# Trust property: `on:` is push-to-main only — no `pull_request`, no # `workflow_dispatch`, no schedule — so this never runs against an # untrusted diff, and the `PREEM_PUSH_TOKEN` secret never reaches a PR # run. The job also gates on the `PUBLIC_FORGE` repo variable, an # opt-in only the public copy sets — job-level `if:` can't see the # `github`/`forgejo` context on this runner (confirmed empirically), # so origin/URL comparisons aren't usable here; `vars.*` is. Internal # CI's own jobs gate on the inverse, so if this variable is ever unset # or misconfigured, internal CI keeps running (fail toward "still # tests", not "silently skips"). name: public bin cache on: push: branches: [main] jobs: push-cache: name: build + push to preem:grid if: vars.PUBLIC_FORGE == 'true' runs-on: nixos steps: - uses: actions/checkout@v3 - name: build the deployed closures run: | nix build \ .#default \ .#swarm-controller \ .#swarmctl \ .#swarm-ui \ .#swarm-nats-auth \ .#swarm-matrix-ctl \ .#swarm-authelia-bridge - name: push to the public cache env: PREEM_PUSH_TOKEN: ${{ secrets.PREEM_PUSH_TOKEN }} run: | nix shell --inputs-from . nixpkgs#attic-client -c sh -c ' attic login preem https://preem-bincache.trollhive.monster "$PREEM_PUSH_TOKEN" attic push preem:grid ./result* '