Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
Guards internal-only jobs (ci.yml, coverage.yml, flake-update.yml) with `vars.PUBLIC_CACHE != 'true'` and adds public-cache.yml, guarded to the inverse, to build the deployed closures and push them to the public attic cache on a push to main. `PUBLIC_CACHE` is a repo Actions variable, opt-in only on the public copy: unset here, it leaves internal CI's `!=` guards true so internal jobs always run. Job-level `if:` cannot see the `github`/`forgejo` context at all on this runner (confirmed empirically — a `github.server_url` comparison always evaluates false at job level, though the identical comparison resolves correctly inside a step), so `vars.*`, which is available at job level, is the only usable opt-in signal here.
41 lines
1.5 KiB
YAML
41 lines
1.5 KiB
YAML
# Trust property: `on:` is push-to-main only — no `pull_request`, no
|
|
# `workflow_dispatch`, no schedule — so this never runs against an
|
|
# untrusted diff, and the `PREEM_PUSH_TOKEN` secret never reaches a PR
|
|
# run. The job also gates on the `PUBLIC_FORGE` repo variable, an
|
|
# opt-in only the public copy sets — job-level `if:` can't see the
|
|
# `github`/`forgejo` context on this runner (confirmed empirically),
|
|
# so origin/URL comparisons aren't usable here; `vars.*` is. Internal
|
|
# CI's own jobs gate on the inverse, so if this variable is ever unset
|
|
# or misconfigured, internal CI keeps running (fail toward "still
|
|
# tests", not "silently skips").
|
|
name: public bin cache
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
jobs:
|
|
push-cache:
|
|
name: build + push to preem:grid
|
|
if: vars.PUBLIC_FORGE == 'true'
|
|
runs-on: nixos
|
|
steps:
|
|
- uses: actions/checkout@v3
|
|
- name: build the deployed closures
|
|
run: |
|
|
nix build \
|
|
.#default \
|
|
.#swarm-controller \
|
|
.#swarmctl \
|
|
.#swarm-ui \
|
|
.#swarm-nats-auth \
|
|
.#swarm-matrix-ctl \
|
|
.#swarm-authelia-bridge
|
|
- name: push to the public cache
|
|
env:
|
|
PREEM_PUSH_TOKEN: ${{ secrets.PREEM_PUSH_TOKEN }}
|
|
run: |
|
|
nix shell --inputs-from . nixpkgs#attic-client -c sh -c '
|
|
attic login preem https://preem-bincache.trollhive.monster "$PREEM_PUSH_TOKEN"
|
|
attic push preem:grid ./result*
|
|
'
|