ci: run nothing but a main-only bin-cache push on the public forge
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
Guards internal-only jobs (ci.yml, coverage.yml, flake-update.yml) with `vars.PUBLIC_CACHE != 'true'` and adds public-cache.yml, guarded to the inverse, to build the deployed closures and push them to the public attic cache on a push to main. `PUBLIC_CACHE` is a repo Actions variable, opt-in only on the public copy: unset here, it leaves internal CI's `!=` guards true so internal jobs always run. Job-level `if:` cannot see the `github`/`forgejo` context at all on this runner (confirmed empirically — a `github.server_url` comparison always evaluates false at job level, though the identical comparison resolves correctly inside a step), so `vars.*`, which is available at job level, is the only usable opt-in signal here.
This commit is contained in:
parent
9a444c27fa
commit
97c4771514
4 changed files with 52 additions and 0 deletions
|
|
@ -10,6 +10,7 @@ on:
|
||||||
jobs:
|
jobs:
|
||||||
check:
|
check:
|
||||||
name: nix flake check
|
name: nix flake check
|
||||||
|
if: vars.PUBLIC_FORGE != 'true'
|
||||||
runs-on: [hive-ci]
|
runs-on: [hive-ci]
|
||||||
# 30 min is well above a cold-cache rebuild (~15 min observed) and well
|
# 30 min is well above a cold-cache rebuild (~15 min observed) and well
|
||||||
# under the runner's 3h cap
|
# under the runner's 3h cap
|
||||||
|
|
@ -21,6 +22,7 @@ jobs:
|
||||||
|
|
||||||
tracker-tags:
|
tracker-tags:
|
||||||
name: tracker-tag lint
|
name: tracker-tag lint
|
||||||
|
if: vars.PUBLIC_FORGE != 'true'
|
||||||
runs-on: [hive-ci]
|
runs-on: [hive-ci]
|
||||||
timeout-minutes: 5
|
timeout-minutes: 5
|
||||||
steps:
|
steps:
|
||||||
|
|
@ -30,6 +32,7 @@ jobs:
|
||||||
|
|
||||||
comment-blocks:
|
comment-blocks:
|
||||||
name: comment-block lint
|
name: comment-block lint
|
||||||
|
if: vars.PUBLIC_FORGE != 'true'
|
||||||
runs-on: [hive-ci]
|
runs-on: [hive-ci]
|
||||||
timeout-minutes: 5
|
timeout-minutes: 5
|
||||||
steps:
|
steps:
|
||||||
|
|
@ -39,6 +42,7 @@ jobs:
|
||||||
|
|
||||||
doc-refs:
|
doc-refs:
|
||||||
name: doc-pointer lint
|
name: doc-pointer lint
|
||||||
|
if: vars.PUBLIC_FORGE != 'true'
|
||||||
runs-on: [hive-ci]
|
runs-on: [hive-ci]
|
||||||
timeout-minutes: 5
|
timeout-minutes: 5
|
||||||
steps:
|
steps:
|
||||||
|
|
@ -48,6 +52,7 @@ jobs:
|
||||||
|
|
||||||
attribution-trailers:
|
attribution-trailers:
|
||||||
name: attribution-trailer lint
|
name: attribution-trailer lint
|
||||||
|
if: vars.PUBLIC_FORGE != 'true'
|
||||||
runs-on: [hive-ci]
|
runs-on: [hive-ci]
|
||||||
timeout-minutes: 5
|
timeout-minutes: 5
|
||||||
steps:
|
steps:
|
||||||
|
|
@ -59,6 +64,7 @@ jobs:
|
||||||
|
|
||||||
dashboard-descriptions:
|
dashboard-descriptions:
|
||||||
name: dashboard-description lint
|
name: dashboard-description lint
|
||||||
|
if: vars.PUBLIC_FORGE != 'true'
|
||||||
runs-on: [hive-ci]
|
runs-on: [hive-ci]
|
||||||
timeout-minutes: 5
|
timeout-minutes: 5
|
||||||
steps:
|
steps:
|
||||||
|
|
@ -70,6 +76,7 @@ jobs:
|
||||||
|
|
||||||
shellcheck:
|
shellcheck:
|
||||||
name: shellcheck
|
name: shellcheck
|
||||||
|
if: vars.PUBLIC_FORGE != 'true'
|
||||||
runs-on: [hive-ci]
|
runs-on: [hive-ci]
|
||||||
timeout-minutes: 10
|
timeout-minutes: 10
|
||||||
steps:
|
steps:
|
||||||
|
|
@ -86,6 +93,7 @@ jobs:
|
||||||
|
|
||||||
prose-lint:
|
prose-lint:
|
||||||
name: prose lint (vale)
|
name: prose lint (vale)
|
||||||
|
if: vars.PUBLIC_FORGE != 'true'
|
||||||
runs-on: [hive-ci]
|
runs-on: [hive-ci]
|
||||||
timeout-minutes: 5
|
timeout-minutes: 5
|
||||||
steps:
|
steps:
|
||||||
|
|
@ -98,6 +106,7 @@ jobs:
|
||||||
|
|
||||||
prose-lint-errors:
|
prose-lint-errors:
|
||||||
name: prose lint (vale, errors)
|
name: prose lint (vale, errors)
|
||||||
|
if: vars.PUBLIC_FORGE != 'true'
|
||||||
runs-on: [hive-ci]
|
runs-on: [hive-ci]
|
||||||
timeout-minutes: 5
|
timeout-minutes: 5
|
||||||
steps:
|
steps:
|
||||||
|
|
|
||||||
|
|
@ -17,6 +17,7 @@ on:
|
||||||
jobs:
|
jobs:
|
||||||
coverage:
|
coverage:
|
||||||
name: cargo llvm-cov
|
name: cargo llvm-cov
|
||||||
|
if: vars.PUBLIC_FORGE != 'true'
|
||||||
runs-on: [hive-ci]
|
runs-on: [hive-ci]
|
||||||
# Above the 30 min `nix flake check` allows, because instrumented
|
# Above the 30 min `nix flake check` allows, because instrumented
|
||||||
# builds are slower than the ordinary ones and this starts from a
|
# builds are slower than the ordinary ones and this starts from a
|
||||||
|
|
|
||||||
|
|
@ -22,6 +22,7 @@ on:
|
||||||
jobs:
|
jobs:
|
||||||
update:
|
update:
|
||||||
name: nix flake update
|
name: nix flake update
|
||||||
|
if: vars.PUBLIC_FORGE != 'true'
|
||||||
runs-on: [hive-ci]
|
runs-on: [hive-ci]
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
steps:
|
steps:
|
||||||
|
|
|
||||||
41
.forgejo/workflows/public-cache.yml
Normal file
41
.forgejo/workflows/public-cache.yml
Normal file
|
|
@ -0,0 +1,41 @@
|
||||||
|
# Trust property: `on:` is push-to-main only — no `pull_request`, no
|
||||||
|
# `workflow_dispatch`, no schedule — so this never runs against an
|
||||||
|
# untrusted diff, and the `PREEM_PUSH_TOKEN` secret never reaches a PR
|
||||||
|
# run. The job also gates on the `PUBLIC_FORGE` repo variable, an
|
||||||
|
# opt-in only the public copy sets — job-level `if:` can't see the
|
||||||
|
# `github`/`forgejo` context on this runner (confirmed empirically),
|
||||||
|
# so origin/URL comparisons aren't usable here; `vars.*` is. Internal
|
||||||
|
# CI's own jobs gate on the inverse, so if this variable is ever unset
|
||||||
|
# or misconfigured, internal CI keeps running (fail toward "still
|
||||||
|
# tests", not "silently skips").
|
||||||
|
name: public bin cache
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
push-cache:
|
||||||
|
name: build + push to preem:grid
|
||||||
|
if: vars.PUBLIC_FORGE == 'true'
|
||||||
|
runs-on: nixos
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v3
|
||||||
|
- name: build the deployed closures
|
||||||
|
run: |
|
||||||
|
nix build \
|
||||||
|
.#default \
|
||||||
|
.#swarm-controller \
|
||||||
|
.#swarmctl \
|
||||||
|
.#swarm-ui \
|
||||||
|
.#swarm-nats-auth \
|
||||||
|
.#swarm-matrix-ctl \
|
||||||
|
.#swarm-authelia-bridge
|
||||||
|
- name: push to the public cache
|
||||||
|
env:
|
||||||
|
PREEM_PUSH_TOKEN: ${{ secrets.PREEM_PUSH_TOKEN }}
|
||||||
|
run: |
|
||||||
|
nix shell --inputs-from . nixpkgs#attic-client -c sh -c '
|
||||||
|
attic login preem https://preem-bincache.trollhive.monster "$PREEM_PUSH_TOKEN"
|
||||||
|
attic push preem:grid ./result*
|
||||||
|
'
|
||||||
Loading…
Reference in a new issue