mirror of
https://github.com/ruvnet/RuView
synced 2026-07-19 16:53:18 +00:00
3833929dcb
New `.github/workflows/cog-ha-matter-release.yml`:
* Triggers on `cog-ha-matter-v*` tag-push + manual dispatch
* Three jobs: build-x86_64, build-arm, publish-gcs
* x86_64: native ubuntu-latest cargo build
* arm: aarch64-unknown-linux-gnu via apt-installed gcc-aarch64-linux-gnu
linker (no `cross` dep needed — keeps workflow self-contained)
* Each build job runs make build-{arch} + make sign-{arch} +
gated Ed25519 sign step (skipped when COGNITUM_OWNER_SIGNING_KEY
secret is unset — workflow still produces unsigned artifacts so
we get build coverage now and signing later without re-merging)
* publish-gcs job gated on `vars.HAS_GCP_CREDENTIALS == 'true'`
so the workflow is safe to merge before credentials land —
no-op until the org admin sets the variable
* Uploads binary + sha256 + (optional) sig to
`gs://cognitum-apps/cogs/{arch}/cog-ha-matter-{arch}`
* Prints the app-registry.json snippet for the cognitum-one PR
(so the publish step's output is the exact JSON the user pastes)
Fixed a bug inherited from cog-pose-estimation's Makefile: the
precedent produces `dist/cog-cog-pose-estimation-arm` (double
`cog-` prefix because CRATE name already starts with `cog-`) but
the manifest URL has single prefix `cog-pose-estimation-arm`. The
upload path doesn't match the binary_url — a latent bug in the
pose cog's pipeline.
My copy now produces `dist/cog-ha-matter-arm` matching the
manifest URL `cog-ha-matter-{{ARCH}}`. Changed: Makefile (build /
sign / upload / verify / clean targets), workflow (artifact names
+ gsutil paths), README (local dry-run instructions). The
cog-pose-estimation precedent is unchanged — separate fix if/when
the user wants to align it.
What this iter does NOT do (P8 remaining):
* provision GCP_CREDENTIALS / COGNITUM_OWNER_SIGNING_KEY secrets
(user action — needs org admin access)
* actually run the workflow (needs a `cog-ha-matter-v0.1.0` tag
push, or workflow_dispatch from the Actions tab)
* append to app-registry.json in cognitum-one (separate repo PR)
Next iter: tag a v0.0.1-dev (so the workflow runs once + we see
any build-time errors on real CI runners) OR scaffold the
app-registry.json patch payload as a check-in doc.
Co-Authored-By: claude-flow <ruv@ruv.net>
84 lines
2.5 KiB
Makefile
84 lines
2.5 KiB
Makefile
# Build / sign / upload pipeline for cog-ha-matter.
|
|
# See ADR-100 §"Build pipeline" + ADR-116 §"Phases" for the contract.
|
|
# Mirrors cog-pose-estimation/cog/Makefile so the Seed runtime treats
|
|
# both cogs identically — `cognitum cog install ha-matter` works the
|
|
# same as `cognitum cog install pose-estimation`.
|
|
|
|
CRATE := cog-ha-matter
|
|
VERSION := $(shell cargo pkgid -p $(CRATE) 2>/dev/null | sed -E 's/.*#([0-9.]+).*/\1/')
|
|
GCS_BUCKET := gs://cognitum-apps/cogs
|
|
|
|
ARCHES := arm x86_64
|
|
|
|
# --- Build targets ---
|
|
|
|
.PHONY: build build-arm build-x86_64
|
|
|
|
build: build-arm build-x86_64
|
|
|
|
build-arm:
|
|
mkdir -p dist
|
|
cargo build -p $(CRATE) --release --target aarch64-unknown-linux-gnu
|
|
cp ../../target/aarch64-unknown-linux-gnu/release/$(CRATE) ./dist/$(CRATE)-arm
|
|
|
|
build-x86_64:
|
|
mkdir -p dist
|
|
cargo build -p $(CRATE) --release --target x86_64-unknown-linux-gnu
|
|
cp ../../target/x86_64-unknown-linux-gnu/release/$(CRATE) ./dist/$(CRATE)-x86_64
|
|
|
|
# --- Sign ---
|
|
|
|
.PHONY: sign sign-arm sign-x86_64
|
|
|
|
sign: sign-arm sign-x86_64
|
|
|
|
sign-arm: dist/$(CRATE)-arm
|
|
sha256sum dist/$(CRATE)-arm | cut -d' ' -f1 > dist/$(CRATE)-arm.sha256
|
|
# Signature: gcloud secrets versions access latest --secret=COGNITUM_OWNER_SIGNING_KEY \
|
|
# | openssl pkeyutl -sign -inkey /dev/stdin -rawin -in dist/$(CRATE)-arm.sha256 \
|
|
# | base64 -w0 > dist/$(CRATE)-arm.sig
|
|
@echo "TODO: wire Ed25519 sign step once COGNITUM_OWNER_SIGNING_KEY is provisioned to CI."
|
|
|
|
sign-x86_64: dist/$(CRATE)-x86_64
|
|
sha256sum dist/$(CRATE)-x86_64 | cut -d' ' -f1 > dist/$(CRATE)-x86_64.sha256
|
|
@echo "TODO: wire Ed25519 sign step once COGNITUM_OWNER_SIGNING_KEY is provisioned to CI."
|
|
|
|
# --- Upload to GCS ---
|
|
|
|
.PHONY: upload upload-arm upload-x86_64
|
|
|
|
upload: upload-arm upload-x86_64
|
|
|
|
upload-arm: dist/$(CRATE)-arm
|
|
gsutil cp dist/$(CRATE)-arm $(GCS_BUCKET)/arm/$(CRATE)-arm
|
|
|
|
upload-x86_64: dist/$(CRATE)-x86_64
|
|
gsutil cp dist/$(CRATE)-x86_64 $(GCS_BUCKET)/x86_64/$(CRATE)-x86_64
|
|
|
|
# --- Manifest ---
|
|
|
|
.PHONY: manifest
|
|
|
|
manifest:
|
|
@cargo run -p $(CRATE) --release -- --print-manifest
|
|
|
|
# --- Convenience ---
|
|
|
|
.PHONY: release verify clean
|
|
|
|
release: build sign upload manifest
|
|
@echo "Release pipeline complete for $(CRATE) v$(VERSION)"
|
|
|
|
verify:
|
|
@for arch in $(ARCHES); do \
|
|
f=dist/$(CRATE)-$$arch; \
|
|
if [ ! -f $$f ]; then echo " MISSING $$f"; continue; fi; \
|
|
actual=$$(sha256sum $$f | cut -d' ' -f1); \
|
|
expected=$$(cat $$f.sha256 2>/dev/null); \
|
|
if [ "$$actual" = "$$expected" ]; then echo " OK $$f ($$actual)"; \
|
|
else echo " FAIL $$f (expected $$expected, got $$actual)"; fi; \
|
|
done
|
|
|
|
clean:
|
|
rm -rf dist/$(CRATE)-*
|