Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/.forgejo/workflows/ci.yml
atlas 97c4771514
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
ci: run nothing but a main-only bin-cache push on the public forge
Guards internal-only jobs (ci.yml, coverage.yml, flake-update.yml) with
`vars.PUBLIC_CACHE != 'true'` and adds public-cache.yml, guarded to the
inverse, to build the deployed closures and push them to the public
attic cache on a push to main.

`PUBLIC_CACHE` is a repo Actions variable, opt-in only on the public
copy: unset here, it leaves internal CI's `!=` guards true so internal
jobs always run. Job-level `if:` cannot see the `github`/`forgejo`
context at all on this runner (confirmed empirically — a
`github.server_url` comparison always evaluates false at job level,
though the identical comparison resolves correctly inside a step),
so `vars.*`, which is available at job level, is the only usable
opt-in signal here.
2026-09-28 17:24:06 +02:00

117 lines
3.6 KiB
YAML

name: CI
on:
# No `push` trigger, so nothing re-validates a merge commit on main — an accepted infra-load tradeoff mara signed off on, not an oversight.
pull_request:
branches: ["**"]
# Lets `hive-forge ci-rerun` re-trigger CI via workflow-dispatch API
workflow_dispatch:
jobs:
check:
name: nix flake check
if: vars.PUBLIC_FORGE != 'true'
runs-on: [hive-ci]
# 30 min is well above a cold-cache rebuild (~15 min observed) and well
# under the runner's 3h cap
timeout-minutes: 30
steps:
- uses: actions/checkout@v3
- name: check
run: nix flake check
tracker-tags:
name: tracker-tag lint
if: vars.PUBLIC_FORGE != 'true'
runs-on: [hive-ci]
timeout-minutes: 5
steps:
- uses: actions/checkout@v3
- name: lint
run: sh scripts/check-issue-refs.sh
comment-blocks:
name: comment-block lint
if: vars.PUBLIC_FORGE != 'true'
runs-on: [hive-ci]
timeout-minutes: 5
steps:
- uses: actions/checkout@v3
- name: lint
run: sh scripts/check-comment-blocks.sh
doc-refs:
name: doc-pointer lint
if: vars.PUBLIC_FORGE != 'true'
runs-on: [hive-ci]
timeout-minutes: 5
steps:
- uses: actions/checkout@v3
- name: lint
run: sh scripts/check-doc-refs.sh
attribution-trailers:
name: attribution-trailer lint
if: vars.PUBLIC_FORGE != 'true'
runs-on: [hive-ci]
timeout-minutes: 5
steps:
- uses: actions/checkout@v3
with:
fetch-depth: 0
- name: lint
run: sh scripts/check-attribution-trailers.sh
dashboard-descriptions:
name: dashboard-description lint
if: vars.PUBLIC_FORGE != 'true'
runs-on: [hive-ci]
timeout-minutes: 5
steps:
- uses: actions/checkout@v3
- name: lint
# jq isn't a project dependency elsewhere in this repo — same
# nix-shell-for-one-tool shape the vale/shellcheck jobs above use.
run: nix shell nixpkgs#jq --command sh scripts/check-dashboard-descriptions.sh
shellcheck:
name: shellcheck
if: vars.PUBLIC_FORGE != 'true'
runs-on: [hive-ci]
timeout-minutes: 10
steps:
- uses: actions/checkout@v3
- name: lint
# By shebang, not a `*.sh` glob — scripts/pre-push has no suffix.
run: |
files=$(grep -lE '^#!.*/(env[[:space:]]+)?(ba)?sh([[:space:]]|$)' scripts/* 2>/dev/null)
if [ -z "$files" ]; then
echo "no shell files discovered under scripts/ — check the shebang pattern" >&2
exit 1
fi
echo "$files" | xargs nix develop -c shellcheck -S warning
prose-lint:
name: prose lint (vale)
if: vars.PUBLIC_FORGE != 'true'
runs-on: [hive-ci]
timeout-minutes: 5
steps:
- uses: actions/checkout@v3
- name: lint
# Styles are fetched fresh from Vale Package Hub each run (not vendored).
# Not wired into branch protection — see prose-lint-errors below for the
# error-only slice that is.
run: XDG_DATA_HOME="$PWD/.vale-data" nix shell nixpkgs#vale --command sh -c 'vale sync && vale docs'
prose-lint-errors:
name: prose lint (vale, errors)
if: vars.PUBLIC_FORGE != 'true'
runs-on: [hive-ci]
timeout-minutes: 5
steps:
- uses: actions/checkout@v3
- name: lint
# Error-level-only slice. Split out so this job alone can be a required
# check without blocking merges on the warning/suggestion backlog.
run: XDG_DATA_HOME="$PWD/.vale-data" nix shell nixpkgs#vale --command sh -c 'vale sync && vale --minAlertLevel=error docs'