A collection of reusable workflows used by the Launchpad team
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-28 08:53:20 +00:00
.forgejo/workflows fix(publish-charm): run charmcraft upload from the charm project dir 2026-09-28 09:28:28 +02:00
README.md chore: rename secret to CHARMCRAFT_AUTH 2026-09-25 16:44:30 +02:00

lp-forgejo-actions

Reusable Forgejo Actions workflows shared across Launchpad repositories.

Workflows

build-rock.yaml

Builds a rock and uploads the resulting .rock as an artifact. By default the build runs on Launchpad via rockcraft remote-build.

jobs:
  build-rock:
    uses: launchpad/lp-forgejo-actions/.forgejo/workflows/build-rock.yaml@main
    with:
      working-directory: webapp   # optional, defaults to "."
      artifact-name: webapp-rock
    secrets:
      LAUNCHPAD_CREDENTIALS: ${{ secrets.LAUNCHPAD_CREDENTIALS }}

Set use-local-build: "true" to build on the workflow's own runner with rockcraft pack --destructive-mode instead. This path needs no LAUNCHPAD_CREDENTIALS, but because destructive mode builds directly against the runner container's rootfs it produces a rock using the runner's base.

jobs:
  build-rock:
    uses: launchpad/lp-forgejo-actions/.forgejo/workflows/build-rock.yaml@main
    with:
      artifact-name: webapp-rock
      use-local-build: "true"
Input Required Default Description
working-directory no "." Directory containing rockcraft.yaml, relative to the repo root.
artifact-name yes — Name of the uploaded artifact containing the built .rock.
commit-sha no "" Commit SHA to check out; defaults to the triggering commit.
use-local-build no "false" Build on the runner instead of on Launchpad.

publish-rock.yaml

Downloads a previously-built rock artifact and pushes it, as an OCI image, to the ps7 OCI registry (oci-registry.ps7.admin.canonical.com).

jobs:
  publish-rock:
    uses: launchpad/lp-forgejo-actions/.forgejo/workflows/publish-rock.yaml@main
    with:
      artifact-name: webapp-rock
      package-name: mobot-webapp
      package-version: ${{ forgejo.sha }}
    secrets: inherit

Requires OCI_REGISTRY_USERNAME and OCI_REGISTRY_API_KEY secrets in the calling repository.

build-charm.yaml

Builds a charm on Launchpad via charmcraft remote-build and uploads the resulting .charm as an artifact. Works both for a repo with charmcraft.yaml at its root (working-directory: .) and for a monorepo subdirectory.

jobs:
  build-charm:
    uses: launchpad/lp-forgejo-actions/.forgejo/workflows/build-charm.yaml@main
    with:
      working-directory: charm/mobot-webapp   # optional, defaults to "."
      artifact-name: webapp-charm
    secrets: inherit
Input Required Default Description
working-directory no "." Directory containing charmcraft.yaml, relative to the repo root.
artifact-name yes — Name of the uploaded artifact containing the built .charm.
commit-sha no "" Commit SHA to check out; defaults to the triggering commit.
use-local-build no "false" Build on the runner instead of on Launchpad.

Requires a LAUNCHPAD_CREDENTIALS secret in the calling repository.

Set use-local-build: "true" to build on the workflow's own runner with charmcraft pack --destructive-mode instead. This path needs no LAUNCHPAD_CREDENTIALS, but because destructive mode builds directly against the runner container's rootfs, the charm's base must match the runner image (ubuntu@24.04).

jobs:
  build-charm:
    uses: launchpad/lp-forgejo-actions/.forgejo/workflows/build-charm.yaml@main
    with:
      working-directory: charm/mobot-webapp
      artifact-name: webapp-charm
      use-local-build: "true"

publish-charm.yaml

Downloads a previously-built .charm artifact and a previously-built .rock artifact, uploads the rock to Charmhub as the charm's OCI-image resource, then uploads the charm and releases it to the given channel(s) with that resource attached.

jobs:
  publish-charm:
    needs: [build-webapp-rock, build-webapp-charm]
    uses: launchpad/lp-forgejo-actions/.forgejo/workflows/publish-charm.yaml@main
    with:
      charm-artifact-name: webapp-charm
      rock-artifact-name: webapp-rock
      charm-name: mobot-webapp
      channel: edge
    secrets: inherit
Input Required Default Description
charm-artifact-name yes — Artifact containing the .charm file.
rock-artifact-name yes — Artifact containing the .rock file used as the OCI-image resource.
charm-name yes — Name of the charm on Charmhub.
resource-name no "app-image" OCI-image resource name declared in charmcraft.yaml.
channel yes — Channel(s) to release to, comma-separated for multiple.

Requires a CHARMCRAFT_AUTH secret in the calling repository, holding the credentials produced by charmcraft login --export.

Note that artifacts cannot be shared across separate Forgejo Actions workflow runs, so the rock build, the charm build and this publish job must all live in the same workflow run.