Releasing and the downloads bucket
The repository is private, so users cannot download from GitHub Releases. Every
release installer is also published to a public Cloudflare R2 bucket, served
at https://downloads.edgeweave.app. The website's Download page
links to it and reads its version details.
What gets published
For a tag v0.4.0, .github/workflows/release.yml builds the installer and its
publish-installer job uploads (via scripts/make_release_manifest.py):
| Object | Purpose | Caching |
|---|---|---|
v0.4.0/EdgeWeave-Setup-0.4.0.exe | permanent, versioned copy | forever (immutable) |
latest/EdgeWeave-Setup.exe | stable link behind every Download button | 5 minutes |
latest.json | version, date, size, SHA-256, URLs (read by /download) | 1 minute |
latest.json is uploaded last, so it never points at a file that has not finished
uploading. A pre-release tag such as v0.5.0-beta.1 only gets its versioned
copy: latest/ and latest.json are left alone.
The script refuses to publish if the tag and the installer's own version differ
(the installer's version comes from frontend/package.json), so a mislabelled
build can never become "latest".
One-time setup
You need the Cloudflare account that owns edgeweave.app.
1. Create the bucket
R2 Object Storage > Create bucket. Name it edgeweave-releases, leave the
location on automatic. This is separate from the private edgeweave-modules bucket
the marketplace uses.
2. Give it a public address
Open the bucket, then Settings > Custom Domains > Add, enter
downloads.edgeweave.app and confirm. Because the domain's DNS is on Cloudflare,
the record is created for you. Wait until the domain shows Active.
Do not turn on the r2.dev public URL: it is rate-limited and meant for testing.
3. Allow the site to read latest.json
In the bucket, Settings > CORS Policy > Add and paste:
[
{
"AllowedOrigins": ["https://edgeweave.app", "https://www.edgeweave.app"],
"AllowedMethods": ["GET", "HEAD"],
"AllowedHeaders": ["*"],
"MaxAgeSeconds": 3600
}
]
Without this the Download page still works (the button is a plain link), but it cannot show the version, size and checksum.
4. Create an upload token
R2 Object Storage > Manage API Tokens > Create API token. Choose Object
Read & Write, limit it to the edgeweave-releases bucket, and create it. Cloudflare
shows the Access Key ID and Secret Access Key once, plus the S3 endpoint
(https://<account-id>.r2.cloudflarestorage.com). Keep that page open for the next step.
5. Add GitHub secrets
In the workflow_app repository: Settings > Secrets and variables > Actions >
New repository secret:
| Secret | Value |
|---|---|
R2_ENDPOINT_URL | the S3 endpoint above |
R2_ACCESS_KEY_ID | the Access Key ID |
R2_SECRET_ACCESS_KEY | the Secret Access Key |
Optional repository variables (the defaults are shown): R2_RELEASES_BUCKET
(edgeweave-releases) and DOWNLOADS_BASE_URL (https://downloads.edgeweave.app).
Until the three secrets exist, publish-installer only prints a warning and the
release still succeeds.
Releasing a version
-
Set
versioninfrontend/package.jsonand merge it tomain. -
Tag it:
git tag v0.5.0 && git push origin v0.5.0. -
Watch Actions > Release.
publish-installerruns after the installer is built. -
Check it:
curl -sI https://downloads.edgeweave.app/latest/EdgeWeave-Setup.execurl -s https://downloads.edgeweave.app/latest.json
Publishing a version that is already released
The first time (and for any release made before publish-installer existed), publish
by hand. Download the installer from the GitHub release page (it arrives as
EdgeWeave.Setup.0.4.0.exe; the script accepts that name), then:
python scripts/make_release_manifest.py EdgeWeave.Setup.0.4.0.exe --tag v0.4.0 --out upload
and upload the contents of upload/ to the bucket in this order: the v0.4.0/ file,
then latest/EdgeWeave-Setup.exe, then latest.json. Any S3-compatible tool works
(the AWS CLI with --endpoint-url, rclone, or the Cloudflare dashboard's
upload button). Use the same cache headers as release.yml if you can.
Code signing
The installer is not code-signed yet, so Windows SmartScreen warns on first run. The
Download page explains this. When a signing certificate is in place, sign in the
build-windows job (the workflow currently sets CSC_IDENTITY_AUTO_DISCOVERY: false)
and delete the SmartScreen paragraph from docs/src/pages/download.js.