infrasynth-backend-kit/.forgejo/workflows/publish.yml
jcv-dev a2930426b4 feat: tenant configs, live signals, and automatic permission management
- infrasynth.configs: typed multi-tenant config store (registry, service,
  secrets, cache) + public config_changed/config_reset signals and API
- emit the declared-but-dead signals (features flags/overrides, scheduler
  task_completed/task_failed, tenancy tenant_updated, audit model_changed)
  and per-model audit field exclusions
- security: permission catalog (security_permission), Django-style
  model-derived AutoPermission, PermissionRegistry, RoleAssignment,
  global-or-tenant Grant/Revoke, catalog API
- consolidate the permission surface: PermissionRegistry only (drop the
  settings dict), IsAuthenticatedAndPermitted aliases HybridPermission,
  require_permission replaced by required_permissions + require_all
- packaging: add [build-system]; add Forgejo publish workflow (.forgejo)
2026-09-29 17:06:54 -05:00

49 lines
1.4 KiB
YAML

name: Publish
# Publishes the package to the Forgejo package registry (PyPI-compatible).
# Trigger by pushing an annotated tag, e.g.: git tag v1.0.1 && git push origin main --tags
#
# Required repository secrets (Settings → Actions → Secrets):
# FORGEJO_USERNAME your Forgejo username (e.g. moravak)
# FORGEJO_TOKEN an access token with the `write:package` scope
#
# `runs-on` must match a label registered by your Forgejo runner
# (commonly `ubuntu-latest` or `docker`).
on:
push:
tags: ["v*"]
workflow_dispatch:
permissions:
contents: read
env:
PYTHON_VERSION: "3.12"
# Forgejo's PyPI registry is /api/packages/<owner>/pypi
REGISTRY_URL: https://git.infrasynth.net/api/packages/moravak/pypi
jobs:
publish:
name: Build & publish
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: ${{ env.PYTHON_VERSION }}
cache: pip
- name: Install build tooling
run: python -m pip install --upgrade pip build twine
- name: Build sdist + wheel
run: python -m build
- name: Publish to Forgejo PyPI registry
env:
TWINE_USERNAME: ${{ secrets.FORGEJO_USERNAME }}
TWINE_PASSWORD: ${{ secrets.FORGEJO_TOKEN }}
run: |
python -m twine upload --non-interactive --repository-url "$REGISTRY_URL" dist/*