This document describes how to automatically publish Maven artifacts to Maven Central via GitHub Actions, including the complete workflow for secret configuration, token generation, and GPG signing.
This project contains three independent Java packages, each with a corresponding GitHub Actions Workflow for publishing:
| Java Package Path | Description | Workflow File |
|---|---|---|
e2b/java |
E2B Client — E2B Sandbox API client | publish-e2b-client.yml |
k8s/java |
K8s Client — Kubernetes CRD model client | publish-k8s-client.yml |
runtime/java |
Runtime Client — Sandbox Runtime API client | publish-runtime-client.yml |
Each Workflow is manually triggered and requires a version number to be specified.
- A Sonatype Central account
- GPG tool installed locally (verify with
gpg --version)
- Visit https://central.sonatype.com/usertoken
- Log in with your GitHub account
- Click Generate User Token
- Record the generated
usernameandpassword(to be configured in GitHub Secrets later)
gpg --full-generate-keyFollow the prompts:
- Key type: Enter
1(RSA and RSA) - Keysize: Enter
4096(more secure) - Expiration: Enter
0(never expires) or1y(one year validity) - Real name: Enter your name
- Email address: Must use your company email
zq01297892@alibaba-inc.com, as this determines whether your signature can be automatically recognized - Passphrase: Set a strong password (used to unlock the key for each code submission)
⚠️ Note: This Passphrase must be set in theGPG_PASSPHRASEvariable. Please keep it safe.
After successful generation, output similar to the following will be displayed. Save the Key ID (e.g.,
***):
gpg: ***
pub rsa4096 2026-04-07 [SC]
***
uid agents-client-java (Maven Central Signing) <***@alibaba-inc.com>
sub rsa4096 2026-04-07 [E]
Use the Key ID from the previous step to export the private key. Save the complete output to GPG_PRIVATE_KEY:
gpg --armor --export-secret-key <KEY-ID>
# Example:
# gpg --armor --export-secret-key ***The output starts with -----BEGIN PGP PRIVATE KEY BLOCK----- and ends with -----END PGP PRIVATE KEY BLOCK-----. Copy
the entire content.
Upload the public key to a public key server so Maven Central can verify signatures:
gpg --keyserver hkps://keyserver.ubuntu.com --send-keys <KEY-ID>
# Example:
# gpg --keyserver hkps://keyserver.ubuntu.com --send-keys ***
⚠️ Note: It may take a few minutes to several hours for the public key to propagate on the key server. If signature verification fails, please retry later.
After uploading, you can search for the Key ID on Ubuntu Keyserver to verify it has taken effect.
Set the following 4 variables in the GitHub repository under Settings → Secrets and variables → Actions:
| Variable Name | Description | Source |
|---|---|---|
CENTRAL_USERNAME |
Sonatype Token username | Generated username |
CENTRAL_PASSWORD |
Sonatype Token password | Generated password |
GPG_PASSPHRASE |
GPG key passphrase | The Passphrase you set |
GPG_PRIVATE_KEY |
GPG private key (ASCII) | Full exported content |
- Go to the Actions page of the GitHub repository
- Select the Workflow to publish (e.g.,
Publish E2B Client to Maven Central) - Click the Run workflow button
- Enter the version number (e.g.,
0.1.0) and click Run workflow - Wait for the Workflow to complete
- After successful publishing, search for the artifact on Maven Central
Post-publish Verification:
Visit Sonatype Publishing Deployments to check the publishing status (may take a few minutes to several hours to sync).
- Namespace must match GroupId: The Namespace owned by your Sonatype Central account must match the
groupIdinpom.xml(e.g.,io.openkruise), otherwise publishing will be rejected - GPG Email must match Developer Email: The Email in the GPG key must match the
<email>in<developers>section ofpom.xml, otherwise signature verification will fail - Private Key Security:
GPG_PRIVATE_KEYis sensitive information — store it only in GitHub Secrets, never commit it to the code repository - Passphrase Safekeeping:
GPG_PASSPHRASEcannot be recovered if lost — keep it safe - Token Validity: Sonatype Tokens are valid indefinitely, but if compromised, regenerate immediately at central.sonatype.com and update GitHub Secrets
<dependency>
<groupId>io.openkruise</groupId>
<artifactId>agents-client-java</artifactId>
<version>latest-version</version>
</dependency>**Maven Central **: https://central.sonatype.com/artifact/io.openkruise/agents-client-java
Configuration Improvements:
- Split into three independent packages:
e2b,runtime,k8s - Removed proxy configuration from config files
- Added
httpClientparameter for custom HTTP client support
- **agents-client-e2b **: https://central.sonatype.com/artifact/io.openkruise/agents-client-e2b
- **agents-client-runtime **: https://central.sonatype.com/artifact/io.openkruise/agents-client-runtime
- **agents-client-k8s **: https://central.sonatype.com/artifact/io.openkruise/agents-client-k8s