diff --git a/.forgejo/workflows/ci.yml b/.forgejo/workflows/ci.yml index e87d724a..54764db0 100644 --- a/.forgejo/workflows/ci.yml +++ b/.forgejo/workflows/ci.yml @@ -10,6 +10,7 @@ on: jobs: check: name: nix flake check + if: vars.PUBLIC_FORGE != 'true' runs-on: [hive-ci] # 30 min is well above a cold-cache rebuild (~15 min observed) and well # under the runner's 3h cap @@ -21,6 +22,7 @@ jobs: tracker-tags: name: tracker-tag lint + if: vars.PUBLIC_FORGE != 'true' runs-on: [hive-ci] timeout-minutes: 5 steps: @@ -30,6 +32,7 @@ jobs: comment-blocks: name: comment-block lint + if: vars.PUBLIC_FORGE != 'true' runs-on: [hive-ci] timeout-minutes: 5 steps: @@ -39,6 +42,7 @@ jobs: doc-refs: name: doc-pointer lint + if: vars.PUBLIC_FORGE != 'true' runs-on: [hive-ci] timeout-minutes: 5 steps: @@ -48,6 +52,7 @@ jobs: attribution-trailers: name: attribution-trailer lint + if: vars.PUBLIC_FORGE != 'true' runs-on: [hive-ci] timeout-minutes: 5 steps: @@ -59,6 +64,7 @@ jobs: dashboard-descriptions: name: dashboard-description lint + if: vars.PUBLIC_FORGE != 'true' runs-on: [hive-ci] timeout-minutes: 5 steps: @@ -70,6 +76,7 @@ jobs: shellcheck: name: shellcheck + if: vars.PUBLIC_FORGE != 'true' runs-on: [hive-ci] timeout-minutes: 10 steps: @@ -86,6 +93,7 @@ jobs: prose-lint: name: prose lint (vale) + if: vars.PUBLIC_FORGE != 'true' runs-on: [hive-ci] timeout-minutes: 5 steps: @@ -98,6 +106,7 @@ jobs: prose-lint-errors: name: prose lint (vale, errors) + if: vars.PUBLIC_FORGE != 'true' runs-on: [hive-ci] timeout-minutes: 5 steps: diff --git a/.forgejo/workflows/coverage.yml b/.forgejo/workflows/coverage.yml index 2edba45c..aec15769 100644 --- a/.forgejo/workflows/coverage.yml +++ b/.forgejo/workflows/coverage.yml @@ -17,6 +17,7 @@ on: jobs: coverage: name: cargo llvm-cov + if: vars.PUBLIC_FORGE != 'true' runs-on: [hive-ci] # Above the 30 min `nix flake check` allows, because instrumented # builds are slower than the ordinary ones and this starts from a diff --git a/.forgejo/workflows/flake-update.yml b/.forgejo/workflows/flake-update.yml index 2dc79bd2..0bbd3ed9 100644 --- a/.forgejo/workflows/flake-update.yml +++ b/.forgejo/workflows/flake-update.yml @@ -22,6 +22,7 @@ on: jobs: update: name: nix flake update + if: vars.PUBLIC_FORGE != 'true' runs-on: [hive-ci] timeout-minutes: 30 steps: diff --git a/.forgejo/workflows/public-cache.yml b/.forgejo/workflows/public-cache.yml new file mode 100644 index 00000000..17d5ee00 --- /dev/null +++ b/.forgejo/workflows/public-cache.yml @@ -0,0 +1,41 @@ +# Trust property: `on:` is push-to-main only — no `pull_request`, no +# `workflow_dispatch`, no schedule — so this never runs against an +# untrusted diff, and the `PREEM_PUSH_TOKEN` secret never reaches a PR +# run. The job also gates on the `PUBLIC_FORGE` repo variable, an +# opt-in only the public copy sets — job-level `if:` can't see the +# `github`/`forgejo` context on this runner (confirmed empirically), +# so origin/URL comparisons aren't usable here; `vars.*` is. Internal +# CI's own jobs gate on the inverse, so if this variable is ever unset +# or misconfigured, internal CI keeps running (fail toward "still +# tests", not "silently skips"). +name: public bin cache + +on: + push: + branches: [main] + +jobs: + push-cache: + name: build + push to preem:grid + if: vars.PUBLIC_FORGE == 'true' + runs-on: nixos + steps: + - uses: actions/checkout@v3 + - name: build the deployed closures + run: | + nix build \ + .#default \ + .#swarm-controller \ + .#swarmctl \ + .#swarm-ui \ + .#swarm-nats-auth \ + .#swarm-matrix-ctl \ + .#swarm-authelia-bridge + - name: push to the public cache + env: + PREEM_PUSH_TOKEN: ${{ secrets.PREEM_PUSH_TOKEN }} + run: | + nix shell --inputs-from . nixpkgs#attic-client -c sh -c ' + attic login preem https://preem-bincache.trollhive.monster "$PREEM_PUSH_TOKEN" + attic push preem:grid ./result* + '