feat(ci): checks-on-push workflow (Forgejo Actions, eval tier)
.forgejo/workflows/check.yml runs on every push to main/v1 (+ manual dispatch): nix flake check --no-build (full module-system eval incl. the downstream template through mkFlake), py_compile of nomarchy-theme-sync, and bash -n over tracked .sh files. The always-on net under direct-to-main pushes — first slice of the ROADMAP lock-bump CI item. Scoped to the eval tier deliberately: the instance's runner is an act_runner docker container (no systemd, no /dev/kvm — established from the legacy repo's .gitea/workflows/check.yml, which ran 57 times on it), so the checks.* VM suite and real builds can't run there. A commented vm-checks job documents the KVM-runner upgrade path; the legacy workflow's container gotchas (nixbld setup for the single-user installer, sandbox=false for Stylix IFD, Nix pinned 2.31.5 vs lazy-trees, no JS actions past node20) are carried over verbatim in the header. docs/TESTING.md §1b documents what a green run does and does not mean. Verified: V0 locally (the same check commands, minus the container Nix install) + YAML parse. A real green run depends on the runner still being registered — not API-visible unauthenticated, so that is queued as [human] BACKLOG item 20. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -17,6 +17,25 @@ Template:
|
||||
|
||||
---
|
||||
|
||||
## 2026-07-04 — CI checks-on-push shipped (loop iteration #2)
|
||||
- **Task:** BACKLOG NOW#2 — Forgejo Actions workflow.
|
||||
- **Did:** `.forgejo/workflows/check.yml` (push to main/v1 + dispatch):
|
||||
flake check --no-build, theme-sync py_compile, bash -n over tracked
|
||||
.sh. Scoped to the **eval tier** deliberately — API probing +
|
||||
archaeology of the legacy `.gitea/workflows/check.yml` (57 runs on
|
||||
this instance) showed the runner is an act_runner docker container
|
||||
(no KVM/systemd), so the VM suite can't run there; a commented
|
||||
`vm-checks` job documents the KVM-runner upgrade path. Legacy's
|
||||
hard-won container gotchas (nixbld setup, sandbox=false for Stylix
|
||||
IFD, Nix 2.31.5 pin) carried over verbatim. TESTING.md §1b added.
|
||||
- **Verified:** V0 locally (same commands the workflow runs, minus the
|
||||
container Nix install) + yq YAML parse. The real green run needs the
|
||||
runner to be alive — **not confirmable from here** (runners API is
|
||||
401 unauthenticated); watching the run after push.
|
||||
- **Pending:** new `[human]` item 20 — confirm/re-register the runner;
|
||||
stretch: a KVM runner unlocks the vm-checks job.
|
||||
- **Next suggestion:** NOW#3 (memory-pressure protection).
|
||||
|
||||
## 2026-07-04 — Opt-in auto-commit shipped (loop iteration #1)
|
||||
- **Task:** BACKLOG NOW#1 — auto-commit of state mutations (in-flake
|
||||
state Phase 4). First autonomous /loop iteration.
|
||||
|
||||
Reference in New Issue
Block a user