build: wire a Forgejo Actions workflow for checks and the static-binary release
check runs devbox run check on push, PR and dispatch; release reuses the existing nix run .#release-static app to ship packages.static as a Forgejo release tagged by short commit hash, gated on check passing first.
This commit is contained in:
parent
603f29b0f0
commit
1b47145522
1 changed files with 54 additions and 0 deletions
54
.forgejo/workflows/ci.yml
Normal file
54
.forgejo/workflows/ci.yml
Normal file
|
|
@ -0,0 +1,54 @@
|
|||
name: CI
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
check:
|
||||
runs-on: linux-x86_64
|
||||
steps:
|
||||
- uses: https://code.forgejo.org/actions/checkout@v4
|
||||
- uses: https://code.forgejo.org/actions/cache@v4
|
||||
with:
|
||||
path: |
|
||||
~/.cargo/registry
|
||||
target
|
||||
key: cargo-linux-${{ hashFiles('Cargo.lock') }}
|
||||
restore-keys: cargo-linux-
|
||||
# Forgejo auto-injects GITHUB_TOKEN (GH Actions compatibility), scoped
|
||||
# to this Forgejo instance. Nix auto-detects that env var and assumes
|
||||
# it's a github.com credential, so it sends it to api.github.com when
|
||||
# fetching nixpkgs tarballs for devbox - which rejects it with 401.
|
||||
# Clearing it here falls back to unauthenticated (fine for public
|
||||
# nixpkgs fetches, same as this succeeds locally with no token set).
|
||||
- run: devbox run check
|
||||
env:
|
||||
GITHUB_TOKEN: ""
|
||||
|
||||
# Ships the static musl binary (flake.nix packages.static) the way
|
||||
# `nix run .#release-static` already does from a dev machine: one release
|
||||
# per commit landing on main, tagged by its short hash, created if absent
|
||||
# and with its asset replaced if present. Gated on `check` so a failing
|
||||
# build or test on main is never published - unlike a tag push, which only
|
||||
# happens once a human has already decided a commit is good, a push to
|
||||
# main is not itself that decision.
|
||||
#
|
||||
# `nix build`/`nix run` draw from the Nix store and its binary cache, not
|
||||
# from ~/.cargo/registry or ./target, so there is nothing here for the
|
||||
# `check` job's cache to help with.
|
||||
release:
|
||||
needs: check
|
||||
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
|
||||
runs-on: linux-x86_64
|
||||
steps:
|
||||
- uses: https://code.forgejo.org/actions/checkout@v4
|
||||
# forge.token is Forgejo Actions' auto-injected, repo-scoped
|
||||
# credential - the CI equivalent of running this app locally with
|
||||
# FORGEJO_TOKEN set in .env.
|
||||
- run: nix run .#release-static
|
||||
env:
|
||||
FORGEJO_TOKEN: ${{ forge.token }}
|
||||
GITHUB_TOKEN: ""
|
||||
Loading…
Add table
Add a link
Reference in a new issue