Releasing
Releases are cut by a maintainer, from main, by image-build.yml on
the self-hosted runners: the same run that builds and tests every image
publishes them.
Versions
Section titled “Versions”Releases are dated: vYYYY.MM.DD, then -2, -3… for more the same
day - several a day is normal. A release is cumulative and only the
latest is supported (security policy); releases are
marked alpha in their name, not as pre-releases.
Cutting one
Section titled “Cutting one”- The notes:
.github/release-notes/<version>.md, written by hand for operators - a short Highlights section, then one section per theme, each with its emoji (🌐 network, 🖥️ Controller, 🐛 fixes, ⚠️ upgrade notes…), built fromgit log <previous tag>..HEAD, whose<theme>:subjects give the grouping (the notes’ README). The workflow refuses to start without them. - Security fixes - an upstream component, a Go module, the Go
toolchain, an npm package, or Janus’s own code: the notes need a
## 🔒 Securitysection, drafted withmake upstream-security-notes FROM=<previous tag> RELEASE=<version>and rewritten for operators - which nodes, what to do. - Dispatch
image-build.ymlonmainwithrelease_version.
What the run publishes
Section titled “What the run publishes”Once every test job passed, the publishing job - on the runner labelled
janus-publish, the only one trusted to build what’s published:
- builds the signed release bundle and checks its signatures against the committed certificate;
- creates the tag and the GitHub release - the alpha warning, the notes,
the changelog link - with the images, the bundle, the build inputs of
custom images, the
janusctlpackages, the Terraform provider, the Controller’s image reference,security.jsonand an SBOM; - pushes the Controller’s image to Docker Hub (
latest, the commit, the version); - publishes
janusctlto the apt repository; - deploys the docs -
/docs/now follows the release; - publishes a security advisory for each fix of Janus’s own code, and for an upstream fix rated high or worse.
A release fixing something gets ”🔒 security update” in its name, and the Controller marks the update on the nodes it concerns.
Without a release
Section titled “Without a release”Dispatched without release_version, the same run builds and tests
everything and uploads the images as workflow artifacts - the way to
prove a change before a release. It also pushes the Controller’s
latest image.