mirror of
https://github.com/certbot/certbot.git
synced 2026-07-26 07:39:52 +02:00
90f7404b19e829a6f3d73a40ce0056164efb9329
This PR automates the release process steps to: - update the candidate branch with the contents of the release branch on the repo in the subfolder - create a PR merging the candidate branch into main - create a new branch without the version bump. usually `1.2.x`, unless it's a point release. - if it's a point release, create a PR merging the new branch without version bumps into the existing `1.2.x` branch. This draws from steps 10, 12, and 13. Step 10 should still have the code to push to pypi, since that's a different though, though I think that could move here in the future as well. My general design philosophy was "error out instead of letting the script put git into a bad state," with the exception of PR creation which seemed safe to skip and continue. I've also added some flags, mostly to make testing this easier, but could be useful for re-running the script as well. Unlike `promote_snaps` and `generate_community_forum_post`, `synchronize_github_repo` is *not* idempotent. I do not think it should be, because of how git works. I think if branches already exist and the user really did want to synchronize branches again, the user would want to know that it can't be done automatically, and should instead be told what to do to make it possible, or how to skip the whole thing. I don't think we should, for example, go ahead and create a PR based on an old version of a branch and just skip the pulling step, or automatically delete a branch. In `_create_and_push_branch_without_version_bump`, if you have created the branch then fail after, you'll rerun and then get a message saying to delete the branch. I think that's nicer than automatically deleting it, in case you want to inspect it. successful test run: ``` $ git switch create-pr Switched to branch 'create-pr' $ RELEASE_GPG_KEY=[test key] tools/release.sh 4.35.0 4.36.0 [release output] $ tools/finish_release.py --test-version 4.35.0 --skip-snaps Creating PR to merge candidate-4.35.0 into main... PR location: https://github.com/certbot/certbot/pull/10714 Creating branch without version bump commit named 4.35.x... Created. Generating announcement text for community forum post release not found Generating announcement text failed. $ git switch 4.35.x Switched to branch '4.35.x' $ RELEASE_GPG_KEY=[test key] tools/release.sh 4.35.1 4.36.0 [release output] $ tools/finish_release.py --test-version 4.35.1 --skip-snaps Creating PR to merge candidate-4.35.1 into main... PR location: https://github.com/certbot/certbot/pull/10715 Creating branch without version bump commit named point-candidate-4.35.1... Created. Creating PR to merge point-candidate-4.35.1 into 4.35.x... PR location: https://github.com/certbot/certbot/pull/10716 Generating announcement text for community forum post release not found Generating announcement text failed. ``` then here's some errors and their outputs -- trying to run `finish_release.py` again: ``` $ tools/finish_release.py --test-version 4.34.1 --skip-snaps Creating PR to merge candidate-4.35.1 into main... PR to merge release changes into main already exists...skipping creation. To create a new PR, delete the old one on GitHub. PR location: https://github.com/certbot/certbot/pull/10715 Creating branch without version bump commit named point-candidate-4.35.1... Error running `git branch point-candidate-4.35.1` Branch point-candidate-4.35.1 already exists. Delete it using `git branch -D point-candidate-4.35.1`. fatal: a branch named 'point-candidate-4.35.1' already exists To skip pushing updated branches to GitHub and creating PRs, run this script with the `--skip-github-sync` flag. Traceback (most recent call last): File "/Users/erica/certbot/tools/finish_release.py", line 370, in <module> main(sys.argv[1:]) ~~~~^^^^^^^^^^^^^^ File "/Users/erica/certbot/tools/finish_release.py", line 366, in main synchronize_github_repo(version) ~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^ File "/Users/erica/certbot/tools/finish_release.py", line 329, in synchronize_github_repo _create_and_push_branch_without_version_bump(version, branch_name) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^ File "/Users/erica/certbot/tools/finish_release.py", line 280, in _create_and_push_branch_without_version_bump _run_silent_except_error(f'git branch {branch_name}'.split(), msg) ~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/Users/erica/certbot/tools/finish_release.py", line 209, in _run_silent_except_error raise e File "/Users/erica/certbot/tools/finish_release.py", line 201, in _run_silent_except_error process = subprocess.run(cmd, check=True, universal_newlines=True, capture_output=True) File "/Users/erica/.pyenv/versions/3.14.3/lib/python3.14/subprocess.py", line 577, in run raise CalledProcessError(retcode, process.args, output=stdout, stderr=stderr) subprocess.CalledProcessError: Command '['git', 'branch', 'point-candidate-4.35.1']' returned non-zero exit status 128. ``` local changes to branch: ``` $ touch test_file.txt $ git add -A $ tools/finish_release.py --test-version 4.35.1 --skip-snaps Error running `git diff --quiet HEAD` You have uncommitted changes that will be deleted. Stash your changes before rerunning this script. To skip pushing updated branches to GitHub and creating PRs, run this script with the `--skip-github-sync` flag. Traceback (most recent call last): File "/Users/erica/certbot/tools/finish_release.py", line 370, in <module> main(sys.argv[1:]) ~~~~^^^^^^^^^^^^^^ File "/Users/erica/certbot/tools/finish_release.py", line 366, in main synchronize_github_repo(version) ~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^ File "/Users/erica/certbot/tools/finish_release.py", line 315, in synchronize_github_repo _run_silent_except_error('git diff --quiet HEAD'.split(), message) ~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/Users/erica/certbot/tools/finish_release.py", line 209, in _run_silent_except_error raise e File "/Users/erica/certbot/tools/finish_release.py", line 201, in _run_silent_except_error process = subprocess.run(cmd, check=True, universal_newlines=True, capture_output=True) File "/Users/erica/.pyenv/versions/3.14.3/lib/python3.14/subprocess.py", line 577, in run raise CalledProcessError(retcode, process.args, output=stdout, stderr=stderr) subprocess.CalledProcessError: Command '['git', 'diff', '--quiet', 'HEAD']' returned non-zero exit status 1. ``` branch doesn't match the one on github (shows that stdout is now also printed on error): ``` $ cd releases/le.4.35.1.89372/ $ git commit --amend # change the message [candidate-4.35.1 8d34a67a4] Bump version to 4.36.0 new message Date: Tue Jun 23 10:47:56 2026 -0700 20 files changed, 20 insertions(+), 20 deletions(-) $ cd ../../ $ tools/finish_release.py --test-version 4.35.1 --skip-snaps Error running `git push origin candidate-4.35.1` To delete the branch on GitHub, run `git push origin --delete candidate-4.35.1`. To https://github.com/certbot/certbot.git ! [rejected] candidate-4.35.1 -> candidate-4.35.1 (non-fast-forward) error: failed to push some refs to 'https://github.com/certbot/certbot.git' hint: Updates were rejected because the tip of your current branch is behind hint: its remote counterpart. If you want to integrate the remote changes, hint: use 'git pull' before pushing again. hint: See the 'Note about fast-forwards' in 'git push --help' for details. To skip pushing updated branches to GitHub and creating PRs, run this script with the `--skip-github-sync` flag. Traceback (most recent call last): File "/Users/erica/certbot/tools/finish_release.py", line 370, in <module> main(sys.argv[1:]) ~~~~^^^^^^^^^^^^^^ File "/Users/erica/certbot/tools/finish_release.py", line 366, in main synchronize_github_repo(version) ~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^ File "/Users/erica/certbot/tools/finish_release.py", line 317, in synchronize_github_repo _sync_candidate_from_temp_to_origin(version) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^ File "/Users/erica/certbot/tools/finish_release.py", line 247, in _sync_candidate_from_temp_to_origin _run_silent_except_error(command_str.split(), message) ~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/Users/erica/certbot/tools/finish_release.py", line 209, in _run_silent_except_error raise e File "/Users/erica/certbot/tools/finish_release.py", line 201, in _run_silent_except_error process = subprocess.run(cmd, check=True, universal_newlines=True, capture_output=True) File "/Users/erica/.pyenv/versions/3.14.3/lib/python3.14/subprocess.py", line 577, in run raise CalledProcessError(retcode, process.args, output=stdout, stderr=stderr) subprocess.CalledProcessError: Command '['git', 'push', 'origin', 'candidate-4.35.1']' returned non-zero exit status 1. ``` I've hit basically all of the errors with text at some point during testing, but can recreate them if you'd like. Once this is merged, I'll update the release instructions and delete the test branches and PRs. --------- Co-authored-by: Will Greenberg <ifnspifn@gmail.com> Co-authored-by: Will Greenberg <willg@eff.org>
Add --use-pep517 flag to pip to silence warning in tools/venv.py, and switch codebase to src-layout (#10249)
This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
.. This file contains a series of comments that are used to include sections of this README in other files. Do not modify these comments unless you know what you are doing. tag:intro-begin |build-status| .. |build-status| image:: https://img.shields.io/github/actions/workflow/status/certbot/certbot/nightly.yml :target: https://github.com/certbot/certbot/actions/workflows/nightly.yml :alt: GitHub Actions nightly CI status .. image:: https://raw.githubusercontent.com/EFForg/design/master/logos/certbot/eff-certbot-lockup.png :width: 200 :alt: EFF Certbot Logo Certbot is part of EFF’s effort to encrypt the entire Internet. Secure communication over the Web relies on HTTPS, which requires the use of a digital certificate that lets browsers verify the identity of web servers (e.g., is that really google.com?). Web servers obtain their certificates from trusted third parties called certificate authorities (CAs). Certbot is an easy-to-use client that fetches a certificate from Let’s Encrypt—an open certificate authority launched by the EFF, Mozilla, and others—and deploys it to a web server. Anyone who has gone through the trouble of setting up a secure website knows what a hassle getting and maintaining a certificate is. Certbot and Let’s Encrypt can automate away the pain and let you turn on and manage HTTPS with simple commands. Using Certbot and Let's Encrypt is free. .. _installation: Getting Started --------------- The best way to get started is to use our `interactive guide <https://certbot.eff.org>`_. It generates instructions based on your configuration settings. In most cases, you’ll need `root or administrator access <https://certbot.eff.org/faq/#does-certbot-require-root-administrator-privileges>`_ to your web server to run Certbot. Certbot is meant to be run directly on your web server on the command line, not on your personal computer. If you’re using a hosted service and don’t have direct access to your web server, you might not be able to use Certbot. Check with your hosting provider for documentation about uploading certificates or using certificates issued by Let’s Encrypt. Contributing ------------ If you'd like to contribute to this project please read `Developer Guide <https://certbot.eff.org/docs/contributing.html>`_. This project is governed by `EFF's Public Projects Code of Conduct <https://www.eff.org/pages/eppcode>`_. Links ===== .. Do not modify this comment unless you know what you're doing. tag:links-begin Documentation: https://certbot.eff.org/docs Software project: https://github.com/certbot/certbot Changelog: https://github.com/certbot/certbot/blob/main/certbot/CHANGELOG.md For Contributors: https://certbot.eff.org/docs/contributing.html For Users: https://certbot.eff.org/docs/using.html Main Website: https://certbot.eff.org Let's Encrypt Website: https://letsencrypt.org Community: https://community.letsencrypt.org ACME spec: `RFC 8555 <https://tools.ietf.org/html/rfc8555>`_ ACME working area in github (archived): https://github.com/ietf-wg-acme/acme .. Do not modify this comment unless you know what you're doing. tag:links-end .. Do not modify this comment unless you know what you're doing. tag:intro-end .. Do not modify this comment unless you know what you're doing. tag:features-begin Current Features ===================== * Supports multiple web servers: - Apache 2.4+ - nginx/0.8.48+ - webroot (adds files to webroot directories in order to prove control of domains and obtain certificates) - standalone (runs its own simple webserver to prove you control a domain) - other server software via `third party plugins <https://certbot.eff.org/docs/using.html#third-party-plugins>`_ * The private key is generated locally on your system. * Can talk to the Let's Encrypt CA or optionally to other ACME compliant services. * Can get domain-validated (DV) certificates. * Can revoke certificates. * Supports ECDSA (default) and RSA certificate private keys. * Can optionally install a http -> https redirect, so your site effectively runs https only. * Fully automated. * Configuration changes are logged and can be reverted. .. Do not modify this comment unless you know what you're doing. tag:features-end Thanks ------ We appreciate the donation of credits to help us test and develop Certbot from: .. image:: https://opensource.nyc3.cdn.digitaloceanspaces.com/attribution/assets/SVG/DO_Logo_horizontal_blue.svg :width: 201 :alt: DigitalOcean Logo :target: https://www.digitalocean.com/
Description
Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol.
146 MiB
Languages
Python
94.5%
Shell
3.7%
Batchfile
0.8%
Makefile
0.7%
Augeas
0.2%