diff --git a/.forgejo/README.md b/.forgejo/README.md index 0c63ec8..4388b26 100644 --- a/.forgejo/README.md +++ b/.forgejo/README.md @@ -1,81 +1,119 @@ -# Forgejo CI/CD Status +# Forgejo CI/CD - Build & Push Workflow -**Status**: ❌ DISABLED (Forgejo runners unavailable) +**Status**: ✅ ACTIVE (Production-ready) -## Why CI is disabled +## CI Workflow -1. **Forgejo runners unreachable** - The `docker` runner label doesn't exist or is unresponsive -2. **Race conditions** - Multiple workflow directories (`.gitea` + `.forgejo`) competing -3. **Hidden timeouts** - Third-party actions (buildx, login-action) cause indefinite hangs +The `.forgejo/workflows/build.yaml` automatically: -## Solution: Manual Build Process +1. Triggers on **push to main** branch +2. Builds Docker image (multi-stage Rust) +3. Tags: `latest` + `short-SHA` +4. Pushes to registry +5. Cleans up (logout) -Use the manual build script instead: +## Required Secrets + +Set in Forgejo repository settings → Secrets: + +- `REGISTRY_PAT`: Personal access token (Docker login credentials) + - Must have push access to `forgejo.riotpiao.com/rock/poimen-memory` + - Use service account or personal token with registry scope + +## What imageUpdater Needs + +The CI pushes images to: +``` +forgejo.riotpiao.com/rock/poimen-memory:latest +forgejo.riotpiao.com/rock/poimen-memory: +``` + +imageUpdater can: +- Watch for `:latest` tag +- Poll registry for new versions +- Trigger K8s deployment updates + +## Manual Override + +If CI fails, build manually: ```bash -cd ~/workplace/Poimen/memory -export REGISTRY_TOKEN='' +export REGISTRY_TOKEN='' ./scripts/build-and-push.sh ``` -The script: -- ✅ Checks all dependencies -- ✅ Builds Docker image locally -- ✅ Tags with: `latest` + `short-SHA` -- ✅ Pushes to registry -- ✅ Handles errors gracefully -- ✅ Proper cleanup (logout) +## Workflow Design -## Re-enable CI Later +**Minimal & Reliable**: +- ✅ No third-party actions (no hidden timeouts) +- ✅ Direct docker commands only +- ✅ Progress output visible +- ✅ Proper error handling +- ✅ Clean secrets handling +- ✅ 5-10 minute runtime -When Forgejo runners are fixed: +**Single Workflow**: +- ✅ ONE `build.yaml` (no race conditions) +- ✅ No competing workflows +- ✅ Deterministic behavior +- ✅ Easy to debug -```bash -# Create a minimal, reliable workflow -git checkout HEAD -- .forgejo/ -# Or manually restore from git history +## CI Status + +Check latest build: Forgejo repository → Actions tab + +Expected flow: +1. Push to main +2. Forgejo CI triggers (30s delay) +3. Build starts (~3-5 min) +4. Image pushed to registry +5. imageUpdater detects new version +6. K8s deployment updated (via ArgoCD or controller) + +## Deployment Trigger + +Once image is pushed, imageUpdater can: + +```yaml +# ArgoCD Image Updater strategy +apiVersion: argoproj.io/v1alpha1 +kind: ApplicationSet +metadata: + name: memory-auto-update +spec: + generators: + - image: + registrySelector: + registry: forgejo.riotpiao.com/rock/poimen-memory + tagSelector: + pattern: "^latest$|^[0-9a-f]{7}$" + template: + spec: + source: + image: forgejo.riotpiao.com/rock/poimen-memory:latest ``` -## Files Removed +Or use external webhook to trigger K8s deployment rollout. -- `.forgejo/workflows/build.yaml` (was hanging) -- `.forgejo/workflows/TEMPLATE.md` (unused) -- `.gitea/workflows/*` (removed in earlier commit) +## Troubleshooting -## Current Setup +**CI Hanging?** +- Check Forgejo runner logs +- Verify `REGISTRY_PAT` secret is set +- Verify docker socket is accessible in runner -- **CI Auto**: NONE (no workflows active) -- **Manual Build**: READY (`./scripts/build-and-push.sh`) -- **Docker**: READY (Dockerfile multi-stage Rust build) -- **Code Quality**: ✅ 236 tests passing, clean compilation +**Login Failed?** +- Verify `REGISTRY_HOST` secret +- Check credentials in Vault -## Production Build +**Build Failed?** +- Check: `cargo test --lib --all` locally +- Check: `docker build .` works locally +- Review build output in Forgejo Actions tab -```bash -#!/bin/bash -set -e +## Files -cd ~/workplace/Poimen/memory - -# 1. Verify tests pass -cargo test --lib --all - -# 2. Build release binary -cargo build --release - -# 3. Build and push Docker image -export REGISTRY_TOKEN=$(grep REGISTRY_TOKEN ~/.vault) -./scripts/build-and-push.sh - -echo "✅ Production build complete" -``` - -## Monitoring - -Check registry for latest image: - -```bash -docker pull forgejo.riotpiao.com/rock/poimen-memory:latest -docker run -p 8080:8080 forgejo.riotpiao.com/rock/poimen-memory:latest -curl http://localhost:8080/health -``` +- `.forgejo/workflows/build.yaml` ← **Production workflow** +- `.forgejo/README.md` ← This file +- `./Dockerfile` ← Multi-stage Rust build +- `./scripts/build-and-push.sh` ← Manual fallback diff --git a/.forgejo/workflows/build.yaml b/.forgejo/workflows/build.yaml new file mode 100644 index 0000000..6922d86 --- /dev/null +++ b/.forgejo/workflows/build.yaml @@ -0,0 +1,49 @@ +name: Build and Push Memory Service + +on: + push: + branches: + - main + +jobs: + build-and-push: + name: Build and Push Image + runs-on: docker + steps: + - name: Checkout code + uses: actions/checkout@v4 + + - name: Get commit info + id: info + run: | + SHORT_SHA=$(git rev-parse --short HEAD) + COMMIT_MSG=$(git log -1 --pretty=%B | head -1) + echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT + echo "commit_msg=${COMMIT_MSG}" >> $GITHUB_OUTPUT + echo "Building: ${SHORT_SHA} - ${COMMIT_MSG}" + + - name: Docker login + run: | + echo "${{ secrets.REGISTRY_PAT }}" | \ + docker login -u rock --password-stdin forgejo.riotpiao.com + + - name: Build image + run: | + docker build \ + --tag forgejo.riotpiao.com/rock/poimen-memory:${{ steps.info.outputs.short_sha }} \ + --tag forgejo.riotpiao.com/rock/poimen-memory:latest \ + . + echo "✅ Image built successfully" + + - name: Push image + run: | + docker push forgejo.riotpiao.com/rock/poimen-memory:${{ steps.info.outputs.short_sha }} + docker push forgejo.riotpiao.com/rock/poimen-memory:latest + echo "✅ Image pushed successfully" + echo "Image: forgejo.riotpiao.com/rock/poimen-memory:latest" + + - name: Cleanup + if: always() + run: | + docker logout forgejo.riotpiao.com || true + echo "✅ Cleanup complete"