Pulumi SDK docs - Java #10
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| permissions: write-all # Equivalent to default permissions + id-token: write | |
| env: | |
| ESC_ACTION_OIDC_AUTH: true | |
| ESC_ACTION_OIDC_ORGANIZATION: pulumi | |
| ESC_ACTION_OIDC_REQUESTED_TOKEN_TYPE: urn:pulumi:token-type:access_token:organization | |
| ESC_ACTION_ENVIRONMENT: github-secrets/pulumi-docs | |
| ESC_ACTION_EXPORT_ENVIRONMENT_VARIABLES: GITHUB_TOKEN=PULUMI_BOT_TOKEN | |
| name: Pulumi SDK docs - Java | |
| on: | |
| repository_dispatch: | |
| types: | |
| - pulumi-java-sdk | |
| workflow_dispatch: | |
| inputs: | |
| version: | |
| description: "pulumi-java version (e.g. 0.10.0, with or without leading 'v')" | |
| required: true | |
| skip_auto_merge: | |
| description: "Skip enabling auto-merge on the generated PR (for testing)" | |
| type: boolean | |
| default: false | |
| publish_only: | |
| description: "Generate + publish the versioned snapshot only; skip the latest-docs PR (for backfill)" | |
| type: boolean | |
| default: false | |
| publish_versioned: | |
| description: "Also publish an immutable versioned snapshot to the archive bucket" | |
| type: boolean | |
| default: false | |
| target_env: | |
| description: "Versioned-docs publish target (when publishing)" | |
| type: choice | |
| options: | |
| - production | |
| - testing | |
| default: production | |
| jobs: | |
| pull-request: | |
| runs-on: ubuntu-latest | |
| needs: build-pulumi-sdk-java-docs | |
| if: needs.build-pulumi-sdk-java-docs.outputs.has_changes == 'true' && github.event.inputs.publish_only != 'true' | |
| steps: | |
| - name: Fetch secrets from ESC | |
| id: esc-secrets | |
| uses: pulumi/esc-action@v2 | |
| - name: checkout docs repo | |
| uses: actions/checkout@v6 | |
| - name: set the java sdk version | |
| env: | |
| RAW_VERSION: ${{ github.event.inputs.version || github.event.client_payload.ref }} | |
| run: | | |
| echo "JAVA_SDK_VERSION=${RAW_VERSION#v}" >> $GITHUB_ENV | |
| - name: pull-request | |
| id: create-pr | |
| uses: repo-sync/pull-request@v2 | |
| with: | |
| source_branch: "pulumi-sdk-java-docs/${{ github.run_id }}-${{ github.run_number }}" | |
| destination_branch: "master" | |
| pr_title: "Generate Pulumi SDK docs - Java @v${{ env.JAVA_SDK_VERSION }}" | |
| pr_body: | | |
| Automated PR generated by the [Pulumi SDK docs - Java](https://github.com/${{ github.repository }}/blob/master/.github/workflows/pulumi-sdk-java-docs.yml) workflow (`.github/workflows/pulumi-sdk-java-docs.yml`). | |
| Workflow run: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} | |
| pr_label: "automation/pulumi-sdk-java-docs,automation/merge" | |
| github_token: ${{ steps.esc-secrets.outputs.PULUMI_BOT_TOKEN }} | |
| - name: Enable auto-merge | |
| if: steps.create-pr.outputs.pr_created == 'true' && github.event.inputs.skip_auto_merge != 'true' | |
| run: gh pr merge ${{ steps.create-pr.outputs.pr_number }} --auto --squash | |
| env: | |
| GITHUB_TOKEN: ${{ steps.esc-secrets.outputs.PULUMI_BOT_TOKEN }} | |
| build-pulumi-sdk-java-docs: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| has_changes: ${{ steps.commit.outputs.has_changes }} | |
| steps: | |
| - name: Fetch secrets from ESC | |
| id: esc-secrets | |
| uses: pulumi/esc-action@v2 | |
| - name: set the java sdk version | |
| env: | |
| RAW_VERSION: ${{ github.event.inputs.version || github.event.client_payload.ref }} | |
| run: | | |
| echo "JAVA_SDK_VERSION=${RAW_VERSION#v}" >> $GITHUB_ENV | |
| - name: checkout docs repo | |
| uses: actions/checkout@v6 | |
| with: | |
| path: docs | |
| - name: checkout pulumi-java repo | |
| uses: actions/checkout@v6 | |
| with: | |
| repository: pulumi/pulumi-java | |
| path: pulumi-java | |
| ref: v${{ env.JAVA_SDK_VERSION }} | |
| submodules: recursive | |
| - name: Install Java | |
| uses: actions/setup-java@v5 | |
| with: | |
| java-version: '17' | |
| distribution: temurin | |
| - name: Install Hugo | |
| uses: peaceiris/actions-hugo@v3 | |
| with: | |
| hugo-version: '0.157.0' | |
| extended: true | |
| - name: Install node | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: '24.x' | |
| cache: 'yarn' | |
| cache-dependency-path: | | |
| docs/yarn.lock | |
| docs/infrastructure/yarn.lock | |
| docs/theme/yarn.lock | |
| docs/theme/stencil/yarn.lock | |
| - name: Install Vale (required by scripts/ensure.sh) | |
| run: | | |
| VALE_VERSION="3.14.1" | |
| VALE_SHA256="ff2b49ffaa9dcd246fd5008f03ff67746d2790b75bf4d3657e2fb9530fb96db3" | |
| curl -fsSL -o /tmp/vale.tar.gz "https://github.com/errata-ai/vale/releases/download/v${VALE_VERSION}/vale_${VALE_VERSION}_Linux_64-bit.tar.gz" | |
| echo "${VALE_SHA256} /tmp/vale.tar.gz" | sha256sum -c - | |
| sudo tar -xz -C /usr/local/bin vale -f /tmp/vale.tar.gz | |
| rm /tmp/vale.tar.gz | |
| - run: make ensure | |
| working-directory: docs | |
| - name: Generate Java SDK docs | |
| run: ./scripts/gen_javadoc.sh | |
| working-directory: docs | |
| env: | |
| JAVA_REPO: ${{ github.workspace }}/pulumi-java | |
| - name: git status | |
| run: git status && git diff | |
| working-directory: docs | |
| - name: commit changes | |
| id: commit | |
| run: | | |
| git config --local user.email "bot@pulumi.com" | |
| git config --local user.name "pulumi-bot" | |
| git checkout -b pulumi-sdk-java-docs/${{ github.run_id }}-${{ github.run_number }} | |
| git add static-prebuilt/ | |
| if git diff --cached --quiet; then | |
| echo "No changes to commit" | |
| echo "has_changes=false" >> $GITHUB_OUTPUT | |
| else | |
| git commit -m "Regenerating Pulumi SDK Java docs for pulumi-java@${{ env.JAVA_SDK_VERSION }}" | |
| if [ "${{ github.event.inputs.publish_only }}" != "true" ]; then | |
| git push origin pulumi-sdk-java-docs/${{ github.run_id }}-${{ github.run_number }} | |
| fi | |
| echo "has_changes=true" >> $GITHUB_OUTPUT | |
| fi | |
| working-directory: docs | |
| # --- Versioned docs: archive this SDK release as an immutable snapshot. --------- | |
| # Gated on publish_versioned (dispatch) or vars.VERSIONED_DOCS_ENABLED; real releases | |
| # are unaffected until that variable is set. Runs after commit, continue-on-error, so | |
| # a publish hiccup never blocks the docs PR. | |
| - name: Resolve versioned-docs publish target | |
| id: vdocs | |
| if: ${{ github.event.inputs.publish_versioned == 'true' || vars.VERSIONED_DOCS_ENABLED == 'true' }} | |
| run: | | |
| TARGET="${{ github.event.inputs.target_env || 'production' }}" | |
| if [ "$TARGET" = "testing" ]; then | |
| { | |
| echo "role_arn=arn:aws:iam::571684982431:role/versioned-docs-publisher-testing" | |
| echo "bucket=pulumi-docs-versioned-testing" | |
| echo "distribution_id=E6LY02AG7JXEZ" | |
| echo "site=https://www.pulumi-test.io" | |
| } >> "$GITHUB_OUTPUT" | |
| else | |
| { | |
| echo "role_arn=arn:aws:iam::388588623842:role/versioned-docs-publisher-production" | |
| echo "bucket=pulumi-docs-versioned-production" | |
| echo "distribution_id=${{ vars.VERSIONED_DOCS_PROD_DISTRIBUTION_ID }}" | |
| echo "site=https://www.pulumi.com" | |
| } >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Configure AWS credentials (versioned-docs publisher) | |
| if: ${{ steps.vdocs.outputs.bucket != '' }} | |
| continue-on-error: true | |
| uses: aws-actions/configure-aws-credentials@v6 | |
| with: | |
| role-to-assume: ${{ steps.vdocs.outputs.role_arn }} | |
| role-session-name: versioned-docs-sdk-publish | |
| aws-region: us-west-2 | |
| - name: Publish versioned snapshot | |
| if: ${{ steps.vdocs.outputs.bucket != '' }} | |
| continue-on-error: true | |
| working-directory: docs | |
| run: | | |
| # Backfill (publish_only) archives an OLD release: do not mark it "latest". | |
| EXTRA=() | |
| [ "${{ github.event.inputs.publish_only }}" = "true" ] && EXTRA+=(--no-mark-latest) | |
| ./scripts/versioned-docs/publish-version.sh --tool java \ | |
| --version "v${{ env.JAVA_SDK_VERSION }}" \ | |
| --src static-prebuilt/docs/reference/pkg/java \ | |
| --live-root /docs/reference/pkg/java/ \ | |
| --bucket "${{ steps.vdocs.outputs.bucket }}" --label "Java SDK" \ | |
| --distribution-id "${{ steps.vdocs.outputs.distribution_id }}" \ | |
| --site "${{ steps.vdocs.outputs.site }}" \ | |
| "${EXTRA[@]}" | |
| notify: | |
| if: failure() | |
| name: Send slack notification | |
| runs-on: ubuntu-latest | |
| needs: [pull-request, build-pulumi-sdk-java-docs] | |
| steps: | |
| - name: Fetch secrets from ESC | |
| id: esc-secrets | |
| uses: pulumi/esc-action@v2 | |
| - name: Slack Notification | |
| uses: docker://sholung/action-slack-notify:v2.3.0 | |
| env: | |
| SLACK_CHANNEL: docs-ops | |
| SLACK_COLOR: "#F54242" | |
| SLACK_MESSAGE: "Pulumi SDK docs - Java build failure in pulumi/docs repo" | |
| SLACK_USERNAME: docsbot | |
| SLACK_WEBHOOK: ${{ steps.esc-secrets.outputs.SLACK_WEBHOOK_URL }} | |
| SLACK_ICON: https://www.pulumi.com/logos/brand/avatar-on-white.png |