build: wire a Forgejo Actions workflow for checks and the static-binary release
check runs devbox run check on push, PR and dispatch; release reuses the existing nix run .#release-static app to ship packages.static as a Forgejo release tagged by short commit hash, gated on check passing first.
This commit is contained in:
parent
603f29b0f0
commit
1b47145522
1 changed files with 54 additions and 0 deletions
54
.forgejo/workflows/ci.yml
Normal file
54
.forgejo/workflows/ci.yml
Normal file
|
|
@ -0,0 +1,54 @@
|
||||||
|
name: CI
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
pull_request:
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
check:
|
||||||
|
runs-on: linux-x86_64
|
||||||
|
steps:
|
||||||
|
- uses: https://code.forgejo.org/actions/checkout@v4
|
||||||
|
- uses: https://code.forgejo.org/actions/cache@v4
|
||||||
|
with:
|
||||||
|
path: |
|
||||||
|
~/.cargo/registry
|
||||||
|
target
|
||||||
|
key: cargo-linux-${{ hashFiles('Cargo.lock') }}
|
||||||
|
restore-keys: cargo-linux-
|
||||||
|
# Forgejo auto-injects GITHUB_TOKEN (GH Actions compatibility), scoped
|
||||||
|
# to this Forgejo instance. Nix auto-detects that env var and assumes
|
||||||
|
# it's a github.com credential, so it sends it to api.github.com when
|
||||||
|
# fetching nixpkgs tarballs for devbox - which rejects it with 401.
|
||||||
|
# Clearing it here falls back to unauthenticated (fine for public
|
||||||
|
# nixpkgs fetches, same as this succeeds locally with no token set).
|
||||||
|
- run: devbox run check
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ""
|
||||||
|
|
||||||
|
# Ships the static musl binary (flake.nix packages.static) the way
|
||||||
|
# `nix run .#release-static` already does from a dev machine: one release
|
||||||
|
# per commit landing on main, tagged by its short hash, created if absent
|
||||||
|
# and with its asset replaced if present. Gated on `check` so a failing
|
||||||
|
# build or test on main is never published - unlike a tag push, which only
|
||||||
|
# happens once a human has already decided a commit is good, a push to
|
||||||
|
# main is not itself that decision.
|
||||||
|
#
|
||||||
|
# `nix build`/`nix run` draw from the Nix store and its binary cache, not
|
||||||
|
# from ~/.cargo/registry or ./target, so there is nothing here for the
|
||||||
|
# `check` job's cache to help with.
|
||||||
|
release:
|
||||||
|
needs: check
|
||||||
|
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
|
||||||
|
runs-on: linux-x86_64
|
||||||
|
steps:
|
||||||
|
- uses: https://code.forgejo.org/actions/checkout@v4
|
||||||
|
# forge.token is Forgejo Actions' auto-injected, repo-scoped
|
||||||
|
# credential - the CI equivalent of running this app locally with
|
||||||
|
# FORGEJO_TOKEN set in .env.
|
||||||
|
- run: nix run .#release-static
|
||||||
|
env:
|
||||||
|
FORGEJO_TOKEN: ${{ forge.token }}
|
||||||
|
GITHUB_TOKEN: ""
|
||||||
Loading…
Add table
Add a link
Reference in a new issue