ci: run nothing but a main-only bin-cache push on the public forge
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
Guards internal-only jobs (ci.yml, coverage.yml, flake-update.yml) with `vars.PUBLIC_CACHE != 'true'` and adds public-cache.yml, guarded to the inverse, to build the deployed closures and push them to the public attic cache on a push to main. `PUBLIC_CACHE` is a repo Actions variable, opt-in only on the public copy: unset here, it leaves internal CI's `!=` guards true so internal jobs always run. Job-level `if:` cannot see the `github`/`forgejo` context at all on this runner (confirmed empirically — a `github.server_url` comparison always evaluates false at job level, though the identical comparison resolves correctly inside a step), so `vars.*`, which is available at job level, is the only usable opt-in signal here.
This commit is contained in:
parent
9a444c27fa
commit
97c4771514
4 changed files with 52 additions and 0 deletions
|
|
@ -10,6 +10,7 @@ on:
|
|||
jobs:
|
||||
check:
|
||||
name: nix flake check
|
||||
if: vars.PUBLIC_FORGE != 'true'
|
||||
runs-on: [hive-ci]
|
||||
# 30 min is well above a cold-cache rebuild (~15 min observed) and well
|
||||
# under the runner's 3h cap
|
||||
|
|
@ -21,6 +22,7 @@ jobs:
|
|||
|
||||
tracker-tags:
|
||||
name: tracker-tag lint
|
||||
if: vars.PUBLIC_FORGE != 'true'
|
||||
runs-on: [hive-ci]
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
|
|
@ -30,6 +32,7 @@ jobs:
|
|||
|
||||
comment-blocks:
|
||||
name: comment-block lint
|
||||
if: vars.PUBLIC_FORGE != 'true'
|
||||
runs-on: [hive-ci]
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
|
|
@ -39,6 +42,7 @@ jobs:
|
|||
|
||||
doc-refs:
|
||||
name: doc-pointer lint
|
||||
if: vars.PUBLIC_FORGE != 'true'
|
||||
runs-on: [hive-ci]
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
|
|
@ -48,6 +52,7 @@ jobs:
|
|||
|
||||
attribution-trailers:
|
||||
name: attribution-trailer lint
|
||||
if: vars.PUBLIC_FORGE != 'true'
|
||||
runs-on: [hive-ci]
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
|
|
@ -59,6 +64,7 @@ jobs:
|
|||
|
||||
dashboard-descriptions:
|
||||
name: dashboard-description lint
|
||||
if: vars.PUBLIC_FORGE != 'true'
|
||||
runs-on: [hive-ci]
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
|
|
@ -70,6 +76,7 @@ jobs:
|
|||
|
||||
shellcheck:
|
||||
name: shellcheck
|
||||
if: vars.PUBLIC_FORGE != 'true'
|
||||
runs-on: [hive-ci]
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
|
|
@ -86,6 +93,7 @@ jobs:
|
|||
|
||||
prose-lint:
|
||||
name: prose lint (vale)
|
||||
if: vars.PUBLIC_FORGE != 'true'
|
||||
runs-on: [hive-ci]
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
|
|
@ -98,6 +106,7 @@ jobs:
|
|||
|
||||
prose-lint-errors:
|
||||
name: prose lint (vale, errors)
|
||||
if: vars.PUBLIC_FORGE != 'true'
|
||||
runs-on: [hive-ci]
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
|
|
|
|||
|
|
@ -17,6 +17,7 @@ on:
|
|||
jobs:
|
||||
coverage:
|
||||
name: cargo llvm-cov
|
||||
if: vars.PUBLIC_FORGE != 'true'
|
||||
runs-on: [hive-ci]
|
||||
# Above the 30 min `nix flake check` allows, because instrumented
|
||||
# builds are slower than the ordinary ones and this starts from a
|
||||
|
|
|
|||
|
|
@ -22,6 +22,7 @@ on:
|
|||
jobs:
|
||||
update:
|
||||
name: nix flake update
|
||||
if: vars.PUBLIC_FORGE != 'true'
|
||||
runs-on: [hive-ci]
|
||||
timeout-minutes: 30
|
||||
steps:
|
||||
|
|
|
|||
41
.forgejo/workflows/public-cache.yml
Normal file
41
.forgejo/workflows/public-cache.yml
Normal file
|
|
@ -0,0 +1,41 @@
|
|||
# Trust property: `on:` is push-to-main only — no `pull_request`, no
|
||||
# `workflow_dispatch`, no schedule — so this never runs against an
|
||||
# untrusted diff, and the `PREEM_PUSH_TOKEN` secret never reaches a PR
|
||||
# run. The job also gates on the `PUBLIC_FORGE` repo variable, an
|
||||
# opt-in only the public copy sets — job-level `if:` can't see the
|
||||
# `github`/`forgejo` context on this runner (confirmed empirically),
|
||||
# so origin/URL comparisons aren't usable here; `vars.*` is. Internal
|
||||
# CI's own jobs gate on the inverse, so if this variable is ever unset
|
||||
# or misconfigured, internal CI keeps running (fail toward "still
|
||||
# tests", not "silently skips").
|
||||
name: public bin cache
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
|
||||
jobs:
|
||||
push-cache:
|
||||
name: build + push to preem:grid
|
||||
if: vars.PUBLIC_FORGE == 'true'
|
||||
runs-on: nixos
|
||||
steps:
|
||||
- uses: actions/checkout@v3
|
||||
- name: build the deployed closures
|
||||
run: |
|
||||
nix build \
|
||||
.#default \
|
||||
.#swarm-controller \
|
||||
.#swarmctl \
|
||||
.#swarm-ui \
|
||||
.#swarm-nats-auth \
|
||||
.#swarm-matrix-ctl \
|
||||
.#swarm-authelia-bridge
|
||||
- name: push to the public cache
|
||||
env:
|
||||
PREEM_PUSH_TOKEN: ${{ secrets.PREEM_PUSH_TOKEN }}
|
||||
run: |
|
||||
nix shell --inputs-from . nixpkgs#attic-client -c sh -c '
|
||||
attic login preem https://preem-bincache.trollhive.monster "$PREEM_PUSH_TOKEN"
|
||||
attic push preem:grid ./result*
|
||||
'
|
||||
Loading…
Reference in a new issue