mirror of
https://github.com/element-hq/synapse.git
synced 2026-08-14 20:10:26 +00:00
Add explicit permissions blocks so workflows and jobs no longer rely on GitHub's default GITHUB_TOKEN scopes. Document each granted permission inline with the workflow reason it is needed, so future edits can tell the difference between repository checkout access, package publishing, OIDC authentication, issue creation, and release publishing. Move Docker package and OIDC permissions from the workflow level to the image build and merge jobs that need them. Keep release artifact builds read-only and grant contents: write only to the tag-only release upload job. Grant issues: write only to the scheduled failure issue-creation jobs, pull-requests: read only to the paths-filter job, and disable the token entirely for workflows that do not need the default GITHUB_TOKEN.
106 lines
3.5 KiB
YAML
106 lines
3.5 KiB
YAML
name: Deploy the documentation
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
# For bleeding-edge documentation
|
|
- develop
|
|
# For documentation specific to a release
|
|
- 'release-v*'
|
|
# stable docs
|
|
- master
|
|
|
|
workflow_dispatch:
|
|
|
|
# No default GITHUB_TOKEN permissions are needed at the workflow level.
|
|
permissions: {}
|
|
|
|
jobs:
|
|
pre:
|
|
name: Calculate variables for GitHub Pages deployment
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
# Figure out the target directory.
|
|
#
|
|
# The target directory depends on the name of the branch
|
|
#
|
|
- name: Get the target directory name
|
|
id: vars
|
|
run: |
|
|
# first strip the 'refs/heads/' prefix with some shell foo
|
|
branch="${GITHUB_REF#refs/heads/}"
|
|
|
|
case $branch in
|
|
release-*)
|
|
# strip 'release-' from the name for release branches.
|
|
branch="${branch#release-}"
|
|
;;
|
|
master)
|
|
# deploy to "latest" for the master branch.
|
|
branch="latest"
|
|
;;
|
|
esac
|
|
|
|
# finally, set the 'branch-version' var.
|
|
echo "branch-version=$branch" >> "$GITHUB_OUTPUT"
|
|
outputs:
|
|
branch-version: ${{ steps.vars.outputs.branch-version }}
|
|
|
|
################################################################################
|
|
pages-docs:
|
|
name: GitHub Pages
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
# Required to check out the repository and publish documentation.
|
|
contents: write
|
|
needs:
|
|
- pre
|
|
steps:
|
|
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
|
|
with:
|
|
# Fetch all history so that the schema_versions script works.
|
|
fetch-depth: 0
|
|
|
|
- name: Setup mdbook
|
|
uses: peaceiris/actions-mdbook@ee69d230fe19748b7abf22df32acaa93833fad08 # v2.0.0
|
|
with:
|
|
mdbook-version: '0.5.2'
|
|
|
|
- name: Set version of docs
|
|
run: echo 'window.SYNAPSE_VERSION = "${{ needs.pre.outputs.branch-version }}";' > ./docs/website_files/version.js
|
|
|
|
- name: Setup python
|
|
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
|
with:
|
|
python-version: "3.x"
|
|
|
|
- run: "pip install 'packaging>=20.0' 'GitPython>=3.1.20'"
|
|
|
|
- name: Build the documentation
|
|
# mdbook will only create an index.html if we're including docs/README.md in SUMMARY.md.
|
|
# However, we're using docs/README.md for other purposes and need to pick a new page
|
|
# as the default. Let's opt for the welcome page instead.
|
|
run: |
|
|
mdbook build
|
|
cp book/welcome_and_overview.html book/index.html
|
|
|
|
- name: Prepare and publish schema files
|
|
run: |
|
|
sudo apt-get update && sudo apt-get install -y yq
|
|
mkdir -p book/schema
|
|
# Remove developer notice before publishing.
|
|
rm schema/v*/Do\ not\ edit\ files\ in\ this\ folder
|
|
# Copy schema files that are independent from current Synapse version.
|
|
cp -r -t book/schema schema/v*/
|
|
# Convert config schema from YAML source file to JSON.
|
|
yq < schema/synapse-config.schema.yaml \
|
|
> book/schema/synapse-config.schema.json
|
|
|
|
# Deploy to the target directory.
|
|
- name: Deploy to gh pages
|
|
uses: peaceiris/actions-gh-pages@84c30a85c19949d7eee79c4ff27748b70285e453 # v4.1.0
|
|
with:
|
|
github_token: ${{ secrets.GITHUB_TOKEN }}
|
|
publish_dir: ./book
|
|
destination_dir: ./${{ needs.pre.outputs.branch-version }}
|