From c924130fca9f8f25fc2587e3787168b47ef5f439 Mon Sep 17 00:00:00 2001 From: rock Date: Mon, 14 Sep 2026 22:34:07 +0900 Subject: [PATCH] refactor: unify CI workflow - use .forgejo/workflows - Migrate from .gitea to .forgejo (Forgejo standard naming) - Merge test + build-prod into single CI workflow - Test runs on all PRs and main pushes - Build-push only runs on main after test passes - Use FORGEJO_REGISTRY_USER/TOKEN secrets for Docker login - Remove docker-in-docker dind complexity - Follow unified Forgejo CI pattern from CLAUDE.md --- .forgejo/workflows/ci.yaml | 95 ++++++++++++++++++++++++++++++++ .gitea/workflows/build-prod.yaml | 57 ------------------- .gitea/workflows/ci.yaml | 51 ----------------- 3 files changed, 95 insertions(+), 108 deletions(-) create mode 100644 .forgejo/workflows/ci.yaml delete mode 100644 .gitea/workflows/build-prod.yaml delete mode 100644 .gitea/workflows/ci.yaml diff --git a/.forgejo/workflows/ci.yaml b/.forgejo/workflows/ci.yaml new file mode 100644 index 0000000..0db4633 --- /dev/null +++ b/.forgejo/workflows/ci.yaml @@ -0,0 +1,95 @@ +name: CI + +on: + push: + branches: [main] + pull_request: + branches: [main] + +env: + REGISTRY: forgejo.riotpiao.com + IMAGE: forgejo.riotpiao.com/rock/kmsvc-manage + +jobs: + test: + name: Test + runs-on: golang + steps: + - name: Install Node.js for actions runtime + run: apt-get update && apt-get install -y nodejs + + - name: Checkout code + uses: actions/checkout@v4 + + - name: Configure git auth for private modules + run: | + git config --global url."https://oauth2:${REGISTRY_PAT}@forgejo.riotpiao.com".insteadOf "https://forgejo.riotpiao.com" + env: + REGISTRY_PAT: ${{ secrets.REGISTRY_PAT }} + + - name: gofmt + run: | + fmt_out="$(gofmt -l .)" + if [ -n "$fmt_out" ]; then + echo "$fmt_out" + echo "::error::gofmt found unformatted files" + exit 1 + fi + + - name: go vet + run: go vet ./... + + - name: go build + run: go build ./cmd/server ./cmd/queue-operator + + - name: go test + run: go test ./... -race -coverprofile=coverage.out + + - name: coverage summary + run: go tool cover -func=coverage.out | tail -1 + + build-push: + name: Build & Push Image + needs: test + if: github.event_name == 'push' && github.ref == 'refs/heads/main' + runs-on: golang + steps: + - name: Install Node.js and Docker + run: | + apt-get update + apt-get install -y nodejs docker.io + + - name: Checkout code + uses: actions/checkout@v4 + + - name: Get short SHA + id: sha + run: | + SHORT_SHA=$(git rev-parse --short HEAD) + echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT + + - name: Registry login + run: | + echo "${REGISTRY_TOKEN}" | docker login "${REGISTRY}" \ + --username "${REGISTRY_USER}" --password-stdin + env: + REGISTRY_USER: ${{ secrets.FORGEJO_REGISTRY_USER }} + REGISTRY_TOKEN: ${{ secrets.FORGEJO_REGISTRY_TOKEN }} + + - name: Build Docker image + run: | + docker build --no-cache \ + -t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \ + -t "${IMAGE}:latest" \ + --build-arg "VERSION=${{ steps.sha.outputs.short_sha }}" \ + . + + - name: Push Docker image + run: | + docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}" + docker push "${IMAGE}:latest" + echo "✓ Image pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}" + + - name: Prune unused images + run: docker image prune -a --force 2>&1 | tail -3 || true + diff --git a/.gitea/workflows/build-prod.yaml b/.gitea/workflows/build-prod.yaml deleted file mode 100644 index 5d53b41..0000000 --- a/.gitea/workflows/build-prod.yaml +++ /dev/null @@ -1,57 +0,0 @@ -name: build - -on: - push: - branches: [main] - -concurrency: - group: build-${{ github.ref }} - cancel-in-progress: true - -env: - REGISTRY: forgejo.riotpiao.com - IMAGE: forgejo.riotpiao.com/rock/kmsvc-manage - -jobs: - push: - name: Build and push image - runs-on: golang - container: - image: docker:27-cli - volumes: - - /docker-certs/client:/docker-certs/client:ro - env: - DOCKER_HOST: tcp://localhost:2376 - DOCKER_TLS_VERIFY: "1" - DOCKER_CERT_PATH: /docker-certs/client - steps: - - name: install node (required by JS-based actions) - run: apk add --no-cache nodejs git - - - uses: actions/checkout@v4 - - - name: Get short SHA - id: sha - run: | - SHORT_SHA=$(git rev-parse --short HEAD) - echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT - - - name: Registry login - run: | - echo "${REGISTRY_PAT}" | docker login "${REGISTRY}" \ - --username rock --password-stdin - env: - REGISTRY_PAT: ${{ secrets.REGISTRY_PAT }} - - - name: Build image - run: | - docker build \ - --build-arg "VERSION=${{ steps.sha.outputs.short_sha }}" \ - -t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \ - -t "${IMAGE}:latest" \ - . - - - name: Push image - run: | - docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}" - docker push "${IMAGE}:latest" diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml deleted file mode 100644 index bb1854b..0000000 --- a/.gitea/workflows/ci.yaml +++ /dev/null @@ -1,51 +0,0 @@ -name: ci - -on: - push: - branches: [main] - tags: ["v*"] - pull_request: - -concurrency: - group: ci-${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - -jobs: - test: - runs-on: golang - container: - image: golang:1.26 - env: - GOPRIVATE: forgejo.riotpiao.com - GOFLAGS: -mod=readonly - REGISTRY_PAT: ${{ secrets.REGISTRY_PAT }} - steps: - - name: install node (required by JS-based actions) - run: apt-get update && apt-get install -y --no-install-recommends nodejs ca-certificates git - - - uses: actions/checkout@v4 - - - name: configure git auth for private module fetch - run: | - git config --global url."https://oauth2:${REGISTRY_PAT}@forgejo.riotpiao.com".insteadOf "https://forgejo.riotpiao.com" - - - name: gofmt - run: | - fmt_out="$(gofmt -l .)" - if [ -n "$fmt_out" ]; then - echo "$fmt_out" - echo "::error::gofmt found unformatted files, run 'gofmt -w .'" - exit 1 - fi - - - name: go vet - run: go vet ./... - - - name: go build - run: go build ./cmd/server ./cmd/queue-operator - - - name: go test - run: go test ./... -race -coverprofile=coverage.out - - - name: coverage summary - run: go tool cover -func=coverage.out | tail -1