ci: publish fpr-core/fpr-netty/fpr-bench to the Gitea Maven registry
Publish Maven packages / publish (push) Successful in 47s

maven.relism.dev is down, and Flash5 depends on fpr-core to build. Mirrors
Flash5's own .gitea/workflows/publish-maven.yml exactly: on push to master,
stamp every module with a commit-scoped version (1.1.0-<short-sha>, since
Gitea's Maven registry refuses to re-publish an existing name+version) and
deploy to Relism's Gitea package registry with a write:package PAT (Gitea's
own job token can't publish to package registries at all).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Zakaria El Orche
2026-08-20 10:58:23 +00:00
co-authored by Claude Sonnet 5
parent c72b811145
commit 36216cd401
2 changed files with 74 additions and 0 deletions
+24
View File
@@ -0,0 +1,24 @@
<settings xmlns="http://maven.apache.org/SETTINGS/1.0.0"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/SETTINGS/1.0.0 http://maven.apache.org/xsd/settings-1.0.0.xsd">
<!--
Used only by .gitea/workflows/publish-maven.yml (mvn -s .gitea/maven-settings.xml deploy).
Not used for local builds. PACKAGES_TOKEN is a real personal access token (write:package
scope) on the Relism account, read from the env var the workflow exports — never written
to disk. Deliberately not Gitea's own per-job GITEA_TOKEN: that token can't publish to
any package registry at all, a known unimplemented limitation
(https://github.com/go-gitea/gitea/issues/23642) — same finding already confirmed against
this same Gitea instance for Flash5's identical workflow.
Basic auth (username/password): the <httpHeaders> form Gitea's own docs show for this is
honored by Maven's resolver (used for reading <repositories>) but not reliably by the
wagon-http provider maven-deploy-plugin actually uploads through.
-->
<servers>
<server>
<id>gitea</id>
<username>Relism</username>
<password>${env.PACKAGES_TOKEN}</password>
</server>
</servers>
</settings>
+50
View File
@@ -0,0 +1,50 @@
name: Publish Maven packages
# FastPathRouter's own POM keeps `1.1.0` as its committed version — that's what local
# `mvn install` (Flash's normal dev loop, see its pom.xml `fpr-core` dependency comment)
# always produces, and changing it here would break that. Gitea's Maven registry, unlike a
# real snapshot repository, refuses to re-publish an existing name+version (must delete
# first — see https://docs.gitea.com/usage/packages/maven#publish-a-package), so every push
# instead publishes under a throwaway version stamped with the commit it built from
# (`1.1.0-<short-sha>`), via `versions:set` on a checkout copy — never touching the
# committed POMs. Consumers (Flash5's pom.xml) pin `fpr-core`'s version to one specific
# published build and bump it by hand to pick up newer FastPathRouter changes — same
# precedent as Flash5's own publish-maven.yml, which this workflow otherwise mirrors exactly.
on:
push:
branches: [master]
jobs:
publish:
runs-on: ubuntu-latest
# No actions/checkout here on purpose: it's a Node-based action, and this container
# (chosen for its preinstalled mvn/JDK 21) has no Node — checkout would fail with
# "node: executable file not found". A plain git clone needs neither.
container:
image: maven:3.9-eclipse-temurin-21
steps:
- name: Checkout
run: |
apt-get update && apt-get install -y --no-install-recommends git
git clone https://git.pixel-services.com/Relism/FastPathRouter.git .
git checkout ${{ gitea.sha }}
- name: Stamp every module with a commit-scoped version
run: |
SHORT_SHA=$(git rev-parse --short HEAD)
mvn -B versions:set -DnewVersion="1.1.0-${SHORT_SHA}" -DprocessAllModules=true -DgenerateBackupPoms=false
echo "Publishing as 1.1.0-${SHORT_SHA}"
- name: Deploy to the Gitea Maven registry
env:
# Not GITEA_TOKEN: Gitea's own job token can't publish to package registries at
# all (a known, still-unimplemented limitation — see
# https://github.com/go-gitea/gitea/issues/23642). Confirmed by testing on this same
# instance for Flash5's identical workflow: GITEA_TOKEN authenticated fine against
# the plain API but still got 401 from this endpoint no matter the auth style.
# PACKAGES_TOKEN is a real PAT with write:package scope.
PACKAGES_TOKEN: ${{ secrets.PACKAGES_TOKEN }}
run: |
mvn -B -s .gitea/maven-settings.xml -DskipTests deploy \
-DaltReleaseDeploymentRepository=gitea::https://git.pixel-services.com/api/packages/Relism/maven \
-DaltSnapshotDeploymentRepository=gitea::https://git.pixel-services.com/api/packages/Relism/maven