- infrasynth.configs: typed multi-tenant config store (registry, service, secrets, cache) + public config_changed/config_reset signals and API - emit the declared-but-dead signals (features flags/overrides, scheduler task_completed/task_failed, tenancy tenant_updated, audit model_changed) and per-model audit field exclusions - security: permission catalog (security_permission), Django-style model-derived AutoPermission, PermissionRegistry, RoleAssignment, global-or-tenant Grant/Revoke, catalog API - consolidate the permission surface: PermissionRegistry only (drop the settings dict), IsAuthenticatedAndPermitted aliases HybridPermission, require_permission replaced by required_permissions + require_all - packaging: add [build-system]; add Forgejo publish workflow (.forgejo)
49 lines
1.4 KiB
YAML
49 lines
1.4 KiB
YAML
name: Publish
|
|
|
|
# Publishes the package to the Forgejo package registry (PyPI-compatible).
|
|
# Trigger by pushing an annotated tag, e.g.: git tag v1.0.1 && git push origin main --tags
|
|
#
|
|
# Required repository secrets (Settings → Actions → Secrets):
|
|
# FORGEJO_USERNAME your Forgejo username (e.g. moravak)
|
|
# FORGEJO_TOKEN an access token with the `write:package` scope
|
|
#
|
|
# `runs-on` must match a label registered by your Forgejo runner
|
|
# (commonly `ubuntu-latest` or `docker`).
|
|
|
|
on:
|
|
push:
|
|
tags: ["v*"]
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
env:
|
|
PYTHON_VERSION: "3.12"
|
|
# Forgejo's PyPI registry is /api/packages/<owner>/pypi
|
|
REGISTRY_URL: https://git.infrasynth.net/api/packages/moravak/pypi
|
|
|
|
jobs:
|
|
publish:
|
|
name: Build & publish
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-python@v5
|
|
with:
|
|
python-version: ${{ env.PYTHON_VERSION }}
|
|
cache: pip
|
|
|
|
- name: Install build tooling
|
|
run: python -m pip install --upgrade pip build twine
|
|
|
|
- name: Build sdist + wheel
|
|
run: python -m build
|
|
|
|
- name: Publish to Forgejo PyPI registry
|
|
env:
|
|
TWINE_USERNAME: ${{ secrets.FORGEJO_USERNAME }}
|
|
TWINE_PASSWORD: ${{ secrets.FORGEJO_TOKEN }}
|
|
run: |
|
|
python -m twine upload --non-interactive --repository-url "$REGISTRY_URL" dist/*
|