Files
tatlock/.gitea/workflows/build.yml
T
jpmschweitzerandClaude Fable 5 da5ded48ab fix(ci): the release step tolerates a release that already exists
A re-fired tag hits the release POST with a 409 and curl -sf turns
"already exists" into a red job while the image jobs succeed — observed
on boilerroom's v0.1.0 re-fires tonight; this workflow fails the same
way. Check-then-create makes the step idempotent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-11 22:28:39 +02:00

56 lines
1.7 KiB
YAML

name: Build and Push
on:
push:
tags:
- 'v[0-9]*'
jobs:
release:
runs-on: ubuntu-latest
steps:
- name: Create Gitea Release
# Idempotent: a re-fired tag finds its release already present and
# says so instead of failing on the 409.
run: |
api="${{ github.server_url }}/api/v1/repos/${{ github.repository }}/releases"
auth='Authorization: token ${{ secrets.GITHUB_TOKEN }}'
if curl -sf -H "$auth" "$api/tags/${{ github.ref_name }}" > /dev/null; then
echo "release for ${{ github.ref_name }} already exists — nothing to do"
exit 0
fi
curl -sf -X POST \
-H "$auth" \
-H "Content-Type: application/json" \
-d '{"tag_name": "${{ github.ref_name }}", "name": "Release ${{ github.ref_name }}", "body": "Automated release for ${{ github.ref_name }}"}' \
"$api"
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Login to Gitea Registry
uses: docker/login-action@v3
with:
registry: git.schweitz.net
username: ${{ secrets.REGISTRY_USER }}
password: ${{ secrets.REGISTRY_PASSWORD }}
- name: Build and push
uses: docker/build-push-action@v6
with:
context: .
push: true
provenance: false
sbom: false
tags: |
git.schweitz.net/jpmschweitzer/tatlock:latest
git.schweitz.net/jpmschweitzer/tatlock:${{ github.ref_name }}
- name: Trigger Watchtower update
if: success()
run: |
curl -sf -H "Authorization: Bearer ${{ secrets.WATCHTOWER_TOKEN }}" \
http://watchtower:8080/v1/update