# Path is .gitea/workflows/, not .forgejo/workflows/ -- verified live on this # Forgejo instance (forgejo.riotpiao.com) that a .forgejo/workflows/*.yaml # file never creates an action_run row on push, for any repo. This CI has # never once executed until this move. name: ci on: push: branches: [main] pull_request: jobs: buf: runs-on: golang container: image: bufbuild/buf:latest steps: # actions/checkout@v4 is a JS action -- it needs `node` inside the # job's container, and bufbuild/buf ships none. Plain git clone avoids # that dependency. # # GITHUB_SERVER_URL on this instance is the internal Service address, # e.g. http://forgejo-gitea-http.cicd.svc.cluster.local:3000 -- plain # HTTP, not HTTPS. The previous version of this step did # `${GITHUB_SERVER_URL#https://}` (strip an "https://" prefix) and then # unconditionally re-prepended "https://", producing the malformed URL # "https://http://forgejo-gitea-http...". That is what the "trust # homelab CA" step (and the HOMELAB_CA_CERT secret it needed, which # never existed on this repo) was trying to paper over. Inserting the # token right after whatever scheme is actually present, instead of # assuming https, needs no CA at all -- there's no TLS in the internal # path to trust in the first place. - name: checkout env: GIT_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | url=$(echo "${GITHUB_SERVER_URL}" | sed -E "s#(https?://)#\1x-access-token:${GIT_TOKEN}@#") git clone "${url}/${GITHUB_REPOSITORY}.git" . git checkout "${GITHUB_SHA}" - name: buf lint run: buf lint - name: buf breaking (against main) run: buf breaking --against '.git#branch=main' if: github.ref != 'refs/heads/main' codegen-check: runs-on: golang container: image: golang:1.26 steps: # Same reason as the buf job: golang:1.25 has no Node.js either. - name: checkout env: GIT_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | url=$(echo "${GITHUB_SERVER_URL}" | sed -E "s#(https?://)#\1x-access-token:${GIT_TOKEN}@#") git clone "${url}/${GITHUB_REPOSITORY}.git" . git checkout "${GITHUB_SHA}" - name: Install buf and protoc plugins run: | go install github.com/bufbuild/buf/cmd/buf@latest go install google.golang.org/protobuf/cmd/protoc-gen-go@latest go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@latest go install github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-grpc-gateway@latest - name: Regenerate and diff run: | export PATH="$PATH:$(go env GOPATH)/bin" buf generate git diff --exit-code -- gen || (echo "::error::gen/ is out of date — run buf generate and commit the result" && exit 1) - name: go build run: go build ./...