--- type: User Story title: Build and publish versioned releases description: Gitea Actions validate every change and publish semantically versioned Velocity and container artifacts. tags: [operations, ci, release, velocity, docker] timestamp: 2026-08-01T19:01:47Z story_id: US-016 status: implemented --- # User Story As a platform operator, I want automated validation and semantic releases, so that deployable web, migration, and Velocity artifacts are reproducible and downloadable. # Acceptance Criteria - [ ] Pushes and pull requests run OKF validation, linting, type checks, tests, the web build, and the Velocity build. - [ ] Pull requests validate conventional commit messages. - [ ] CI uploads the development Velocity JAR as a workflow artifact. - [ ] Main-branch conventional commits determine the next semantic version and create a `vMAJOR.MINOR.PATCH` tag. - [x] A release build embeds the semantic version in the Velocity plugin and JAR filename. - [ ] A public Gitea release exposes the versioned Velocity JAR as a downloadable asset. - [ ] Releases publish versioned and `latest` web runtime images to the Gitea registry. - [ ] Releases publish versioned and `latest` migration images that run versioned Drizzle migrations. - [x] Runtime containers use unprivileged users and exclude development source and secrets where practical. - [x] Operators are told which repository secrets must be configured before the first push. # Implementation - [CI workflow](../.gitea/workflows/ci.yml) - [Release workflow](../.gitea/workflows/release.yml) - [Semantic Release configuration](../.releaserc) - [Web and migration Docker targets](../Dockerfile) - [Velocity Gradle build](../plugins/velocity/build.gradle.kts) - [Release and deployment guide](../docs/releases.md) # Validation Local OKF, lint, typecheck, test, Next.js build, and versioned Velocity JAR checks pass. A test `1.2.3` JAR was generated with matching Velocity metadata. Workflow YAML parses successfully. Container builds and remote publication remain pending because the local Docker daemon is unavailable and the first push is intentionally paused until repository secrets are configured. # Related Stories - [Deploy and operate securely](us-015-platform-operations.md) - [Velocity game admission](us-009-velocity-admission.md)