Skip to content
File

Blob: .github/workflows/release.yml

yaml332 lines
1name: Build & Release
2 
3on:
4 push:
5 branches:
6 - main
7 workflow_dispatch:
8 inputs:
9 patch:
10 description: 'Patch Version'
11 required: true
12 default: '0'
13 prerelease:
14 description: 'Is Prerelease'
15 type: boolean
16 default: false
17permissions:
18 id-token: write
19 contents: write
20 actions: write
21 
22jobs:
23 version:
24 outputs:
25 date: ${{ steps.echo.outputs.date }}
26 version: ${{ steps.echo.outputs.version }}
27 types_version: ${{ steps.echo.outputs.types_version }}
28 # version job uses ubuntu 24.04, this way we don't have to install the updated clang while
29 # the build job uses 22.04 for libc compatibility.
30 runs-on: ubuntu-24.04
31 steps:
32 - uses: actions/checkout@v6
33 - id: echo
34 run: |
35 echo "date=$(cat src/workerd/io/release-version.txt)" >> $GITHUB_OUTPUT;
36 echo "version=${{ (github.event_name != 'push' && inputs.prerelease == true) && '0' || '1'}}.$(cat src/workerd/io/release-version.txt | tr -d '-').${{ github.event_name == 'push' && '1' || inputs.patch }}" >> $GITHUB_OUTPUT;
37 echo "types_version=${{ (github.event_name != 'push' && inputs.prerelease == true) && '0' || '4'}}.$(cat src/workerd/io/release-version.txt | tr -d '-').${{ github.event_name == 'push' && '1' || inputs.patch }}" >> $GITHUB_OUTPUT;
38 check-tag:
39 name: Check tag is new
40 outputs:
41 exists: ${{ steps.check_tag.outputs.exists }}
42 needs: [version]
43 runs-on: ubuntu-latest
44 steps:
45 - name: Checkout Repo
46 uses: actions/checkout@v6
47 with:
48 fetch-depth: 0
49 - uses: mukunku/tag-exists-action@v1.7.0
50 id: check_tag
51 with:
52 tag: v${{ needs.version.outputs.version }}
53 
54 tag-and-release:
55 name: Tag & Release
56 outputs:
57 upload_url: ${{ steps.create_release.outputs.upload_url }}
58 needs: [check-tag, version]
59 runs-on: ubuntu-latest
60 if: ${{ needs.check-tag.outputs.exists != 'true' }}
61 steps:
62 - name: Checkout Repo
63 uses: actions/checkout@v6
64 with:
65 fetch-depth: 0
66 - run: git tag v${{ needs.version.outputs.version }} && git push origin v${{ needs.version.outputs.version }}
67 - uses: ncipollo/release-action@v1
68 id: create_release
69 with:
70 generateReleaseNotes: true
71 token: ${{ secrets.GITHUB_TOKEN }}
72 tag: v${{ needs.version.outputs.version }}
73 
74 build:
75 strategy:
76 matrix:
77 include:
78 - title: linux
79 os-name: Linux
80 image: ubuntu-22.04-16core
81 bazel-config: release_linux
82 target-arch: X64
83 - title: linux-arm64
84 os-name: Linux
85 image: ubuntu-22.04-arm-16core
86 bazel-config: release_linux
87 target-arch: ARM64
88 # Based on runner availability, we build both Apple Silicon and (cross-compiled) x86
89 # release binaries on the macos-15-xlarge runner.
90 - title: macOS-x64
91 os-name: macOS
92 # This configuration is used for cross-compiling – macos-15-xlarge is Apple Silicon-based but
93 # we use it to compile the x64 release.
94 image: macos-15-xlarge
95 bazel-config: release_macos_cross_x86_64
96 target-arch: X64
97 - title: macOS-arm64
98 os-name: macOS
99 image: macos-15-xlarge
100 bazel-config: release_macos
101 target-arch: ARM64
102 - title: windows
103 os-name: Windows
104 image: windows-2025-16core
105 bazel-config: release_windows
106 target-arch: X64
107 name: build (${{ matrix.title }})
108 uses: './.github/workflows/_bazel.yml'
109 with:
110 image: ${{ matrix.image }}
111 os_name: ${{ matrix.os-name }}
112 phase: '-release'
113 extra_bazel_args: '--strip=always --config=${{matrix.bazel-config}} --config=ci-release --config=wpt-report --config=wpt-test'
114 arch_name: ${{ matrix.target-arch }}
115 upload_binary: true
116 macos_use_lld: true
117 # On release, generate a full WPT report...
118 run_tests: true
119 upload_test_logs: true
120 test_target: //src/wpt/...
121 secrets:
122 BAZEL_CACHE_KEY: ${{ secrets.BAZEL_CACHE_KEY }}
123 WORKERS_MIRROR_URL: ${{ secrets.WORKERS_MIRROR_URL }}
124 GOOGLESOURCE_COOKIE: ${{ secrets.GOOGLESOURCE_COOKIE }}
125 
126 upload-artifacts:
127 name: Upload Artifacts
128 needs: [version, tag-and-release, build]
129 runs-on: ubuntu-latest
130 strategy:
131 matrix:
132 arch: [linux-64, darwin-64, windows-64]
133 # This variable itself is unused, but allows us to set up two macOS builds. arm64 builds for
134 # other platforms will be supported later, then we'll list both architectures here.
135 cpu: [X64]
136 include:
137 - arch: linux-64
138 name: Linux-X64
139 - arch: linux-arm64
140 name: Linux-ARM64
141 cpu: ARM64
142 - arch: darwin-64
143 name: macOS-X64
144 - arch: darwin-arm64
145 name: macOS-ARM64
146 cpu: ARM64
147 - arch: windows-64
148 name: Windows-X64
149 steps:
150 - name: Checkout Repo
151 uses: actions/checkout@v6
152 with:
153 fetch-depth: 0
154 
155 - name: Download ${{ matrix.name }}
156 uses: actions/download-artifact@v8
157 with:
158 name: ${{ matrix.name }}-binary
159 path: /tmp
160 # Set execute permissions before compressing the binary
161 - if: matrix.arch != 'windows-64'
162 run: chmod +x /tmp/workerd
163 - name: Compress release binary
164 run: |
165 # As of release v1.20230404.0 the Linux x64 binary after debug_strip is 65.8 MB,
166 # 21.0 MB with gzip and 17.3 MB with brotli -9. Use gzip as a widely supported format
167 # which still produces an acceptable compressed size.
168 gzip -9N -k /tmp/workerd${{ matrix.arch == 'windows-64' && '.exe' || '' }}
169 - run: mv /tmp/workerd${{ matrix.arch == 'windows-64' && '.exe' || '' }}.gz /tmp/workerd-${{ matrix.arch }}.gz
170 # Upload compressed release binaries – one set of artifacts is sufficient with gzip being
171 # widely supported
172 - name: Upload Release Assets
173 id: upload-release-asset
174 uses: actions/upload-release-asset@v1
175 env:
176 GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
177 with:
178 upload_url: ${{ needs.tag-and-release.outputs.upload_url }}
179 asset_path: /tmp/workerd-${{ matrix.arch }}.gz
180 asset_name: workerd-${{ matrix.arch }}.gz
181 asset_content_type: application/gzip
182 
183 # Upload release to npm
184 - name: Use Node
185 uses: actions/setup-node@v6
186 with:
187 node-version: 24
188 - name: Modify package.json version
189 run: node npm/scripts/bump-version.mjs npm/workerd-${{ matrix.arch }}/package.json
190 env:
191 WORKERD_VERSION: ${{ needs.version.outputs.version }}
192 LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }}
193 - run: mkdir npm/workerd-${{ matrix.arch }}/bin
194 - run: cp /tmp/workerd${{ matrix.arch == 'windows-64' && '.exe' || '' }} npm/workerd-${{ matrix.arch }}/bin/workerd${{ matrix.arch == 'windows-64' && '.exe' || '' }}
195 - run: echo '//registry.npmjs.org/:_authToken=${NPM_TOKEN}' > npm/workerd-${{ matrix.arch }}/.npmrc
196 - run: cd npm/workerd-${{ matrix.arch }} && npm publish --access public --tag ${{ startsWith(needs.version.outputs.version, '0') && 'beta' || 'latest'}}
197 env:
198 NPM_TOKEN: ${{ secrets.NPM_ACCESS_TOKEN }}
199 
200 miniflare-test:
201 name: Run Miniflare tests
202 needs: [build]
203 runs-on: ubuntu-latest
204 steps:
205 - name: Checkout workers-sdk
206 uses: actions/checkout@v6
207 with:
208 repository: cloudflare/workers-sdk
209 
210 - name: Install pnpm
211 uses: pnpm/action-setup@v5
212 - name: Use Node.js
213 uses: actions/setup-node@v6
214 with:
215 node-version: lts/*
216 cache: 'pnpm'
217 - name: Install workers-sdk dependencies
218 run: pnpm install
219 
220 - name: Download workerd binary
221 uses: actions/download-artifact@v8
222 with:
223 name: Linux-X64-binary
224 path: /tmp
225 - name: Make workerd binary executable
226 run: chmod +x /tmp/workerd
227 
228 - name: Build Miniflare and dependencies
229 run: pnpm turbo build --filter miniflare
230 
231 - name: Run Miniflare tests
232 run: pnpm --filter miniflare test
233 env:
234 MINIFLARE_WORKERD_PATH: /tmp/workerd
235 
236 publish-wrapper:
237 name: Publish `workerd` to NPM
238 needs: [version, upload-artifacts]
239 runs-on: ubuntu-22.04-16core
240 steps:
241 - name: Checkout Repo
242 uses: actions/checkout@v6
243 with:
244 fetch-depth: 0
245 
246 - name: Use Node
247 uses: actions/setup-node@v6
248 with:
249 node-version: 24
250 
251 - name: Cache
252 id: cache
253 uses: actions/cache@v5
254 # Use same cache and build configuration as release build, this allows us to keep download
255 # sizes small and generate types with optimization enabled, should be slightly faster.
256 with:
257 path: ~/bazel-disk-cache
258 key: bazel-disk-cache-release-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('.bazelversion', '.bazelrc', 'MODULE.bazel') }}
259 - name: Setup Runner
260 uses: ./.github/actions/setup-runner
261 with:
262 GOOGLESOURCE_COOKIE: ${{ secrets.GOOGLESOURCE_COOKIE }}
263 - name: Build type generating Worker
264 run: |
265 bazel build --strip=always --remote_cache=https://bazel:${{ secrets.BAZEL_CACHE_KEY }}@bazel-remote-cache.devprod.cloudflare.dev --config=ci --config=release_linux //types:types_worker
266
267 - name: Modify package.json version
268 run: node npm/scripts/bump-version.mjs npm/workerd/package.json
269 env:
270 WORKERD_VERSION: ${{ needs.version.outputs.version }}
271 LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }}
272 - run: mkdir -p npm/workerd/lib
273 - run: mkdir -p npm/workerd/bin
274 - name: Build node-install
275 run: npx esbuild npm/lib/node-install.ts --outfile=npm/workerd/install.js --bundle --target=node22 --define:LATEST_COMPATIBILITY_DATE="\"${LATEST_COMPATIBILITY_DATE}\"" --define:WORKERD_VERSION="\"${WORKERD_VERSION}\"" --platform=node --external:workerd --log-level=warning
276 env:
277 WORKERD_VERSION: ${{ needs.version.outputs.version }}
278 LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }}
279 - name: Build node-shim
280 run: npx esbuild npm/lib/node-shim.ts --outfile=npm/workerd/bin/workerd --bundle --target=node22 --define:LATEST_COMPATIBILITY_DATE="\"${LATEST_COMPATIBILITY_DATE}\"" --define:WORKERD_VERSION="\"${WORKERD_VERSION}\"" --platform=node --external:workerd --log-level=warning
281 env:
282 WORKERD_VERSION: ${{ needs.version.outputs.version }}
283 LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }}
284 - name: Build node-path
285 run: npx esbuild npm/lib/node-path.ts --outfile=npm/workerd/lib/main.js --bundle --target=node22 --define:LATEST_COMPATIBILITY_DATE="\"${LATEST_COMPATIBILITY_DATE}\"" --define:WORKERD_VERSION="\"${WORKERD_VERSION}\"" --platform=node --external:workerd --log-level=warning
286 env:
287 WORKERD_VERSION: ${{ needs.version.outputs.version }}
288 LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }}
289 - name: Build package
290 run: node npm/scripts/build-shim-package.mjs
291 env:
292 WORKERD_VERSION: ${{ needs.version.outputs.version }}
293 LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }}
294 - run: echo '//registry.npmjs.org/:_authToken=${NPM_TOKEN}' > npm/workerd/.npmrc
295 - run: cd npm/workerd && npm publish --access public --tag ${{ startsWith(needs.version.outputs.version, '0') && 'beta' || 'latest'}}
296 
297 build-and-publish-types:
298 runs-on: ubuntu-22.04-16core
299 needs: [version, upload-artifacts]
300 steps:
301 - uses: actions/checkout@v6
302 with:
303 show-progress: false
304 - name: Use Node
305 uses: actions/setup-node@v6
306 with:
307 node-version: 24 # needed for a version of npm that supports "trusted publishing".
308 - name: Cache
309 id: cache
310 uses: actions/cache@v5
311 # Use same cache and build configuration as release build, this allows us to keep download
312 # sizes small and generate types with optimization enabled, should be slightly faster.
313 with:
314 path: ~/bazel-disk-cache
315 key: bazel-disk-cache-release-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('.bazelversion', '.bazelrc', 'MODULE.bazel') }}
316 - name: Setup Runner
317 uses: ./.github/actions/setup-runner
318 with:
319 GOOGLESOURCE_COOKIE: ${{ secrets.GOOGLESOURCE_COOKIE }}
320 - name: build types
321 run: |
322 bazel build --strip=always --remote_cache=https://bazel:${{ secrets.BAZEL_CACHE_KEY }}@bazel-remote-cache.devprod.cloudflare.dev --config=ci --config=release_linux //types
323 - name: Build package
324 run: node npm/scripts/build-types-package.mjs
325 env:
326 WORKERD_VERSION: ${{ needs.version.outputs.types_version }}
327 LATEST_COMPATIBILITY_DATE: ${{ needs.version.outputs.date }}
328 - run: cp -r bazel-bin/types/definitions/. npm/workers-types
329 - run: cp npm/workers-types/oldest/* npm/workers-types
330 - run: echo '//registry.npmjs.org/:_authToken=${NPM_TOKEN}' > npm/workers-types/.npmrc
331 - run: cd npm/workers-types && npm publish --access public --tag ${{ startsWith(needs.version.outputs.version, '0') && 'beta' || 'latest'}}