Files
kmsvc-proto/.gitea/workflows/ci.yaml
T
rock 6cde453e04
ci / buf (push) Canceled after 0s
ci / codegen-check (push) Canceled after 0s
fix: use golang runner label instead of deprecated docker label
2026-08-28 15:36:26 -07:00

77 lines
2.9 KiB
YAML

# Path is .gitea/workflows/, not .forgejo/workflows/ -- verified live on this
# Forgejo instance (forgejo.riotpiao.com) that a .forgejo/workflows/*.yaml
# file never creates an action_run row on push, for any repo. This CI has
# never once executed until this move.
name: ci
on:
push:
branches: [main]
pull_request:
jobs:
buf:
runs-on: golang
container:
image: bufbuild/buf:latest
steps:
# actions/checkout@v4 is a JS action -- it needs `node` inside the
# job's container, and bufbuild/buf ships none. Plain git clone avoids
# that dependency.
#
# GITHUB_SERVER_URL on this instance is the internal Service address,
# e.g. http://forgejo-gitea-http.cicd.svc.cluster.local:3000 -- plain
# HTTP, not HTTPS. The previous version of this step did
# `${GITHUB_SERVER_URL#https://}` (strip an "https://" prefix) and then
# unconditionally re-prepended "https://", producing the malformed URL
# "https://http://forgejo-gitea-http...". That is what the "trust
# homelab CA" step (and the HOMELAB_CA_CERT secret it needed, which
# never existed on this repo) was trying to paper over. Inserting the
# token right after whatever scheme is actually present, instead of
# assuming https, needs no CA at all -- there's no TLS in the internal
# path to trust in the first place.
- name: checkout
env:
GIT_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
url=$(echo "${GITHUB_SERVER_URL}" | sed -E "s#(https?://)#\1x-access-token:${GIT_TOKEN}@#")
git clone "${url}/${GITHUB_REPOSITORY}.git" .
git checkout "${GITHUB_SHA}"
- name: buf lint
run: buf lint
- name: buf breaking (against main)
run: buf breaking --against '.git#branch=main'
if: github.ref != 'refs/heads/main'
codegen-check:
runs-on: golang
container:
image: golang:1.25
steps:
# Same reason as the buf job: golang:1.25 has no Node.js either.
- name: checkout
env:
GIT_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
url=$(echo "${GITHUB_SERVER_URL}" | sed -E "s#(https?://)#\1x-access-token:${GIT_TOKEN}@#")
git clone "${url}/${GITHUB_REPOSITORY}.git" .
git checkout "${GITHUB_SHA}"
- name: Install buf and protoc plugins
run: |
go install github.com/bufbuild/buf/cmd/buf@latest
go install google.golang.org/protobuf/cmd/protoc-gen-go@latest
go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@latest
go install github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-grpc-gateway@latest
- name: Regenerate and diff
run: |
export PATH="$PATH:$(go env GOPATH)/bin"
buf generate
git diff --exit-code -- gen || (echo "::error::gen/ is out of date — run buf generate and commit the result" && exit 1)
- name: go build
run: go build ./...