Public Access
CI / build (push) Successful in 8m0s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2.8 KiB
2.8 KiB
R1 — Releases
Status: in progress (branch ci): CI and signed releases on Gitea (issue #5). The Issues App (#4) and updates from Gitea (#6) come after; #6 waits for this.
Goal: a tag is a release, built the same way every time and published where a device can find it.
CI and releases (issue #5)
Until now the tests, the builds, the signing and the flashing all happened on one machine, through scripts/ci.sh and scripts/flash.sh. Nothing was published.
Decisions (design round 2026-10-06)
| # | Decision |
|---|---|
| Q151 | Every push, to any branch: the host tests and both builds. A tag v*: the same, then a release. |
| Q152 | CI signs. The signing key is the repository secret OTA_SIGNING_KEY; a tag push makes a complete, signed release with no manual step (ADR 0008). |
| Q153 | The Debug Build is built in CI with a token of the runner's own, to prove it compiles, and isn't published: it would hand everyone its Debug Console token. |
| Q154 | Pull requests from forks don't start a run. |
| Q155 | A release carries roro9stack-<version>.ota (signed), -factory.bin for USB, .elf.gz to decode crashes, and SHA256SUMS. |
| Q156 | Its text is the tag's message, what the files are, and the commits since the tag before. |
| Q157 | No cache service to begin with: measure first. |
| Q158 | Reproducible builds aren't needed for signing any more (Q152); not pursued here. |
| Q159 | The tags from before CI get their releases too, v0.1.0 to v0.10.0, built from each tag's own sources by running the workflow by hand. |
| Q160 | Actions is switched on for the repository. |
As built
- One workflow,
.gitea/workflows/ci.yml, one job. The runner (runner0) executes jobs on its own host, where Docker is, so the steps are plain shell and the build runs in the project's image throughscripts/ci.sh, exactly as on a developer's machine. The toolchains live in the sameroro9stack-pioDocker volume, on the runner: that is the cache. - No JavaScript actions: the host has no Node. The checkout is four git commands.
- The runner's label is registered as
ubuntu://docker:ubuntu:resolute, the whole string, and that is whatruns-onhas to say. It looks likeubuntu:docker://ubuntu:resolutewas meant, which would run jobs in a container; the workflow would then need Docker inside that container, or a rewrite. As it is, it works. scripts/release_build.sh <checkout> <out>builds a tag's own sources with today's build image and signing tools, signs, verifies, and writes the files and the release's text.scripts/release_publish.pycreates the Gitea release or completes it; run twice, it replaces what's there. Both run the same on a developer's machine.scripts/ota_verify.pychecks an Update File as a device does, on a PC.