ci: daily nix flake update workflow

This commit is contained in:
damocles 2026-09-13 18:56:00 +02:00
commit 16f86d24e7

View file

@ -0,0 +1,60 @@
name: flake update
# Daily `nix flake update`; opens a PR only if the lock changed, never
# merges (mara does, by hand - branch protection requires it anyway).
# Separate file from ci.yml/coverage.yml for the same reason coverage.yml
# is: a workflow_dispatch in ci.yml fires every job there.
#
# Plain branch + curl POST (not AGit), mirroring mara's own
# nixos-configuration:.forgejo/workflows/flake-update.yaml - a daily lock
# bump never updates an existing PR, so AGit's advantage there doesn't
# apply. Stale PRs just stack; newest lock wins.
#
# `PR_BOT_TOKEN` (repo secret) is the `flake-bot` account's write token.
# Self-signed forge cert: not worked around with `curl -k` - hive-ci.nix
# already sets SSL_CERT_FILE to a bundle with the hive CA (wiring
# confirmed; anchor coverage for the swarm forge specifically isn't).
on:
workflow_dispatch:
schedule:
- cron: "0 3 * * *"
jobs:
update:
name: nix flake update
runs-on: [hive-ci]
timeout-minutes: 30
steps:
- uses: actions/checkout@v3
- name: update and open a PR if the lock changed
env:
PR_BOT_TOKEN: ${{ secrets.PR_BOT_TOKEN }}
run: |
set -euo pipefail
nix flake update
if git diff --quiet -- flake.lock; then
echo "flake.lock unchanged, nothing to do"
exit 0
fi
# origin's scheme+host, not a hardcoded forge URL - checkout
# already resolved an address this runner can reach.
origin_url="$(git remote get-url origin)"
scheme="${origin_url%%://*}"
host="$(printf '%s\n' "$origin_url" | sed -E 's#^[a-z]+://([^/]+)/.*#\1#')"
branch="flake-update-$(date +%F)"
git checkout -b "$branch"
git -c user.name="flake-bot" \
-c user.email="git+flake-bot@darkest.space" \
commit -am "nix flake update"
git push "${scheme}://flake-bot:${PR_BOT_TOKEN}@${host}/hyperhive/hyperhive.git" "$branch"
printf '{"title":"nix flake update","head":"%s","base":"main"}' \
"$branch" > /tmp/flake-update-pr.json
curl -sf -X POST \
-H "Authorization: token ${PR_BOT_TOKEN}" \
-H "Content-Type: application/json" \
-d @/tmp/flake-update-pr.json \
"${scheme}://${host}/api/v1/repos/hyperhive/hyperhive/pulls"