Skip to content

ci: 每晚安检查构建,自动打 tag 并发布 patch release - #100

Merged
IchenDEV merged 1 commit into
mainfrom
agent/qa/nightly-release-workflow
Sep 18, 2026
Merged

IchenDEV merged 1 commit into
mainfrom
agent/qa/nightly-release-workflow

Conversation

@IchenDEV

Copy link
Copy Markdown
Owner

变更

把发布方向反过来:每晚安检查 main → 有变更则自动打 tag 并发布正式 patch release。手动 tag 触发的 release.yml 保留为兜底。

三个层次

  1. .github/workflows/nightly-release.yml(新增)

    • schedule: cron "0 12 * * *"(= 每天 20:00 Asia/Shanghai)+ workflow_dispatch
    • concurrency: group: nightly-release,cancel-in-progress: false(不会取消正在发布的那次)
    • plan(ubuntu)→ validate(仓库检查 + swift test)→ 复用发布流水线并 create_tag: true
    • changed=false 时后两个 job 直接跳过,并在 log + step summary 写明原因(无新提交、最新 tag 等)
  2. .github/workflows/release-artifact.yml(新增,workflow_call)
    把 release.yml 的 Sign/Verify/Publish 整段抽成 reusable workflow,两处入口共用,避免漂移:凭证校验 → 证书导入(OpenSSL 3 -legacy 回退)→ Metal toolchain → 签名构建 → verify-release-artifact.sh → Developer ID 公证(适用时)→ 校验和 → draft 发布 → 回下载校验 → 转正式 release。job 名仍是 Sign, Verify & Publish。输入 version / tag / create_tag / require_ancestor。

    • nightly 路径在 build 前要求 HEAD == origin/main tip、远程无同名 tag,然后创建附注 tag 并 push;不移动/不删除/不覆盖任何已发布资产。
  3. scripts/nightly-release-plan.sh(新增,只读规划器)
    取最高稳定版 tag(数值序,忽略 prerelease/build)→ 与分支 tip 比较 → 输出 changed / version(patch 递增)/ latest_tag / head_sha / commit_count / commit_summary / reason。输出的版本再过一遍 release-version.sh 校验。

release.yml 只保留 validate job(SemVer + main ancestry、仓库检查、单测)并改为调用 reusable workflow;v* 触发不变。

SDLC(高风险)

新增 docs/sdlc/changes/2026-09-18-nightly-release-pipeline/:intent / spec / plan / verification。spec 记录了标签写入、并发、无变更夜、密钥与失败containment 的设计与拒绝过的替代方案;rollback = 关掉/回滚 nightly workflow,手动 tag 流程不受影响。

需要确认的两个假设

  • a) 定时时间:按北京时间 20:00(0 12 * * * UTC)实现。
  • b) 发布形态:有变更即发布正式 patch release(非 prerelease)。若想要 nightly-* 预发布包,改动很小(把 version/tag 换成 nightly-<date>,gh release create 加 --prerelease)。

测试与验证

  • bash scripts/tests/test_nightly_release_plan.sh → passed(首次 0.0.1 / 无变更跳过并给 reason / patch 递增 0.0.46 / 9→10 进位 0.1.10 / 数值序 v0.0.10 > v0.0.9 / 忽略 prerelease tag / 未知分支与缺参 fail closed / workflow 接线断言 / 共享流水线护栏断言)
  • bash scripts/tests/test_release_version.sh、test_build_version.sh → passed(护栏断言改指 release-artifact.yml)
  • bash scripts/sdlc-checks.sh → passed;bash scripts/ci-basic-checks.sh → passed
  • 三个 workflow YAML 均可解析(jobs: release [validate, release]、artifact [release]、nightly [plan, validate, release])
  • swift build + 聚焦 swift test → 397 passed / 8 skipped / 0 failures(无 App 代码改动)
  • PR CI(Contract & Tests / Release-style App Build / SDLC Gate)待跑

真实发布路径无法在 PR 上演练:production 环境限制了 tag 部署,且 workflow 的改动只有合并后在默认分支才生效。合并后可用 workflow_dispatch 观察规划输出/跳过原因;注意若当时 main 有新提交,dispatch 会真的发布。

交付

  • 分支:agent/qa/nightly-release-workflow(从最新 main)
  • commit:efec93e — ci: add scheduled nightly release pipeline
  • PR:(见下方链接,base main,未 merge)

单条命令均 <8 分钟。

Nightly releases are now driven by change detection instead of a manual tag: a scheduled workflow inspects main against the latest stable release tag and, when there are new commits, creates the next patch tag and publishes through the same signed pipeline as the tag workflow. release.yml keeps its tag trigger as a manual fallback.

Extract the sign/verify/publish job into the reusable release-artifact.yml so both entry points cannot drift, add scripts/nightly-release-plan.sh for change detection and patch bumping with shell tests wired into ci-basic-checks.sh, and record the change in docs/sdlc/changes/2026-09-18-nightly-release-pipeline/.

Co-authored-by: multica-agent <github@multica.ai>
@IchenDEV
IchenDEV merged commit 2ece2d7 into main Sep 18, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant