add ci
Some checks failed
build / build (muede-lpt2) (push) Has been cancelled
build / build (muede-pc2) (push) Has been cancelled
build / close-on-failure (push) Has been cancelled

This commit is contained in:
müde 2026-09-13 14:36:08 +02:00
commit cb4acd6665
4 changed files with 104 additions and 0 deletions

View file

@ -0,0 +1,36 @@
name: build
on:
pull_request: {}
push:
branches: [ main ]
jobs:
build:
runs-on: nixos
strategy:
matrix:
# keep-sorted start
host: [muede-lpt2, muede-pc2]
# keep-sorted end
steps:
- uses: https://code.forgejo.org/actions/checkout@v4
- run: nix build --no-link .#nixosConfigurations.${{ matrix.host }}.config.system.build.toplevel
# nightly-flake-update.yaml opens PRs from flake-update-* branches; if
# the build fails on one of those, close it rather than leaving a
# broken auto-generated PR around. Scoped to that branch prefix so a
# failing build on a human-authored PR is never auto-closed.
close-on-failure:
needs: build
if: failure() && startsWith(github.head_ref, 'flake-update-')
runs-on: nixos
steps:
- run: |
curl -sf -X PATCH \
-H "Authorization: token ${PR_BOT_TOKEN}" \
-H "Content-Type: application/json" \
-d '{"state": "closed"}' \
"https://forge.darkest.space/api/v1/repos/mara/nixos-configs/pulls/${{ github.event.pull_request.number }}"
env:
PR_BOT_TOKEN: ${{ secrets.PR_BOT_TOKEN }}

View file

@ -0,0 +1,33 @@
name: nightly flake update
on:
schedule:
- cron: '0 3 * * *'
workflow_dispatch: {}
jobs:
update:
runs-on: nixos
steps:
- uses: https://code.forgejo.org/actions/checkout@v4
- run: |
nix flake update
if git diff --quiet -- flake.lock; then
exit 0
fi
branch="flake-update-$(date +%F)"
git checkout -b "$branch"
git -c user.name="flake-update-bot" -c user.email="flake-update-bot@darkest.space" \
commit -am "flake: nightly update"
git push "https://flake-update-bot:${PR_BOT_TOKEN}@forge.darkest.space/mara/nixos-configs.git" "$branch"
curl -sf -X POST \
-H "Authorization: token ${PR_BOT_TOKEN}" \
-H "Content-Type: application/json" \
-d "$(jq -n --arg h "$branch" \
'{title: "flake: nightly update", head: $h, base: "main"}')" \
"https://forge.darkest.space/api/v1/repos/mara/nixos-configs/pulls"
env:
PR_BOT_TOKEN: ${{ secrets.PR_BOT_TOKEN }}

View file

@ -2,6 +2,7 @@
{
imports = [
./hardware.nix
./gitea-runner.nix
# ./vscode-server.nix
# ./hass.nix
];

View file

@ -0,0 +1,34 @@
{ config, pkgs, ... }:
{
environment.systemPackages = [ pkgs.forgejo-runner ];
# https://wiki.nixos.org/wiki/Forgejo
services.gitea-actions-runner = {
package = pkgs.forgejo-runner;
instances.default = {
enable = true;
name = "pc2";
url = "https://forge.darkest.space";
# tokenFile should be in format TOKEN=<secret>, since it's EnvironmentFile for systemd
# placed manually, not managed by Nix
tokenFile = "/etc/forgejo-runner/registration_token";
# no docker:// image -> jobs run directly on the host, giving them
# pc2's real Nix store/daemon (needed for `nix build` results to be
# substitutable by other hosts via the existing distributed-builds mesh)
labels = [ "nixos:host" ];
hostPackages = with pkgs; [
bash
coreutils
curl
gawk
gitMinimal
gnused
jq
nodejs
wget
config.nix.package
];
};
};
}