From a9c5bd4ec9db2660840a01a8e5a876774005f1cd Mon Sep 17 00:00:00 2001 From: Ibrahim Halatci Date: Wed, 12 Aug 2026 15:19:23 +0300 Subject: [PATCH] ci: add gated arm64 (.deb) release leg to debian-hll build-package Adds a gated arm64 .deb release leg so arm64 hll packages publish to citusdata/community (the apt index feeding the stable Debian Citus images). Mirrors the merged nightly pattern (#1198) and the all-citus release leg (#1205). Everything arm64 is behind the DEB_BUILD_MULTI_ARCH repo variable (default OFF): with the gate unset the matrix stays amd64-only and the existing release pipeline is byte-for-byte unchanged. When the gate is on, arm64 runs on native ubuntu-24.04-arm runners and builds the builder + debsigner images in-job by cloning develop's tooling (this branch carries none). citus_package's docker run has no --platform flag and prefers a local image, so the native arm64 images are used automatically; amd64 keeps pulling the published images from Docker Hub. The matrix is deb-only so no RPM exclude block is needed. One file touched; no changes to debian/control.in (already Architecture: any), the deb entrypoint, or the upload script -> version strings are identical to amd64 by construction. Requires the develop jq fix (#1204) merged first for the arm64 builder images to build. Nothing runs until #1204 lands and the gate is flipped. Part of Track 2 of citusdata/citus#8612 (ARM64 Debian Docker images). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0259dd2c-9208-48f9-a8c2-8031dca8ab75 --- .github/workflows/build-package.yml | 32 ++++++++++++++++++++++++++++- 1 file changed, 31 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build-package.yml b/.github/workflows/build-package.yml index 9da4034a..f8d40e36 100644 --- a/.github/workflows/build-package.yml +++ b/.github/workflows/build-package.yml @@ -17,7 +17,8 @@ on: jobs: build_package: name: Build package - runs-on: ubuntu-latest + # arm64 legs run on native ARM64 runners; amd64 stays on ubuntu-latest. + runs-on: ${{ matrix.arch == 'arm64' && 'ubuntu-24.04-arm' || 'ubuntu-latest' }} strategy: fail-fast: false matrix: @@ -27,6 +28,9 @@ jobs: - debian/trixie - ubuntu/jammy - ubuntu/noble + # arm64 debs are gated behind the DEB_BUILD_MULTI_ARCH repo variable + # (default OFF -> amd64 only, so the existing release pipeline is unchanged). + arch: ${{ fromJSON(vars.DEB_BUILD_MULTI_ARCH == 'true' && '["amd64", "arm64"]' || '["amd64"]') }} steps: - name: Checkout repository @@ -41,6 +45,32 @@ jobs: - name: Install python requirements run: python -m pip install -r tools/packaging_automation/requirements.txt + # The arm64 builder/signer images are not published to Docker Hub yet, so + # build them natively in-job by cloning develop's tooling (this branch has + # none). "docker run" prefers a local image, so citus_package picks these up + # automatically; amd64 keeps pulling the published images from Docker Hub. + - name: Login to Docker Hub + if: matrix.arch == 'arm64' + uses: docker/login-action@v4 + with: + username: ${{ secrets.DOCKERHUB_USER_NAME }} + password: ${{ secrets.DOCKERHUB_PASSWORD }} + + - name: Build arm64 builder image + if: matrix.arch == 'arm64' + run: | + git clone -b develop --depth=1 https://github.com/citusdata/packaging.git tooling + cd tooling + export TEST=false + export TARGET_PLATFORM="${PLATFORM/\//,}" + ./update_image + env: + PLATFORM: ${{ matrix.platform }} + + - name: Build arm64 debsigner image + if: matrix.arch == 'arm64' + run: docker build -t citusdata/packaging:debsigner -f tooling/dockerfiles/debsigner/Dockerfile tooling + - name: Build packages run: | python -m tools.packaging_automation.citus_package \