Skip to main content

Releasing and the downloads bucket

The repository is private, so users cannot download from GitHub Releases. Every release installer is also published to a public Cloudflare R2 bucket, served at https://downloads.edgeweave.app. The website's Download page links to it and reads its version details.

What gets published​

For a tag v0.4.0, .github/workflows/release.yml builds the installer and its publish-installer job uploads (via scripts/make_release_manifest.py):

ObjectPurposeCaching
v0.4.0/EdgeWeave-Setup-0.4.0.exepermanent, versioned copyforever (immutable)
latest/EdgeWeave-Setup.exestable link behind every Download button5 minutes
latest.jsonversion, date, size, SHA-256, URLs (read by /download)1 minute

latest.json is uploaded last, so it never points at a file that has not finished uploading. A pre-release tag such as v0.5.0-beta.1 only gets its versioned copy: latest/ and latest.json are left alone.

The script refuses to publish if the tag and the installer's own version differ (the installer's version comes from frontend/package.json), so a mislabelled build can never become "latest".

One-time setup​

You need the Cloudflare account that owns edgeweave.app.

1. Create the bucket​

R2 Object Storage > Create bucket. Name it edgeweave-releases, leave the location on automatic. This is separate from the private edgeweave-modules bucket the marketplace uses.

2. Give it a public address​

Open the bucket, then Settings > Custom Domains > Add, enter downloads.edgeweave.app and confirm. Because the domain's DNS is on Cloudflare, the record is created for you. Wait until the domain shows Active.

Do not turn on the r2.dev public URL: it is rate-limited and meant for testing.

3. Allow the site to read latest.json​

In the bucket, Settings > CORS Policy > Add and paste:

[
{
"AllowedOrigins": ["https://edgeweave.app", "https://www.edgeweave.app"],
"AllowedMethods": ["GET", "HEAD"],
"AllowedHeaders": ["*"],
"MaxAgeSeconds": 3600
}
]

Without this the Download page still works (the button is a plain link), but it cannot show the version, size and checksum.

4. Create an upload token​

R2 Object Storage > Manage API Tokens > Create API token. Choose Object Read & Write, limit it to the edgeweave-releases bucket, and create it. Cloudflare shows the Access Key ID and Secret Access Key once, plus the S3 endpoint (https://<account-id>.r2.cloudflarestorage.com). Keep that page open for the next step.

5. Add GitHub secrets​

In the workflow_app repository: Settings > Secrets and variables > Actions > New repository secret:

SecretValue
R2_ENDPOINT_URLthe S3 endpoint above
R2_ACCESS_KEY_IDthe Access Key ID
R2_SECRET_ACCESS_KEYthe Secret Access Key

Optional repository variables (the defaults are shown): R2_RELEASES_BUCKET (edgeweave-releases) and DOWNLOADS_BASE_URL (https://downloads.edgeweave.app).

Until the three secrets exist, publish-installer only prints a warning and the release still succeeds.

Releasing a version​

  1. Set version in frontend/package.json and merge it to main.

  2. Tag it: git tag v0.5.0 && git push origin v0.5.0.

  3. Watch Actions > Release. publish-installer runs after the installer is built.

  4. Check it:

    curl -sI https://downloads.edgeweave.app/latest/EdgeWeave-Setup.exe
    curl -s https://downloads.edgeweave.app/latest.json

Publishing a version that is already released​

The first time (and for any release made before publish-installer existed), publish by hand. Download the installer from the GitHub release page (it arrives as EdgeWeave.Setup.0.4.0.exe; the script accepts that name), then:

python scripts/make_release_manifest.py EdgeWeave.Setup.0.4.0.exe --tag v0.4.0 --out upload

and upload the contents of upload/ to the bucket in this order: the v0.4.0/ file, then latest/EdgeWeave-Setup.exe, then latest.json. Any S3-compatible tool works (the AWS CLI with --endpoint-url, rclone, or the Cloudflare dashboard's upload button). Use the same cache headers as release.yml if you can.

Code signing​

The installer is not code-signed yet, so Windows SmartScreen warns on first run. The Download page explains this. When a signing certificate is in place, sign in the build-windows job (the workflow currently sets CSC_IDENTITY_AUTO_DISCOVERY: false) and delete the SmartScreen paragraph from docs/src/pages/download.js.