fix(ci): move workflow to .gitea/workflows — the server is Gitea, not Forgejo
All checks were successful
Check / eval (push) Successful in 2m50s
All checks were successful
Check / eval (push) Successful in 2m50s
The runner was alive all along (gitea/act_runner, ubuntu-latest label); no run ever appeared because Gitea only reads .gitea/workflows/ (or .github/workflows/) and ignores the .forgejo/ path the workflow shipped under. The legacy repo's .gitea/workflows/check.yml was the clue. References corrected (workflow header, TESTING.md, agent files); this push doubles as the first live trigger of the workflow. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
101
.gitea/workflows/check.yml
Normal file
101
.gitea/workflows/check.yml
Normal file
@@ -0,0 +1,101 @@
|
||||
# Nomarchy CI — the always-on net under direct-to-main pushes.
|
||||
#
|
||||
# Scope (deliberate): the EVAL tier only. The runner behind this Gitea
|
||||
# instance is act_runner + docker containers (the legacy repo's check.yml
|
||||
# ran 57 times on it) — no systemd, no /dev/kvm — so the checks.* VM
|
||||
# tests and full toplevel builds can't run here. `nix flake check
|
||||
# --no-build` still catches most breakage (type errors, missing options,
|
||||
# bad merges, template/mkFlake drift — see docs/TESTING.md §1); the VM
|
||||
# suite stays a local/promotion gate until a KVM-capable NixOS runner
|
||||
# exists (see the commented vm-checks job at the bottom).
|
||||
#
|
||||
# Inherited-from-legacy gotchas (learned over 57 runs, kept verbatim):
|
||||
# - Single-user Nix (--no-daemon): no systemd in the container. The
|
||||
# installer runs as root and honours build-users-group=nixbld from
|
||||
# its bundled nix.conf, aborting unless the group exists AND has
|
||||
# members — create nixbld + users first.
|
||||
# - sandbox=false: Stylix/base16.nix do import-from-derivation; the
|
||||
# single-user Nix in this container can't set up the build sandbox
|
||||
# (no user namespaces), which otherwise surfaces as
|
||||
# "path '…-source' is not valid".
|
||||
# - Pin the Nix version: 2.34's lazy-trees git cache doesn't
|
||||
# materialise flake-input `-source` paths into the store, breaking
|
||||
# the same IFD reads. 2.31.5 matches what wrote flake.lock.
|
||||
# - Plain-shell Nix install, not a JS action: act_runner's bundled act
|
||||
# tops out at node20; a `run:` step has no node-runtime coupling.
|
||||
|
||||
name: Check
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main, v1]
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
eval:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 60
|
||||
env:
|
||||
NIX_CONFIG: |
|
||||
experimental-features = nix-command flakes
|
||||
sandbox = false
|
||||
NIX_SSL_CERT_FILE: /etc/ssl/certs/ca-certificates.crt
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Install Nix
|
||||
run: |
|
||||
NIX_VERSION=2.31.5
|
||||
groupadd -r nixbld 2>/dev/null || true
|
||||
for i in $(seq 1 10); do
|
||||
useradd -r -g nixbld -G nixbld -d /var/empty \
|
||||
-s /usr/sbin/nologin -c "Nix build user $i" "nixbld$i" 2>/dev/null || true
|
||||
done
|
||||
curl -L "https://releases.nixos.org/nix/nix-${NIX_VERSION}/install" | sh -s -- --no-daemon
|
||||
echo "$HOME/.nix-profile/bin" >> "$GITHUB_PATH"
|
||||
|
||||
- name: nix flake check (eval only)
|
||||
# Full module-system evaluation of every output — both nixos
|
||||
# configs, the home config, the checks.* derivations (instantiated,
|
||||
# not run) and the downstream template through lib.mkFlake.
|
||||
run: nix flake check --no-build
|
||||
|
||||
- name: Python syntax (nomarchy-theme-sync)
|
||||
# Via nix shell so the step doesn't depend on the runner image
|
||||
# preinstalling python3.
|
||||
run: |
|
||||
nix shell nixpkgs#python3 --command \
|
||||
python3 -m py_compile pkgs/nomarchy-theme-sync/nomarchy-theme-sync.py
|
||||
|
||||
- name: Shell syntax (tracked scripts)
|
||||
# The distro's user-facing scripts are generated by Nix (their
|
||||
# syntax is exercised by the eval + local builds); this covers the
|
||||
# hand-written .sh files: installer helpers and maintainer tools.
|
||||
run: |
|
||||
set -e
|
||||
fail=0
|
||||
while IFS= read -r script; do
|
||||
head -1 "$script" | grep -qE '^#!.*\b(bash|sh)\b' || continue
|
||||
if ! bash -n "$script"; then
|
||||
echo "::error file=$script::bash syntax error"
|
||||
fail=1
|
||||
fi
|
||||
done < <(git ls-files '*.sh')
|
||||
exit "$fail"
|
||||
|
||||
# ── vm-checks (DISABLED until a KVM runner exists) ────────────────────
|
||||
# The real prize: running the checks.* VM suite + a toplevel build in
|
||||
# CI. Needs a runner on a NixOS (or at least nix + /dev/kvm) host —
|
||||
# register one with a dedicated label, then uncomment and set runs-on
|
||||
# to that label. Do NOT enable this against a label that doesn't
|
||||
# exist: Gitea queues such jobs forever instead of failing.
|
||||
#
|
||||
# vm-checks:
|
||||
# runs-on: nix-kvm
|
||||
# timeout-minutes: 120
|
||||
# steps:
|
||||
# - uses: actions/checkout@v4
|
||||
# - run: nix flake check # builds + runs the VM tests
|
||||
# - run: nix build .#nixosConfigurations.nomarchy.config.system.build.toplevel --no-link
|
||||
# - run: nix build .#homeConfigurations.nomarchy.activationPackage --no-link
|
||||
Reference in New Issue
Block a user