From f8497c12378c700181083dc1ef76c37c191ef39f Mon Sep 17 00:00:00 2001 From: rock Date: Mon, 14 Sep 2026 22:50:10 +0900 Subject: [PATCH] refactor: unify CI workflow in .gitea/workflows - Merge test + release/build workflows into single ci.yaml - Add explicit job dependencies (build-push needs test) - Test runs on all PRs + main pushes - Build/release runs on main/tags only (after test passes) - Proper Node.js install before actions/checkout@v4 - Remove docker socket-breaking container overrides --- .gitea/workflows/build-prod.yaml | 57 ------------------------ .gitea/workflows/ci.yaml | 75 +++++++++++++++++++++++++------- 2 files changed, 59 insertions(+), 73 deletions(-) delete mode 100644 .gitea/workflows/build-prod.yaml diff --git a/.gitea/workflows/build-prod.yaml b/.gitea/workflows/build-prod.yaml deleted file mode 100644 index 5d53b41..0000000 --- a/.gitea/workflows/build-prod.yaml +++ /dev/null @@ -1,57 +0,0 @@ -name: build - -on: - push: - branches: [main] - -concurrency: - group: build-${{ github.ref }} - cancel-in-progress: true - -env: - REGISTRY: forgejo.riotpiao.com - IMAGE: forgejo.riotpiao.com/rock/kmsvc-manage - -jobs: - push: - name: Build and push image - runs-on: golang - container: - image: docker:27-cli - volumes: - - /docker-certs/client:/docker-certs/client:ro - env: - DOCKER_HOST: tcp://localhost:2376 - DOCKER_TLS_VERIFY: "1" - DOCKER_CERT_PATH: /docker-certs/client - steps: - - name: install node (required by JS-based actions) - run: apk add --no-cache nodejs git - - - uses: actions/checkout@v4 - - - name: Get short SHA - id: sha - run: | - SHORT_SHA=$(git rev-parse --short HEAD) - echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT - - - name: Registry login - run: | - echo "${REGISTRY_PAT}" | docker login "${REGISTRY}" \ - --username rock --password-stdin - env: - REGISTRY_PAT: ${{ secrets.REGISTRY_PAT }} - - - name: Build image - run: | - docker build \ - --build-arg "VERSION=${{ steps.sha.outputs.short_sha }}" \ - -t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \ - -t "${IMAGE}:latest" \ - . - - - name: Push image - run: | - docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}" - docker push "${IMAGE}:latest" diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index bb1854b..9edab4b 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -1,40 +1,38 @@ -name: ci +name: CI on: push: branches: [main] - tags: ["v*"] pull_request: + branches: [main] -concurrency: - group: ci-${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true +env: + REGISTRY: forgejo.riotpiao.com + IMAGE: forgejo.riotpiao.com/rock/kmsvc-manage jobs: test: + name: Test runs-on: golang - container: - image: golang:1.26 - env: - GOPRIVATE: forgejo.riotpiao.com - GOFLAGS: -mod=readonly - REGISTRY_PAT: ${{ secrets.REGISTRY_PAT }} steps: - - name: install node (required by JS-based actions) - run: apt-get update && apt-get install -y --no-install-recommends nodejs ca-certificates git + - name: Install Node.js for actions runtime + run: apt-get update && apt-get install -y nodejs - - uses: actions/checkout@v4 + - name: Checkout code + uses: actions/checkout@v4 - - name: configure git auth for private module fetch + - name: Configure git auth for private modules run: | git config --global url."https://oauth2:${REGISTRY_PAT}@forgejo.riotpiao.com".insteadOf "https://forgejo.riotpiao.com" + env: + REGISTRY_PAT: ${{ secrets.REGISTRY_PAT }} - name: gofmt run: | fmt_out="$(gofmt -l .)" if [ -n "$fmt_out" ]; then echo "$fmt_out" - echo "::error::gofmt found unformatted files, run 'gofmt -w .'" + echo "::error::gofmt found unformatted files" exit 1 fi @@ -49,3 +47,48 @@ jobs: - name: coverage summary run: go tool cover -func=coverage.out | tail -1 + + build-push: + name: Build & Push Image + needs: test + if: github.event_name == 'push' && github.ref == 'refs/heads/main' + runs-on: golang + steps: + - name: Install Node.js and Docker + run: | + apt-get update + apt-get install -y nodejs docker.io + + - name: Checkout code + uses: actions/checkout@v4 + + - name: Get short SHA + id: sha + run: | + SHORT_SHA=$(git rev-parse --short HEAD) + echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT + + - name: Registry login + run: | + echo "${REGISTRY_TOKEN}" | docker login "${REGISTRY}" \ + --username "${REGISTRY_USER}" --password-stdin + env: + REGISTRY_USER: ${{ secrets.FORGEJO_REGISTRY_USER }} + REGISTRY_TOKEN: ${{ secrets.FORGEJO_REGISTRY_TOKEN }} + + - name: Build Docker image + run: | + docker build --no-cache \ + -t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \ + -t "${IMAGE}:latest" \ + --build-arg "VERSION=${{ steps.sha.outputs.short_sha }}" \ + . + + - name: Push Docker image + run: | + docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}" + docker push "${IMAGE}:latest" + echo "✓ Image pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}" + + - name: Prune unused images + run: docker image prune -a --force 2>&1 | tail -3 || true