itsybitsy/.forgejo/workflows/ci.yml
randogoth 1b47145522 build: wire a Forgejo Actions workflow for checks and the static-binary release
check runs devbox run check on push, PR and dispatch; release reuses the
existing nix run .#release-static app to ship packages.static as a Forgejo
release tagged by short commit hash, gated on check passing first.
2026-10-11 09:07:54 +03:00

54 lines
2.1 KiB
YAML

name: CI
on:
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
check:
runs-on: linux-x86_64
steps:
- uses: https://code.forgejo.org/actions/checkout@v4
- uses: https://code.forgejo.org/actions/cache@v4
with:
path: |
~/.cargo/registry
target
key: cargo-linux-${{ hashFiles('Cargo.lock') }}
restore-keys: cargo-linux-
# Forgejo auto-injects GITHUB_TOKEN (GH Actions compatibility), scoped
# to this Forgejo instance. Nix auto-detects that env var and assumes
# it's a github.com credential, so it sends it to api.github.com when
# fetching nixpkgs tarballs for devbox - which rejects it with 401.
# Clearing it here falls back to unauthenticated (fine for public
# nixpkgs fetches, same as this succeeds locally with no token set).
- run: devbox run check
env:
GITHUB_TOKEN: ""
# Ships the static musl binary (flake.nix packages.static) the way
# `nix run .#release-static` already does from a dev machine: one release
# per commit landing on main, tagged by its short hash, created if absent
# and with its asset replaced if present. Gated on `check` so a failing
# build or test on main is never published - unlike a tag push, which only
# happens once a human has already decided a commit is good, a push to
# main is not itself that decision.
#
# `nix build`/`nix run` draw from the Nix store and its binary cache, not
# from ~/.cargo/registry or ./target, so there is nothing here for the
# `check` job's cache to help with.
release:
needs: check
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
runs-on: linux-x86_64
steps:
- uses: https://code.forgejo.org/actions/checkout@v4
# forge.token is Forgejo Actions' auto-injected, repo-scoped
# credential - the CI equivalent of running this app locally with
# FORGEJO_TOKEN set in .env.
- run: nix run .#release-static
env:
FORGEJO_TOKEN: ${{ forge.token }}
GITHUB_TOKEN: ""