Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Code Signing Key

Create a code signing gpg key for release signing; use <your Apache ID>@apache.org for your primary ID for the code signing key. See the Apache Release Signing documentation for further information.

...

  1. Branch your release:

    git checkout -b <your release name> <commit sha1> 

    push to origin:
    git push origin <your release name>


  2. Apply signed tag on release branch and push to origin

    Example:

     git tag -u <GPG KEY ID> --sign <your release name>-rc# -m "Apache HAWQ <your release name> RC#" <SHA of HEAD of branch>

     git push origin <your release name>-rc#
     

  3. Make a tarball and gzip:
    git archive -o ../apache-hawq-src-<your release name>.tar --prefix=apache-hawq-src-<your release name>/ <your tag/branch name>
    gzip ../apache-hawq-src-<your release name>.tar

    Example:

    $ git archive -o ../apache-hawq-src-2.14.0.0-incubating.tar --prefix=apache-hawq-src-2.14.0.0-incubating/ 2.14.0.0-incubating
    $ gzip ../apache-hawq-src-2.14.0.0-incubating.tar

  4.  Prepare MD5, SHA256 and ASC files from the source tarball:

    md5shasum -a 256 apache-hawq-src-<your release name>.tar.gz > apache-hawq-src-<your release name>.tar.gz.md5
    shasumsha256 
    gpg --detach-sign -a 256 apache-hawq-src-<your release name>.tar.gz >

    Example:

    $ shasum -a 256 apache-hawq-src-<your release name>.tar.gz.sha256 
    gpg2 --detach-sign -a apache-hawq-src-<your release name>2.1.0.0-incubating.tar.gz

    Example:

    $ md5> apache-hawq-src-2.1.0.0-incubating.tar.gz >.sha256
    $ gpg --detach-sign -a apache-hawq-src-2.1.0.0-incubating.tar.gz.md5$
    You shasumneed -a 256 apache-hawq-src-2.1.0.0-incubating.tar.gz > apache-hawq-src-2.1.0.0-incubating.tar.gz.sha256
    $ gpg2 --detach-sign -a apache-hawq-src-2.1.0.0-incubating.tar.gzYou need a passphrase to unlock the secret key for
    user: "Edward passphrase to unlock the secret key for
    user: "Edward Bartolo Espino (CODE SIGNING KEY) <espino@apache.org>"
    4096-bit RSA key, ID 57325522, created 2017-01-09

    $ ls -al apache-hawq-src-2.14.0.0-incubating*
    -rw-r--r-- 1 espino staff 35214063 Jan 10 11:04 apache-hawq-src-2.1.0.0-incubating.tar.gz
    -rw-r--r-- 1 espino staff 819 Jan 10 11:09 apache-hawq-src-2.1.0.0-incubating.tar.gz.asc
    -rw-r--r-- 1 espino staff 83 Jan 10 11:10 apache-hawq-src-2.1.0.0-incubating.tar.gz.md5
    -rw-r--r-- 1 espino staff 84 Jan 10 11:10 apache-hawq-src-2.1.0.0-incubating.tar.gz.sha256
     
  5. Retrieve the subversion dev hawq repo
    Example: svn checkout https://dist.apache.org/repos/dist/dev/hawq/ --username=<your apache user>
     
  6. Create a local folder for the release (e.g. 2.04.0.0-incubating.RC1) in svn. We use apache's distribution repo: https://dist.apache.org/repos/dist/dev/hawq/
  7. Move the files into the release folder on local disk.
  8. svn add <release folder>
  9. Commit artifacts:
    Example: svn commit -m 'adding 2.04.0.0 -incubating RC1 candidate release artifacts' --username=<your apache user id>

Validate the Release Candidate 

As per the Apache documentation, verify that the release candidate artifacts satisfy the following:

  • PGP signatures and SHA256 /MD5 checksum verification

Example (performed on a Macbook Pro: brew install gpg2 coreutils):

$ brew install gpg2 gpg coreutils
brew install gpg2 gpg coreutils
Warning: gnupg2-gnupg 2.0.30_3 2.9 is already installed
Warning: coreutils- coreutils 8.26 30 is already installed
$ which gpg2 gpg gsha256sum gmd5sum
/usr/local/bin/gpg2gpg
/usr/local/bin/gsha256sum
/usr/local/bin/gmd5sum
$ gpg2 gpg --import ../KEYS

gpg: key 60E8C5A6D0D6D44A: "Caleb Welton <cwelton@apache.org>" not changed
gpg: key 0C2F24469AF9C0EE: "Ting (Goden) Yao (CODE SIGNING KEY) <godenyao@apache.org>" not changed
gpg: key 0BD297A18051460D: "Ting (Goden) Yao (CODE SIGNING KEY) <godenyao@apache.org>" not changed
gpg: key 13971DA39475BD5D: 7 signatures not checked due to missing keys
gpg: key 13971DA39475BD5D: "Roman V Shaposhnik (CODE SIGNING KEY) <rvs@apache.org>" not changed
gpg: key 83BCBA982858A0C9: "Lei Chang <lei_chang@apache.org>" not changed
gpg: key FC0662F257325522: "Edward Bartolo Espino (CODE SIGNING KEY) <espino@apache.org>" not changed
gpg: key 8FECDA881B8B6872: "Ruilong Huo (CODE SIGNING KEY) <huor@apache.org>" not changed
gpg: key CE60F90D1333092A: "Yi Jin <yjin@apache.org>" not changed
gpg: key 280B695FCA7FAEB2: "Radar Lei <rlei@apache.org>" not changed
gpg: Total number processed: 9
gpg: unchanged: 9


gpg : directory `/Users/espino/.gnupg' created
gpg: new configuration file `/Users/espino/.gnupg/gpg.conf' created
gpg: WARNING: options in `/Users/espino/.gnupg/gpg.conf' are not yet active during this run
gpg: keyring `/Users/espino/.gnupg/secring.gpg' created
gpg: keyring `/Users/espino/.gnupg/pubring.gpg' created
gpg: /Users/espino/.gnupg/trustdb.gpg: trustdb created
gpg: key D0D6D44A: public key "Caleb Welton <cwelton@apache.org>" imported
gpg: key 9AF9C0EE: public key "Ting (Goden) Yao (CODE SIGNING KEY) <godenyao@apache.org>" imported
gpg: key 8051460D: public key "Ting (Goden) Yao (CODE SIGNING KEY) <godenyao@apache.org>" imported
gpg: key 9475BD5D: public key "Roman V Shaposhnik (CODE SIGNING KEY) <rvs@apache.org>" imported
gpg: key 2858A0C9: public key "Lei Chang <lei_chang@apache.org>" imported
gpg: key 57325522: public key "Edward Bartolo Espino (CODE SIGNING KEY) <espino@apache.org>" imported
gpg: Total number processed: 6
gpg: imported: 6 (RSA: 5)
gpg: no ultimately trusted keys found
$ gpg2 --verify apache-hawq-src-2.14.0.0-incubating.tar.gz.asc

gpg: assuming signed data in 'apache-hawq-src-2.14.0.0-incubating.tar.gz'
gpg: Signature made Tue Jan 10 17:25:01 2017 CST Sep 11 15:54:29 2018 CST
gpg: using RSA key ID 5732552231136E4DB96401A60446D269280B695FCA7FAEB2
gpg: Good signature from "Edward Bartolo Espino (CODE SIGNING KEY) <espino@Radar Lei <rlei@apache.org>" [unknown]ultimate]

$ gsha256sum --check apache-hawq-src-2.4.0.0.tar.gz.sha256

gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: BBED A7B5 F336 D516 B34A DE0C FC06 62F2 5732 5522
$ gsha256sum --check apache-hawq-src-2.1.0.0-incubating.tar.gz.sha256
apache-hawq-src-2.1.4.0.0-incubating.tar.gz: OK$ gmd5sum --check apache-hawq-src-2.1.0.0-incubating.tar.gz.md5
apache-hawq-src-2.1.0.0-incubating.tar.gz: OK

 

...

Vote on the Release

As per the Apache Incubator release guidelines, all releases for incubating projects must go through a two-step voting process. First, release voting must successfully pass within the Apache Release voting must successfully pass within the Apache HAWQ community via the dev@hawq.incubator.apache.org mail list. Then, release voting must successfully pass within the Apache Incubator PMC via the general@incubator.apache.org mail list. 

General information regarding the Apache voting process can be found here.

...

This is the vote for <release name> of Apache HAWQ (incubating). This is a Source only release.
The vote will run for at least 72 hours and will close on <vote closing date>.
Release Notes (Jira generated):
<JIRA Release Notes URL>
Release verification steps can be found at:
https://cwiki.apache.org/confluence/display/HAWQ/Release+Process%3A+Step+by+step+guide#ReleaseProcess:Stepbystepguide-ValidatetheReleaseCandidate
Git branch for the release:
https://github.com/apache/incubator-hawq/tree/<release name>
Sources for the release:
https://dist.apache.org/repos/dist/dev/incubator/hawqhawq/<release name>.RC#/apache-hawq-src-<release name>.tar.gz
Source release verification:
PGP Signature:
https://dist.apache.org/repos/dist/dev/incubator/hawq/<release name>.RC#/apache-hawq-src-<release name>.tar.gz.asc
MD5/SHA256 Hash:
https://dist.apache.org/repos/dist/dev/incubator/hawq/<release name>.RC#/apache-hawq-src-<release name>.tar.gz.md5
https://dist.apache.org/repos/dist/dev/incubator/hawq/<release name>.RC#/apache-hawq-src-<release name>.tar.gz.sha256
Keys to verify the signature of the release artifact are available at:
https://dist.apache.org/repos/dist/dev/incubator/hawq/KEYS
The artifact(s) have been signed with Key : <CODE SIGNING KEY ID>
Please vote accordingly:
[ ] +1 approve
[ ] +0 no opinion
[ ] -1 disapprove (and reason why)

...

The Apache HAWQ <release version> vote is now closed and has
passed as follows:

[number] +1 (binding) votes
[number] -1 (binding) votes

A vote Apache HAWQ <release version> will now be called on
general@incubator.apache.org.

Incubator PMC Vote

Once the candidate release vote passes on dev@hawq.apache.incubator.org, call a vote on IMPC general@incubator.apache.org with an email a with subject: [VOTE]: Apache HAWQ <release version> Release and a body along the lines of:

 

 

...

Publishing and Distributing Release

  1. Finalizing your tag
    switching to master branch
    git tag -s rel/v{version} <commit SHA> -m "Apache HAWQ {version) release (<other comments>)"

     

    Info
    titleSign your release tag

    You need to configure your git user signing key first before you can sign a tag.

    git config --global user.signingkey <Your secret key SHA>


  2. Push your tag to remote (origin)
    git push origin rel/v{version}
     
  3. Move tarballs from staging (dev) folder to release location:

    svn mv 

The PPMC vote for the Apache HAWQ <release version> release has
passed. We kindly request that the IPMC now vote on the release.

The PPMC vote thread is located here: <link to the dev voting thread>

The artifacts can be downloaded here:

  1. https://dist.apache.org/repos/dist/dev

...

  1. /hawq/

...

The artifacts have been signed with Key : <ID of signing key>

All JIRAs completed for this release are tagged with 'FixVersion
= <release version>'. You can view them here: <insert link to the
JIRA release notes>

Please vote accordingly:

[ ] +1, accept as the official Apache HAWQ <release number> release
[ ] -1, do not accept as the official Apache HAWQ <release number> release because...

The vote will run for at least 72 hours.

If any -1 (binding) votes are entered, then address them such that the voter changes their vote to a +1 (binding) or cancel the vote, fix the issues, and start over with Prepare Tarballs (including re-voting within the Apache HAWQ community on dev@hawq.apache.incubator.org).

Once 72 hours has passed (which is generally preferred) and/or at least three +1 (binding) votes have been cast with no -1 (binding) votes, send an email closing the vote and pronouncing the release candidate a success. Please use the subject: [RESULT][VOTE]: Apache HAWQ <release version> Release

 

The Apache HAWQ <release version> vote is now closed and has
passed as follows:
[number] +1 (binding) votes
[number] -1 (binding) votes

The Apache HAWQ (incubating) community will proceed with the release.

 

 

Publishing and Distributing Release

...

git tag -s rel/v{version} <commit SHA> -m "Apache HAWQ(incubating) {version) release (<other comments>)"

 

Info
titleSign your release tag

You need to configure your git user signing key first before you can sign a tag.

git config --global user.signingkey <Your secret key SHA>

...

git push origin rel/v{version}
 

Move tarballs from staging (dev) folder to release location:

svn mv https://dist.apache.org/repos/dist/dev/incubator/hawq/{version}.RC#/ https://dist.apache.org/repos/dist/release/incubator/hawq/{version}
  1. {version}.RC#/ https://dist.apache.org/repos/dist/release/hawq/{version}
    Info
    titleCommit Message

    As if you put https URL in svn commands, it'll commit automatically. A text editor will popup for you to edit commit message, put something like: "Release Apache HAWQ {{version}}"


  2. Add download link on hawq website: http://hawq.apache.org/ 
    Use mirror for latest download, e.g. http://apache.org/dyn/closer.cgi/hawq/2.4.0.0/apache-hawq-rpm-2.4.0.0.tar.gz
    Use dist server links for binary signatures and hashes. e.g. https://www.apache.org/dist/hawq/2.4.0.0/apache-hawq-rpm-2.4.0.0.tar.gz.asc
    Use archive server links for archives downloads. e.g. https://archive.apache.org/dist/hawq/

  3. Go to http://issues.apache.org/jira/browse/hawq to release the specific version (need admin permission, under "Version")
  4. Add the document for the version into the hawq website and modify the link if needed. (https://github.com/apache/hawq-site)

 

...

Announce the Release

After doing the above change, wait for at least 24 hours and then announce the release by send an email to announce@apache.org, user@hawq.apache.org and dev@hawq.apache.org with the subject: [ANNOUNCE] Apache HAWQ <release number> Release and a body along the lines of:

Apache HAWQ Project Team is proud to announce Apache
HAWQ <release version> has been released.

Apache HAWQ combines exceptional MPP-based analytics

performance, robust ANSI SQL compliance, Hadoop ecosystem
integration and manageability, and flexible data-store format
support, all natively in Hadoop, no connectors required. Built
from a decade’s worth of massively parallel processing (MPP)
expertise developed through the creation of the Pivotal
Greenplum® enterprise database and open source PostgreSQL, HAWQ
enables to you to swiftly and interactively query Hadoop data,
natively via HDFS.*Download Link*:
http://hawq.apache.org/#download

*About this release*
This is a release having both source code and binary.
All changes:
https://cwiki.apache.org/confluence/display/HAWQ/HAWQ+Release+2.4.0.0-Release
*HAWQ Resources:*

   - JIRA: https://issues.apache.org/jira/browse/HAWQ
   - Wiki: https://cwiki.apache.org/confluence/display/HAWQ
   - Mailing list(s): dev@hawq.apache.org
user@hawq.apache.org

*Know more about HAWQ:*
http://hawq.apache.org

- Apache HAWQ Team

Info
titleCommit Message

As if you put https URL in svn commands, it'll commit automatically. A text editor will popup for you to edit commit message, put something like: "Release Apache HAWQ (incubating) {{version}}"

...

 

Announce the Release

Send an email to announce@apache.orggeneral@incubator.apache.org, and dev@hawq.incubator.apache.org with the subject: [ANNOUNCE] Apache HAWQ <release number> Release and a body along the lines of:

Apache HAWQ (incubating) Project Team is proud to announce Apache
HAWQ <release version> has been released.
Apache HAWQ (incubating) combines exceptional MPP-based analytics
performance, robust ANSI SQL compliance, Hadoop ecosystem
integration and manageability, and flexible data-store format
support, all natively in Hadoop, no connectors required. Built
from a decade’s worth of massively parallel processing (MPP)
expertise developed through the creation of the Pivotal
Greenplum® enterprise database and open source PostgreSQL, HAWQ
enables to you to swiftly and interactively query Hadoop data,
natively via HDFS.
*Download Link*:
https://dist.apache.org/repos/dist/release/incubator/hawq/<release version>/
*About this release*
This is a source code only release
All changes:
https://cwiki.apache.org/confluence/display/HAWQ/HAWQ+Release+2.1.0.0-incubating+Release
*HAWQ Resources:*
   - JIRA: https://issues.apache.org/jira/browse/HAWQ
   - Wiki: https://cwiki.apache.org/confluence/display/HAWQ/Apache+HAWQ+Home
   - Mailing list(s): dev@hawq.incubator.apache.org
user@hawq.incubator.apache.org
*Know more about HAWQ:*
http://hawq.apache.org
Apache HAWQ (incubating) Team
=====
*Disclaimer*
Apache HAWQ (incubating) is an effort undergoing incubation at The
Apache Software Foundation (ASF), sponsored by the name of Apache
Incubator PMC. Incubation is required of all newly accepted
projects until a further review indicates that the
infrastructure, communications, and decision making process have
stabilized in a manner consistent with other successful ASF
projects. While incubation status is not necessarily a reflection
of the completeness or stability of the code, it does indicate
that the project has yet to be fully endorsed by the ASF.

 

General Apache information regarding announcing a release may be found here.

 

Miscellaneous

...