloop.dev/cli/install.sh | sha256sum
env:
INSTALLER_SHA256: 6ebcdb8edc6f22c92b6ac31a363f7d60da6e04c60c4fadda44169f18492ba46e
run: |
curl -sfL https://dl.chainloop.dev/cli/install.sh -o /tmp/chainloop-install.sh
echo "${INSTALLER_SHA256} /tmp/chainloop-install.sh" | sha256sum -c -
bash /tmp/chainloop-install.sh
- name: Install Docker Sandboxes CLI
run: |
curl -sfL -o /tmp/sbx.deb \
"https://github.com/docker/sbx-releases/releases/download/${SBX_VERSION}/DockerSandboxes-linux-amd64-ubuntu2404.deb"
# The runner image's package index goes stale as Ubuntu supersedes
# versions, and the .deb's dependencies then 404 on the mirror.
sudo apt-get update
sudo apt-get install -y /tmp/sbx.deb
sbx version
# OIDC rather than a stored token: GitHub mints a short-lived identity token
# per run and Docker exchanges it for a registry token that expires with the
# job, so there is no long-lived Docker Hub credential in this repo. Access is
# governed by the connection's ruleset, which matches the subject claim
# repo:chainloop-dev/chainloop:ref:refs/heads/main - adding an `environment:`
# to this job would change that claim and stop it matching.
# Docker Hub OIDC landed in login-action v4.5.0; anything older ignores
# DOCKERHUB_OIDC_CONNECTIONID and fails with "Password required", so this
# pin must not be moved backwards.
- name: Docker login to Docker Hub
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
env:
DOCKERHUB_OIDC_CONNECTIONID: 361a9222-f648-4f62-baf4-5f500f7fbf54
with:
username: chainloop
- name: Validate kit
# Fails loudly here rather than halfway through a push if the pinned sbx
# release does not understand something the spec declares.
run: sbx kit validate "./${KIT_DIR}"
- name: Add Attestation (Sandbox Kit) and Push Kit
run: |
# KIT_VERSION arrives through env, not template interpolation, so the
# value is never expanded into this script's source. Do not write the
# literal expression syntax here either: GitHub expands it inside run
# bodies, shell comments included, and an empty one makes the whole
# workflow file fail to parse.
# Force the version declared in the kit spec and make sure it exists in
# the project by passing --existing-version; if it does not exist the
# attestation fails, and the version needs creating before a re-run.
chainloop attestation init --org chainloop --workflow ${CHAINLOOP_WORKFLOW_NAME} --project ${CHAINLOOP_PROJECT} --version ${KIT_VERSION} --existing-version
# Push the kit. --sign is keyless (Fulcio + Rekor) off the ambient
# GitHub OIDC token, and every push also attaches SLSA provenance.
sbx kit push "./${KIT_DIR}" "${KIT_REPO}:${KIT_VERSION}" --sign
# Move the floating tag to the same release. Note this is a second push
# rather than a retag, so :latest gets its own manifest digest even though
# the content is identical - compare the kit's `version:`, not the digest,
# to tell which release :latest currently points at.
sbx kit push "./${KIT_DIR}" "${KIT_REPO}:latest" --sign
# Attest the published kit. The immutable tag, not :latest, since the
# attestation should keep naming this artifact after the tag moves on.
chainloop attestation add --name sandbox-kit --value "${KIT_REPO}:${KIT_VERSION}"
env:
KIT_VERSION: ${{ steps.kit_version.outputs.kit_version }}
# Needed for commit signature verification: https://docs.chainloop.dev/concepts/attestations#commit-verification
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Finish and Record Attestation
if: ${{ success() }}
run: |
chainloop attestation push
- name: Mark attestation as failed
if: ${{ failure() }}
run: |
chainloop attestation reset
- name: Mark attestation as cancelled
if: ${{ cancelled() }}
run: |
chainloop attestation reset --trigger cancellation