CI=1 -> --ci #448
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: "Build app and create release" | |
| on: | |
| push: | |
| tags: | |
| - v*.*.* | |
| env: | |
| SQLX_OFFLINE: "1" | |
| jobs: | |
| create-release: | |
| name: create-release | |
| runs-on: self-hosted | |
| outputs: | |
| upload_url: ${{ steps.release.outputs.upload_url }} | |
| steps: | |
| - name: Create GitHub release | |
| id: release | |
| uses: softprops/action-gh-release@v3 | |
| with: | |
| draft: true | |
| generate_release_notes: true | |
| create-sbom: | |
| needs: | |
| - create-release | |
| uses: ./.github/workflows/sbom.yml | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| ubuntu-22-04-build: | |
| needs: | |
| - create-release | |
| runs-on: | |
| - self-hosted | |
| - Linux | |
| - ${{ matrix.architecture }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| architecture: [ARM64, X64] | |
| include: | |
| - architecture: ARM64 | |
| deb_arch: arm64 | |
| binary_arch: aarch64 | |
| - architecture: X64 | |
| deb_arch: amd64 | |
| binary_arch: x86_64 | |
| container: | |
| image: ubuntu:22.04 | |
| env: | |
| DEBIAN_FRONTEND: noninteractive | |
| HOME: /root | |
| RUSTUP_HOME: /root/.rustup | |
| CARGO_HOME: /root/.cargo | |
| steps: | |
| - name: Install system packages | |
| run: | | |
| apt-get update | |
| apt-get install -y git curl ca-certificates libatomic1 | |
| git config --global --add safe.directory '*' | |
| - uses: actions/checkout@v6 | |
| with: | |
| submodules: recursive | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version: 26 | |
| - name: Install pnpm | |
| uses: pnpm/action-setup@v6 | |
| with: | |
| cache: true | |
| version: 11 | |
| run_install: false | |
| - name: Get pnpm store directory | |
| run: | | |
| echo "STORE_PATH=$(pnpm store path --silent)" >> ${GITHUB_ENV} | |
| - name: Write release version | |
| run: | | |
| VERSION=$(echo ${GITHUB_REF_NAME#v} | cut -d '-' -f1) | |
| echo Version: $VERSION | |
| echo "VERSION=$VERSION" >> ${GITHUB_ENV} | |
| echo "DEFGUARD_CLIENT_BUILD_VERSION=${GITHUB_REF_NAME#v}" >> ${GITHUB_ENV} | |
| # Change to '--frozen-lockfile' once this gets fixed: | |
| # https://github.com/pnpm/action-setup/issues/40 | |
| - name: Install Node dependencies | |
| run: pnpm install --no-frozen-lockfile | |
| - name: Install Node dependencies for new UI | |
| run: | | |
| cd new-ui | |
| pnpm install --no-frozen-lockfile | |
| - name: Install Rust stable | |
| uses: dtolnay/rust-toolchain@stable | |
| - name: Install dependencies | |
| run: | | |
| apt-get install -y build-essential libgtk-3-dev libwebkit2gtk-4.1-dev libayatana-appindicator3-dev librsvg2-dev patchelf libssl-dev libxdo-dev unzip protobuf-compiler libprotobuf-dev rpm | |
| - name: Build new UI | |
| run: | | |
| cd new-ui | |
| pnpm build | |
| - name: Build packages | |
| uses: tauri-apps/tauri-action@v0.5.23 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| args: "--bundles deb" | |
| - name: Upload DEB | |
| uses: shogo82148/actions-upload-release-asset@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| asset_path: src-tauri/target/release/bundle/deb/defguard-client_${{ env.VERSION }}_${{ matrix.deb_arch }}.deb | |
| asset_name: defguard-client${{ env.VERSION }}_${{ matrix.deb_arch }}_ubuntu-22-04-lts.deb | |
| asset_content_type: application/octet-stream | |
| - name: Rename dg binary | |
| run: mv src-tauri/target/release/dg dg-linux-${{ env.VERSION }}_${{ matrix.deb_arch }} | |
| - name: Build dg deb | |
| uses: defGuard/fpm-action@main | |
| with: | |
| fpm_args: "dg-linux-${{ env.VERSION }}_${{ matrix.deb_arch }}=/usr/sbin/dg dg.service=/usr/lib/systemd/system/dg.service src-tauri/cli/.env=/etc/defguard/dg.conf" | |
| fpm_opts: "--architecture ${{ matrix.binary_arch }} --debug --output-type deb --version ${{ env.VERSION }} --package dg-linux-${{ env.VERSION }}_${{ matrix.deb_arch }}_ubuntu-22-04-lts.deb" | |
| - name: Upload DEB | |
| uses: shogo82148/actions-upload-release-asset@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| asset_path: dg-linux-${{ env.VERSION }}_${{ matrix.deb_arch }}_ubuntu-22-04-lts.deb | |
| asset_content_type: application/octet-stream | |
| build-linux: | |
| needs: | |
| - create-release | |
| outputs: | |
| deb_sha256_amd64: ${{ steps.calculate-sha256.outputs.deb_sha256_amd64 }} | |
| runs-on: | |
| - self-hosted | |
| - Linux | |
| - ${{ matrix.architecture }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| architecture: [ARM64, X64] | |
| include: | |
| - architecture: ARM64 | |
| deb_arch: arm64 | |
| binary_arch: aarch64 | |
| - architecture: X64 | |
| deb_arch: amd64 | |
| binary_arch: x86_64 | |
| steps: | |
| - uses: actions/checkout@v6 | |
| with: | |
| submodules: recursive | |
| - name: Write release version | |
| run: | | |
| VERSION=$(echo ${GITHUB_REF_NAME#v} | cut -d '-' -f1) | |
| echo Version: $VERSION | |
| echo "VERSION=$VERSION" >> ${GITHUB_ENV} | |
| echo "DEFGUARD_CLIENT_BUILD_VERSION=${GITHUB_REF_NAME#v}" >> ${GITHUB_ENV} | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version: 26 | |
| - uses: pnpm/action-setup@v6 | |
| with: | |
| cache: true | |
| version: 11 | |
| run_install: false | |
| - name: Get pnpm store directory | |
| shell: bash | |
| run: | | |
| echo "STORE_PATH=$(pnpm store path --silent)" >> ${GITHUB_ENV} | |
| # Change to '--frozen-lockfile' once this gets fixed: | |
| # https://github.com/pnpm/action-setup/issues/40 | |
| - name: Install Node dependencies | |
| run: pnpm install --no-frozen-lockfile | |
| - name: Install Node dependencies for new UI | |
| run: | | |
| cd new-ui | |
| pnpm install --no-frozen-lockfile | |
| - name: Install Rust stable | |
| uses: dtolnay/rust-toolchain@stable | |
| - name: Install Linux dependencies | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y libgtk-3-dev libwebkit2gtk-4.1-dev libayatana-appindicator3-dev librsvg2-dev patchelf libssl-dev libxdo-dev unzip protobuf-compiler libprotobuf-dev rpm | |
| - name: Build new UI | |
| run: | | |
| cd new-ui | |
| pnpm build | |
| - name: Build packages | |
| uses: tauri-apps/tauri-action@v0.5.23 # .24 seems broken, TODO: update when fixed | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| args: "--bundles deb,rpm" | |
| - name: Calculate DEB SHA256 | |
| id: calculate-sha256 | |
| if: matrix.deb_arch == 'amd64' | |
| run: | | |
| DEB_FILE="src-tauri/target/release/bundle/deb/defguard-client_${{ env.VERSION }}_${{ matrix.deb_arch }}.deb" | |
| DEB_SHA256=$(sha256sum "$DEB_FILE" | cut -d ' ' -f1) | |
| echo "DEB SHA256: $DEB_SHA256" | |
| echo "DEB_SHA256=$DEB_SHA256" >> ${GITHUB_ENV} | |
| echo "deb_sha256_${{ matrix.deb_arch }}=$DEB_SHA256" >> ${GITHUB_OUTPUT} | |
| - name: Upload RPM | |
| uses: shogo82148/actions-upload-release-asset@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| asset_path: src-tauri/target/release/bundle/rpm/defguard-client-${{ env.VERSION }}-1.${{ matrix.binary_arch }}.rpm | |
| asset_content_type: application/octet-stream | |
| - name: Upload DEB | |
| uses: shogo82148/actions-upload-release-asset@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| asset_path: src-tauri/target/release/bundle/deb/defguard-client_${{ env.VERSION }}_${{ matrix.deb_arch }}.deb | |
| asset_content_type: application/octet-stream | |
| - name: Rename and tar client binary | |
| run: | | |
| mv src-tauri/target/release/defguard-client defguard-client-linux-${{ matrix.binary_arch }}-${{ github.ref_name }} | |
| tar -zcf defguard-client-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.tar.gz \ | |
| defguard-client-linux-${{ matrix.binary_arch }}-${{ github.ref_name }} | |
| - name: Upload client archive | |
| uses: shogo82148/actions-upload-release-asset@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| asset_path: defguard-client-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.tar.gz | |
| asset_content_type: application/octet-stream | |
| - name: Rename and tar daemon binary | |
| run: | | |
| mv src-tauri/target/release/defguard-service defguard-service-linux-${{ matrix.binary_arch }}-${{ github.ref_name }} | |
| tar -zcf defguard-service-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.tar.gz \ | |
| defguard-service-linux-${{ matrix.binary_arch }}-${{ github.ref_name }} | |
| - name: Upload daemon archive | |
| uses: shogo82148/actions-upload-release-asset@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| asset_path: defguard-service-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.tar.gz | |
| asset_content_type: application/octet-stream | |
| - name: Rename and tar defguard-cli binary | |
| run: | | |
| mv src-tauri/target/release/defguard-cli defguard-cli-linux-${{ matrix.binary_arch }}-${{ github.ref_name }} | |
| tar -zcf defguard-cli-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.tar.gz \ | |
| defguard-cli-linux-${{ matrix.binary_arch }}-${{ github.ref_name }} | |
| - name: Upload defguard-cli archive | |
| uses: shogo82148/actions-upload-release-asset@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| asset_path: defguard-cli-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.tar.gz | |
| asset_content_type: application/octet-stream | |
| - name: Rename and tar dg binary | |
| run: | | |
| mv src-tauri/target/release/dg dg-linux-${{ matrix.binary_arch }}-${{ github.ref_name }} | |
| tar -zcf dg-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.tar.gz \ | |
| dg-linux-${{ matrix.binary_arch }}-${{ github.ref_name }} | |
| - name: Upload dg archive | |
| uses: shogo82148/actions-upload-release-asset@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| asset_path: dg-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.tar.gz | |
| asset_content_type: application/octet-stream | |
| - name: Build dg deb | |
| uses: defGuard/fpm-action@main | |
| with: | |
| fpm_args: "dg-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}=/usr/sbin/dg dg.service=/usr/lib/systemd/system/dg.service src-tauri/cli/.env=/etc/defguard/dg.conf" | |
| fpm_opts: "--architecture ${{ matrix.binary_arch }} --debug --output-type deb --version ${{ env.VERSION }} --package dg-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.deb" | |
| - name: Upload DEB | |
| uses: shogo82148/actions-upload-release-asset@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| asset_path: dg-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.deb | |
| asset_content_type: application/octet-stream | |
| - name: Build dg rpm | |
| uses: defGuard/fpm-action@main | |
| with: | |
| fpm_args: "dg-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}=/usr/sbin/dg dg.service=/usr/lib/systemd/system/dg.service src-tauri/cli/.env=/etc/defguard/dg.conf" | |
| fpm_opts: "--architecture ${{ matrix.binary_arch }} --debug --output-type rpm --version ${{ env.VERSION }} --package dg-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.rpm" | |
| - name: Upload RPM | |
| uses: shogo82148/actions-upload-release-asset@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| asset_path: dg-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.rpm | |
| asset_content_type: application/octet-stream | |
| # Dedicated dg build for AlmaLinux 9 (and the RHEL 9 family: Rocky 9, RHEL 9). | |
| # The default dg RPM is built against a newer glibc/OpenSSL and fails to run on | |
| # Alma 9, so dg is compiled inside an almalinux:9 container to link Alma's | |
| # glibc 2.34 and OpenSSL 3, then packaged with fpm. x86_64 only. | |
| build-dg-alma9: | |
| needs: | |
| - create-release | |
| runs-on: | |
| - self-hosted | |
| - Linux | |
| - X64 | |
| container: | |
| image: almalinux:9 | |
| env: | |
| HOME: /root | |
| RUSTUP_HOME: /root/.rustup | |
| CARGO_HOME: /root/.cargo | |
| SQLX_OFFLINE: "true" | |
| steps: | |
| - name: Install build prerequisites | |
| run: | | |
| dnf -y install git gcc gcc-c++ make openssl-devel perl pkgconfig unzip | |
| git config --global --add safe.directory '*' | |
| - uses: actions/checkout@v6 | |
| with: | |
| submodules: recursive | |
| - name: Write release version | |
| run: | | |
| VERSION=$(echo ${GITHUB_REF_NAME#v} | cut -d '-' -f1) | |
| echo Version: $VERSION | |
| echo "VERSION=$VERSION" >> ${GITHUB_ENV} | |
| - name: Install protoc | |
| run: | | |
| PB_REL='https://github.com/protocolbuffers/protobuf/releases' | |
| PB_VERSION='3.20.0' | |
| curl -LO $PB_REL/download/v$PB_VERSION/protoc-$PB_VERSION-linux-x86_64.zip | |
| unzip -o protoc-$PB_VERSION-linux-x86_64.zip bin/protoc 'include/google/*' -d /usr/local | |
| echo "PROTOC=/usr/local/bin/protoc" >> ${GITHUB_ENV} | |
| - name: Install Rust stable | |
| uses: dtolnay/rust-toolchain@stable | |
| - name: Build dg (AlmaLinux 9) | |
| run: cargo build --release --manifest-path src-tauri/Cargo.toml -p defguard-dg --bin dg | |
| - name: Rename dg binary | |
| run: mv src-tauri/target/release/dg dg-linux-x86_64-${{ github.ref_name }} | |
| - name: Build dg rpm | |
| uses: defGuard/fpm-action@main | |
| with: | |
| fpm_args: "dg-linux-x86_64-${{ github.ref_name }}=/usr/sbin/dg dg.service=/usr/lib/systemd/system/dg.service src-tauri/cli/.env=/etc/defguard/dg.conf" | |
| fpm_opts: "--architecture x86_64 --debug --output-type rpm --version ${{ env.VERSION }} --no-auto-depends --depends openssl-libs --depends wireguard-tools --package dg-linux-x86_64-${{ github.ref_name }}-el9.rpm" | |
| - name: Upload RPM | |
| uses: actions/upload-release-asset@v1.0.2 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| asset_path: dg-linux-x86_64-${{ github.ref_name }}-el9.rpm | |
| asset_name: dg-linux-x86_64-${{ github.ref_name }}-el9.rpm | |
| asset_content_type: application/octet-stream | |
| build-macos: | |
| needs: | |
| - create-release | |
| uses: ./.github/workflows/release-macos.yaml | |
| secrets: inherit | |
| with: | |
| upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| # Builds Windows MSI and uploads it as artifact | |
| # build-windows: | |
| # needs: | |
| # - create-release | |
| # strategy: | |
| # fail-fast: false | |
| # matrix: | |
| # windows_runner: | |
| # - windows-latest | |
| # - windows-11-arm | |
| # include: | |
| # - windows_runner: windows-latest | |
| # cpu: x64 | |
| # - windows_runner: windows-11-arm | |
| # cpu: arm64 | |
| # runs-on: ${{ matrix.windows_runner }} | |
| # steps: | |
| # - uses: actions/checkout@v6 | |
| # with: | |
| # submodules: recursive | |
| # - name: Write release version | |
| # run: | | |
| # $env:VERSION=echo ($env:GITHUB_REF_NAME.Substring(1) -Split "-")[0] | |
| # echo Version: $env:VERSION | |
| # echo "VERSION=$env:VERSION" >> $env:GITHUB_ENV | |
| # - uses: actions/setup-node@v6 | |
| # with: | |
| # node-version: 26 | |
| # - uses: pnpm/action-setup@v6 | |
| # with: | |
| # version: 11 | |
| # run_install: false | |
| # - name: Get pnpm store directory | |
| # shell: bash | |
| # run: echo "STORE_PATH=$(pnpm store path --silent)" >> ${GITHUB_ENV} | |
| # - name: Install deps | |
| # run: pnpm install --frozen-lockfile | |
| # - uses: dtolnay/rust-toolchain@stable | |
| # - name: Install Protoc | |
| # uses: arduino/setup-protoc@v3 | |
| # with: | |
| # repo-token: ${{ secrets.GITHUB_TOKEN }} | |
| # - name: Build packages | |
| # uses: tauri-apps/tauri-action@v0.5.23 # 0.5.24 - 0.6.1 give: Error: Could not find workspace directory, but version and/or name specifies to use workspace package | |
| # env: | |
| # GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| # - name: Upload unsigned bundle | |
| # uses: actions/upload-artifact@v4 | |
| # with: | |
| # name: unsigned-bundle-${{ matrix.cpu }} | |
| # path: src-tauri/target/release/bundle/msi/Defguard_${{ env.VERSION }}_${{ matrix.cpu }}_en-US.msi | |
| # Signs the MSI and uploads it as release asset | |
| # sign-bundle: | |
| # needs: | |
| # - create-release | |
| # - build-windows | |
| # strategy: | |
| # fail-fast: false | |
| # matrix: | |
| # # Match CPUs from build-windows above. | |
| # cpu: | |
| # - x64 | |
| # - arm64 | |
| # runs-on: | |
| # - self-hosted | |
| # - Linux | |
| # - X64 | |
| # steps: | |
| # - name: Write release version | |
| # run: | | |
| # VERSION=$(echo ${GITHUB_REF_NAME#v} | cut -d '-' -f1) | |
| # echo Version: $VERSION | |
| # echo "VERSION=$VERSION" >> ${GITHUB_ENV} | |
| # - name: Download unsigned bundle | |
| # uses: actions/download-artifact@v4 | |
| # with: | |
| # name: unsigned-bundle-${{ matrix.cpu }} | |
| # - name: Sign bundle | |
| # run: osslsigncode sign -pkcs11module /srv/codesign/certum/sc30pkcs11-3.0.6.72-MS.so -pkcs11cert ${{ secrets.CODESIGN_KEYID }} -key ${{ secrets.CODESIGN_KEYID }} -pass ${{ secrets.CODESIGN_PIN }} -h sha256 -t http://time.certum.pl/ -in Defguard_${{ env.VERSION }}_${{ matrix.cpu }}_en-US.msi -out Defguard-signed.msi | |
| # - name: Upload installer asset | |
| # uses: shogo82148/actions-upload-release-asset@v1 | |
| # env: | |
| # GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| # with: | |
| # upload_url: ${{ needs.create-release.outputs.upload_url }} | |
| # asset_path: Defguard-signed.msi | |
| # asset_name: Defguard_${{ env.VERSION }}_${{ matrix.cpu }}_en-US.msi | |
| # asset_content_type: application/octet-stream |