File
Blob: .github/workflows/release.yml
| 1 | name: Build & Release |
| 2 | |
| 3 | on: |
| 4 | push: |
| 5 | branches: |
| 6 | - main |
| 7 | workflow_dispatch: |
| 8 | inputs: |
| 9 | patch: |
| 10 | description: 'Patch Version' |
| 11 | required: true |
| 12 | default: '0' |
| 13 | prerelease: |
| 14 | description: 'Is Prerelease' |
| 15 | type: boolean |
| 16 | default: false |
| 17 | permissions: |
| 18 | id-token: write |
| 19 | contents: write |
| 20 | actions: write |
| 21 | |
| 22 | jobs: |
| 23 | version: |
| 24 | outputs: |
| 25 | date: ${{ steps.echo.outputs.date }} |
| 26 | version: ${{ steps.echo.outputs.version }} |
| 27 | types_version: ${{ steps.echo.outputs.types_version }} |
| 28 | # version job uses ubuntu 24.04, this way we don't have to install the updated clang while |
| 29 | # the build job uses 22.04 for libc compatibility. |
| 30 | runs-on: ubuntu-24.04 |
| 31 | steps: |
| 32 | - uses: actions/checkout@v6 |
| 33 | - id: echo |
| 34 | run: | |
| 35 | echo "date=$(cat src/workerd/io/release-version.txt)" >> $GITHUB_OUTPUT; |
| 36 | echo "version=${{ (github.event_name != 'push' && inputs.prerelease == true) && '0' || '1'}}.$(cat src/workerd/io/release-version.txt | tr -d '-').${{ github.event_name == 'push' && '1' || inputs.patch }}" >> $GITHUB_OUTPUT; |
| 37 | echo "types_version=${{ (github.event_name != 'push' && inputs.prerelease == true) && '0' || '4'}}.$(cat src/workerd/io/release-version.txt | tr -d '-').${{ github.event_name == 'push' && '1' || inputs.patch }}" >> $GITHUB_OUTPUT; |
| 38 | check-tag: |
| 39 | name: Check tag is new |
| 40 | outputs: |
| 41 | exists: ${{ steps.check_tag.outputs.exists }} |
| 42 | needs: [version] |
| 43 | runs-on: ubuntu-latest |
| 44 | steps: |
| 45 | - name: Checkout Repo |
| 46 | uses: actions/checkout@v6 |
| 47 | with: |
| 48 | fetch-depth: 0 |
| 49 | - uses: mukunku/tag-exists-action@v1.7.0 |
| 50 | id: check_tag |
| 51 | with: |
| 52 | tag: v${{ needs.version.outputs.version }} |
| 53 | |
| 54 | tag-and-release: |
| 55 | name: Tag & Release |
| 56 | outputs: |
| 57 | upload_url: ${{ steps.create_release.outputs.upload_url }} |
| 58 | needs: [check-tag, version] |
| 59 | runs-on: ubuntu-latest |
| 60 | if: ${{ needs.check-tag.outputs.exists != 'true' }} |
| 61 | steps: |
| 62 | - name: Checkout Repo |
| 63 | uses: actions/checkout@v6 |
| 64 | with: |
| 65 | fetch-depth: 0 |
| 66 | - run: git tag v${{ needs.version.outputs.version }} && git push origin v${{ needs.version.outputs.version }} |
| 67 | - uses: ncipollo/release-action@v1 |
| 68 | id: create_release |
| 69 | with: |
| 70 | generateReleaseNotes: true |
| 71 | token: ${{ secrets.GITHUB_TOKEN }} |
| 72 | tag: v${{ needs.version.outputs.version }} |
| 73 | |
| 74 | build: |
| 75 | strategy: |
| 76 | matrix: |
| 77 | include: |
| 78 | - title: linux |
| 79 | os-name: Linux |
| 80 | image: ubuntu-22.04-16core |
| 81 | bazel-config: release_linux |
| 82 | target-arch: X64 |
| 83 | - title: linux-arm64 |
| 84 | os-name: Linux |
| 85 | image: ubuntu-22.04-arm-16core |
| 86 | bazel-config: release_linux |
| 87 | target-arch: ARM64 |
| 88 | # Based on runner availability, we build both Apple Silicon and (cross-compiled) x86 |
| 89 | # release binaries on the macos-15-xlarge runner. |
| 90 | - title: macOS-x64 |
| 91 | os-name: macOS |
| 92 | # This configuration is used for cross-compiling – macos-15-xlarge is Apple Silicon-based but |
| 93 | # we use it to compile the x64 release. |
| 94 | image: macos-15-xlarge |
| 95 | bazel-config: release_macos_cross_x86_64 |
| 96 | target-arch: X64 |
| 97 | - title: macOS-arm64 |
| 98 | os-name: macOS |
| 99 | image: macos-15-xlarge |
| 100 | bazel-config: release_macos |
| 101 | target-arch: ARM64 |
| 102 | - title: windows |
| 103 | os-name: Windows |
| 104 | image: windows-2025-16core |
| 105 | bazel-config: release_windows |
| 106 | target-arch: X64 |
| 107 | name: build (${{ matrix.title }}) |
| 108 | uses: './.github/workflows/_bazel.yml' |
| 109 | with: |
| 110 | image: ${{ matrix.image }} |
| 111 | os_name: ${{ matrix.os-name }} |
| 112 | phase: '-release' |
| 113 | extra_bazel_args: '--strip=always --config=${{matrix.bazel-config}} --config=ci-release --config=wpt-report --config=wpt-test' |
| 114 | arch_name: ${{ matrix.target-arch }} |
| 115 | upload_binary: true |
| 116 | macos_use_lld: true |
| 117 | # On release, generate a full WPT report... |
| 118 | run_tests: true |
| 119 | upload_test_logs: true |
| 120 | test_target: //src/wpt/... |
| 121 | secrets: |
| 122 | BAZEL_CACHE_KEY: ${{ secrets.BAZEL_CACHE_KEY }} |
| 123 | WORKERS_MIRROR_URL: ${{ secrets.WORKERS_MIRROR_URL }} |
| 124 | GOOGLESOURCE_COOKIE: ${{ secrets.GOOGLESOURCE_COOKIE }} |
| 125 | |
| 126 | upload-artifacts: |
| 127 | name: Upload Artifacts |
| 128 | needs: [version, tag-and-release, build] |
| 129 | runs-on: ubuntu-latest |
| 130 | strategy: |
| 131 | matrix: |
| 132 | arch: [linux-64, darwin-64, windows-64] |
| 133 | # This variable itself is unused, but allows us to set up two macOS builds. arm64 builds for |
| 134 | # other platforms will be supported later, then we'll list both architectures here. |
| 135 | cpu: [X64] |
| 136 | include: |
| 137 | - arch: linux-64 |
| 138 | name: Linux-X64 |
| 139 | - arch: linux-arm64 |
| 140 | name: Linux-ARM64 |
| 141 | cpu: ARM64 |
| 142 | - arch: darwin-64 |
| 143 | name: macOS-X64 |
| 144 | - arch: darwin-arm64 |
| 145 | name: macOS-ARM64 |
| 146 | cpu: ARM64 |
| 147 | - arch: windows-64 |
| 148 | name: Windows-X64 |
| 149 | steps: |
| 150 | - name: Checkout Repo |
| 151 | uses: actions/checkout@v6 |
| 152 | with: |
| 153 | fetch-depth: 0 |
| 154 | |
| 155 | - name: Download ${{ matrix.name }} |
| 156 | uses: actions/download-artifact@v8 |
| 157 | with: |
| 158 | name: ${{ matrix.name }}-binary |
| 159 | path: /tmp |
| 160 | # Set execute permissions before compressing the binary |
| 161 | - if: matrix.arch != 'windows-64' |
| 162 | run: chmod +x /tmp/workerd |
| 163 | - name: Compress release binary |
| 164 | run: | |
| 165 | # As of release v1.20230404.0 the Linux x64 binary after debug_strip is 65.8 MB, |
| 166 | # 21.0 MB with gzip and 17.3 MB with brotli -9. Use gzip as a widely supported format |
| 167 | # which still produces an acceptable compressed size. |
| 168 | gzip -9N -k /tmp/workerd${{ matrix.arch == 'windows-64' && '.exe' || '' }} |
| 169 | - run: mv /tmp/workerd${{ matrix.arch == 'windows-64' && '.exe' || '' }}.gz /tmp/workerd-${{ matrix.arch }}.gz |
| 170 | # Upload compressed release binaries – one set of artifacts is sufficient with gzip being |
| 171 | # widely supported |
| 172 | - name: Upload Release Assets |
| 173 | id: upload-release-asset |
| 174 | uses: actions/upload-release-asset@v1 |
| 175 | env: |
| 176 | GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} |
| 177 | with: |
| 178 | upload_url: ${{ needs.tag-and-release.outputs.upload_url }} |
| 179 | asset_path: /tmp/workerd-${{ matrix.arch }}.gz |
| 180 | asset_name: workerd-${{ matrix.arch }}.gz |
| 181 | asset_content_type: application/gzip |
| 182 | |
| 183 | # Upload release to npm |
| 184 | - name: Use Node |
| 185 | uses: actions/setup-node@v6 |
| 186 | with: |
| 187 | node-version: 24 |
| 188 | - name: Modify package.json version |
| 189 | run: node npm/scripts/bump-version.mjs npm/workerd-${{ matrix.arch }}/package.json |
| 190 | env: |
| 191 | WORKERD_VERSION: ${{ needs.version.outputs.version }} |
| 192 | LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }} |
| 193 | - run: mkdir npm/workerd-${{ matrix.arch }}/bin |
| 194 | - run: cp /tmp/workerd${{ matrix.arch == 'windows-64' && '.exe' || '' }} npm/workerd-${{ matrix.arch }}/bin/workerd${{ matrix.arch == 'windows-64' && '.exe' || '' }} |
| 195 | - run: echo '//registry.npmjs.org/:_authToken=${NPM_TOKEN}' > npm/workerd-${{ matrix.arch }}/.npmrc |
| 196 | - run: cd npm/workerd-${{ matrix.arch }} && npm publish --access public --tag ${{ startsWith(needs.version.outputs.version, '0') && 'beta' || 'latest'}} |
| 197 | env: |
| 198 | NPM_TOKEN: ${{ secrets.NPM_ACCESS_TOKEN }} |
| 199 | |
| 200 | miniflare-test: |
| 201 | name: Run Miniflare tests |
| 202 | needs: [build] |
| 203 | runs-on: ubuntu-latest |
| 204 | steps: |
| 205 | - name: Checkout workers-sdk |
| 206 | uses: actions/checkout@v6 |
| 207 | with: |
| 208 | repository: cloudflare/workers-sdk |
| 209 | |
| 210 | - name: Install pnpm |
| 211 | uses: pnpm/action-setup@v5 |
| 212 | - name: Use Node.js |
| 213 | uses: actions/setup-node@v6 |
| 214 | with: |
| 215 | node-version: lts/* |
| 216 | cache: 'pnpm' |
| 217 | - name: Install workers-sdk dependencies |
| 218 | run: pnpm install |
| 219 | |
| 220 | - name: Download workerd binary |
| 221 | uses: actions/download-artifact@v8 |
| 222 | with: |
| 223 | name: Linux-X64-binary |
| 224 | path: /tmp |
| 225 | - name: Make workerd binary executable |
| 226 | run: chmod +x /tmp/workerd |
| 227 | |
| 228 | - name: Build Miniflare and dependencies |
| 229 | run: pnpm turbo build --filter miniflare |
| 230 | |
| 231 | - name: Run Miniflare tests |
| 232 | run: pnpm --filter miniflare test |
| 233 | env: |
| 234 | MINIFLARE_WORKERD_PATH: /tmp/workerd |
| 235 | |
| 236 | publish-wrapper: |
| 237 | name: Publish `workerd` to NPM |
| 238 | needs: [version, upload-artifacts] |
| 239 | runs-on: ubuntu-22.04-16core |
| 240 | steps: |
| 241 | - name: Checkout Repo |
| 242 | uses: actions/checkout@v6 |
| 243 | with: |
| 244 | fetch-depth: 0 |
| 245 | |
| 246 | - name: Use Node |
| 247 | uses: actions/setup-node@v6 |
| 248 | with: |
| 249 | node-version: 24 |
| 250 | |
| 251 | - name: Cache |
| 252 | id: cache |
| 253 | uses: actions/cache@v5 |
| 254 | # Use same cache and build configuration as release build, this allows us to keep download |
| 255 | # sizes small and generate types with optimization enabled, should be slightly faster. |
| 256 | with: |
| 257 | path: ~/bazel-disk-cache |
| 258 | key: bazel-disk-cache-release-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('.bazelversion', '.bazelrc', 'MODULE.bazel') }} |
| 259 | - name: Setup Runner |
| 260 | uses: ./.github/actions/setup-runner |
| 261 | with: |
| 262 | GOOGLESOURCE_COOKIE: ${{ secrets.GOOGLESOURCE_COOKIE }} |
| 263 | - name: Build type generating Worker |
| 264 | run: | |
| 265 | bazel build --strip=always --remote_cache=https://bazel:${{ secrets.BAZEL_CACHE_KEY }}@bazel-remote-cache.devprod.cloudflare.dev --config=ci --config=release_linux //types:types_worker |
| 266 | |
| 267 | - name: Modify package.json version |
| 268 | run: node npm/scripts/bump-version.mjs npm/workerd/package.json |
| 269 | env: |
| 270 | WORKERD_VERSION: ${{ needs.version.outputs.version }} |
| 271 | LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }} |
| 272 | - run: mkdir -p npm/workerd/lib |
| 273 | - run: mkdir -p npm/workerd/bin |
| 274 | - name: Build node-install |
| 275 | run: npx esbuild npm/lib/node-install.ts --outfile=npm/workerd/install.js --bundle --target=node22 --define:LATEST_COMPATIBILITY_DATE="\"${LATEST_COMPATIBILITY_DATE}\"" --define:WORKERD_VERSION="\"${WORKERD_VERSION}\"" --platform=node --external:workerd --log-level=warning |
| 276 | env: |
| 277 | WORKERD_VERSION: ${{ needs.version.outputs.version }} |
| 278 | LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }} |
| 279 | - name: Build node-shim |
| 280 | run: npx esbuild npm/lib/node-shim.ts --outfile=npm/workerd/bin/workerd --bundle --target=node22 --define:LATEST_COMPATIBILITY_DATE="\"${LATEST_COMPATIBILITY_DATE}\"" --define:WORKERD_VERSION="\"${WORKERD_VERSION}\"" --platform=node --external:workerd --log-level=warning |
| 281 | env: |
| 282 | WORKERD_VERSION: ${{ needs.version.outputs.version }} |
| 283 | LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }} |
| 284 | - name: Build node-path |
| 285 | run: npx esbuild npm/lib/node-path.ts --outfile=npm/workerd/lib/main.js --bundle --target=node22 --define:LATEST_COMPATIBILITY_DATE="\"${LATEST_COMPATIBILITY_DATE}\"" --define:WORKERD_VERSION="\"${WORKERD_VERSION}\"" --platform=node --external:workerd --log-level=warning |
| 286 | env: |
| 287 | WORKERD_VERSION: ${{ needs.version.outputs.version }} |
| 288 | LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }} |
| 289 | - name: Build package |
| 290 | run: node npm/scripts/build-shim-package.mjs |
| 291 | env: |
| 292 | WORKERD_VERSION: ${{ needs.version.outputs.version }} |
| 293 | LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }} |
| 294 | - run: echo '//registry.npmjs.org/:_authToken=${NPM_TOKEN}' > npm/workerd/.npmrc |
| 295 | - run: cd npm/workerd && npm publish --access public --tag ${{ startsWith(needs.version.outputs.version, '0') && 'beta' || 'latest'}} |
| 296 | |
| 297 | build-and-publish-types: |
| 298 | runs-on: ubuntu-22.04-16core |
| 299 | needs: [version, upload-artifacts] |
| 300 | steps: |
| 301 | - uses: actions/checkout@v6 |
| 302 | with: |
| 303 | show-progress: false |
| 304 | - name: Use Node |
| 305 | uses: actions/setup-node@v6 |
| 306 | with: |
| 307 | node-version: 24 # needed for a version of npm that supports "trusted publishing". |
| 308 | - name: Cache |
| 309 | id: cache |
| 310 | uses: actions/cache@v5 |
| 311 | # Use same cache and build configuration as release build, this allows us to keep download |
| 312 | # sizes small and generate types with optimization enabled, should be slightly faster. |
| 313 | with: |
| 314 | path: ~/bazel-disk-cache |
| 315 | key: bazel-disk-cache-release-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('.bazelversion', '.bazelrc', 'MODULE.bazel') }} |
| 316 | - name: Setup Runner |
| 317 | uses: ./.github/actions/setup-runner |
| 318 | with: |
| 319 | GOOGLESOURCE_COOKIE: ${{ secrets.GOOGLESOURCE_COOKIE }} |
| 320 | - name: build types |
| 321 | run: | |
| 322 | bazel build --strip=always --remote_cache=https://bazel:${{ secrets.BAZEL_CACHE_KEY }}@bazel-remote-cache.devprod.cloudflare.dev --config=ci --config=release_linux //types |
| 323 | - name: Build package |
| 324 | run: node npm/scripts/build-types-package.mjs |
| 325 | env: |
| 326 | WORKERD_VERSION: ${{ needs.version.outputs.types_version }} |
| 327 | LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }} |
| 328 | - run: cp -r bazel-bin/types/definitions/. npm/workers-types |
| 329 | - run: cp npm/workers-types/oldest/* npm/workers-types |
| 330 | - run: echo '//registry.npmjs.org/:_authToken=${NPM_TOKEN}' > npm/workers-types/.npmrc |
| 331 | - run: cd npm/workers-types && npm publish --access public --tag ${{ startsWith(needs.version.outputs.version, '0') && 'beta' || 'latest'}} |