From 1b47145522331a88a047c03933facb78d653bb09 Mon Sep 17 00:00:00 2001 From: randogoth Date: Sun, 11 Oct 2026 08:22:52 +0300 Subject: [PATCH] build: wire a Forgejo Actions workflow for checks and the static-binary release check runs devbox run check on push, PR and dispatch; release reuses the existing nix run .#release-static app to ship packages.static as a Forgejo release tagged by short commit hash, gated on check passing first. --- .forgejo/workflows/ci.yml | 54 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 54 insertions(+) create mode 100644 .forgejo/workflows/ci.yml diff --git a/.forgejo/workflows/ci.yml b/.forgejo/workflows/ci.yml new file mode 100644 index 0000000..6e825b6 --- /dev/null +++ b/.forgejo/workflows/ci.yml @@ -0,0 +1,54 @@ +name: CI + +on: + push: + branches: [main] + pull_request: + workflow_dispatch: + +jobs: + check: + runs-on: linux-x86_64 + steps: + - uses: https://code.forgejo.org/actions/checkout@v4 + - uses: https://code.forgejo.org/actions/cache@v4 + with: + path: | + ~/.cargo/registry + target + key: cargo-linux-${{ hashFiles('Cargo.lock') }} + restore-keys: cargo-linux- + # Forgejo auto-injects GITHUB_TOKEN (GH Actions compatibility), scoped + # to this Forgejo instance. Nix auto-detects that env var and assumes + # it's a github.com credential, so it sends it to api.github.com when + # fetching nixpkgs tarballs for devbox - which rejects it with 401. + # Clearing it here falls back to unauthenticated (fine for public + # nixpkgs fetches, same as this succeeds locally with no token set). + - run: devbox run check + env: + GITHUB_TOKEN: "" + + # Ships the static musl binary (flake.nix packages.static) the way + # `nix run .#release-static` already does from a dev machine: one release + # per commit landing on main, tagged by its short hash, created if absent + # and with its asset replaced if present. Gated on `check` so a failing + # build or test on main is never published - unlike a tag push, which only + # happens once a human has already decided a commit is good, a push to + # main is not itself that decision. + # + # `nix build`/`nix run` draw from the Nix store and its binary cache, not + # from ~/.cargo/registry or ./target, so there is nothing here for the + # `check` job's cache to help with. + release: + needs: check + if: github.event_name == 'push' && github.ref == 'refs/heads/main' + runs-on: linux-x86_64 + steps: + - uses: https://code.forgejo.org/actions/checkout@v4 + # forge.token is Forgejo Actions' auto-injected, repo-scoped + # credential - the CI equivalent of running this app locally with + # FORGEJO_TOKEN set in .env. + - run: nix run .#release-static + env: + FORGEJO_TOKEN: ${{ forge.token }} + GITHUB_TOKEN: ""