check runs devbox run check on push, PR and dispatch; release reuses the existing nix run .#release-static app to ship packages.static as a Forgejo release tagged by short commit hash, gated on check passing first.
54 lines
2.1 KiB
YAML
54 lines
2.1 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
check:
|
|
runs-on: linux-x86_64
|
|
steps:
|
|
- uses: https://code.forgejo.org/actions/checkout@v4
|
|
- uses: https://code.forgejo.org/actions/cache@v4
|
|
with:
|
|
path: |
|
|
~/.cargo/registry
|
|
target
|
|
key: cargo-linux-${{ hashFiles('Cargo.lock') }}
|
|
restore-keys: cargo-linux-
|
|
# Forgejo auto-injects GITHUB_TOKEN (GH Actions compatibility), scoped
|
|
# to this Forgejo instance. Nix auto-detects that env var and assumes
|
|
# it's a github.com credential, so it sends it to api.github.com when
|
|
# fetching nixpkgs tarballs for devbox - which rejects it with 401.
|
|
# Clearing it here falls back to unauthenticated (fine for public
|
|
# nixpkgs fetches, same as this succeeds locally with no token set).
|
|
- run: devbox run check
|
|
env:
|
|
GITHUB_TOKEN: ""
|
|
|
|
# Ships the static musl binary (flake.nix packages.static) the way
|
|
# `nix run .#release-static` already does from a dev machine: one release
|
|
# per commit landing on main, tagged by its short hash, created if absent
|
|
# and with its asset replaced if present. Gated on `check` so a failing
|
|
# build or test on main is never published - unlike a tag push, which only
|
|
# happens once a human has already decided a commit is good, a push to
|
|
# main is not itself that decision.
|
|
#
|
|
# `nix build`/`nix run` draw from the Nix store and its binary cache, not
|
|
# from ~/.cargo/registry or ./target, so there is nothing here for the
|
|
# `check` job's cache to help with.
|
|
release:
|
|
needs: check
|
|
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
|
|
runs-on: linux-x86_64
|
|
steps:
|
|
- uses: https://code.forgejo.org/actions/checkout@v4
|
|
# forge.token is Forgejo Actions' auto-injected, repo-scoped
|
|
# credential - the CI equivalent of running this app locally with
|
|
# FORGEJO_TOKEN set in .env.
|
|
- run: nix run .#release-static
|
|
env:
|
|
FORGEJO_TOKEN: ${{ forge.token }}
|
|
GITHUB_TOKEN: ""
|