ci: remove .forgejo/ (Gitea 1.27 uses .gitea/ instead)
Build and Push Memory Service / Build and Push Image (push) Failing after 11s
Build and Push Memory Service / Build and Push Image (push) Failing after 11s
Gitea 1.27.0-rootless looks for workflows in .gitea/workflows/, not .forgejo/. Removed unused .forgejo/ directory entirely. Workflow is now at: .gitea/workflows/build.yaml
This commit is contained in:
@@ -1,135 +0,0 @@
|
|||||||
# Forgejo CI/CD - Build & Push Workflow
|
|
||||||
|
|
||||||
**Status**: ✅ ACTIVE (Production-ready)
|
|
||||||
|
|
||||||
## CI Workflow
|
|
||||||
|
|
||||||
The `.forgejo/workflows/build.yaml` automatically:
|
|
||||||
|
|
||||||
1. Triggers on **push to main** branch
|
|
||||||
2. Builds Docker image (multi-stage Rust)
|
|
||||||
3. Tags: `latest` + `short-SHA`
|
|
||||||
4. Pushes to registry
|
|
||||||
5. Cleans up (logout)
|
|
||||||
|
|
||||||
## Required Secrets
|
|
||||||
|
|
||||||
Set in Forgejo repository settings → Secrets:
|
|
||||||
|
|
||||||
- `REGISTRY_PAT`: Personal access token (Docker login credentials)
|
|
||||||
- Must have push access to `forgejo.riotpiao.com/rock/poimen-memory`
|
|
||||||
- Use service account or personal token with registry scope
|
|
||||||
|
|
||||||
## What imageUpdater Needs
|
|
||||||
|
|
||||||
The CI pushes images to:
|
|
||||||
```
|
|
||||||
forgejo.riotpiao.com/rock/poimen-memory:latest
|
|
||||||
forgejo.riotpiao.com/rock/poimen-memory:<short-SHA>
|
|
||||||
```
|
|
||||||
|
|
||||||
imageUpdater can:
|
|
||||||
- Watch for `:latest` tag
|
|
||||||
- Poll registry for new versions
|
|
||||||
- Trigger K8s deployment updates
|
|
||||||
|
|
||||||
## Manual Override
|
|
||||||
|
|
||||||
If CI fails, build manually:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
export REGISTRY_TOKEN='<your-token>'
|
|
||||||
./scripts/build-and-push.sh
|
|
||||||
```
|
|
||||||
|
|
||||||
## Workflow Design
|
|
||||||
|
|
||||||
**Minimal & Reliable**:
|
|
||||||
- ✅ No third-party actions (no hidden timeouts)
|
|
||||||
- ✅ Direct docker commands only
|
|
||||||
- ✅ Progress output visible
|
|
||||||
- ✅ Proper error handling
|
|
||||||
- ✅ Clean secrets handling
|
|
||||||
- ✅ 5-10 minute runtime
|
|
||||||
|
|
||||||
**Single Workflow**:
|
|
||||||
- ✅ ONE `build.yaml` (no race conditions)
|
|
||||||
- ✅ No competing workflows
|
|
||||||
- ✅ Deterministic behavior
|
|
||||||
- ✅ Easy to debug
|
|
||||||
|
|
||||||
**Runner Selection**:
|
|
||||||
|
|
||||||
Workflow uses: `runs-on: rust`
|
|
||||||
|
|
||||||
Available runners in Forgejo:
|
|
||||||
- `golang` - golang:1.26-bookworm + dind (for Go projects)
|
|
||||||
- `rust` - rust:1.83-bookworm + dind (✅ for Rust projects)
|
|
||||||
- `node` - node:22-bookworm (for Node.js projects)
|
|
||||||
|
|
||||||
Why `rust` for poimen-memory:
|
|
||||||
- ✅ Pre-installed Rust toolchain
|
|
||||||
- ✅ Docker-in-Docker (dind) for image builds
|
|
||||||
- ✅ 2 CPU, 4GB RAM limits (sufficient)
|
|
||||||
- ✅ 1.83-bookworm base (production-ready)
|
|
||||||
|
|
||||||
## CI Status
|
|
||||||
|
|
||||||
Check latest build: Forgejo repository → Actions tab
|
|
||||||
|
|
||||||
Expected flow:
|
|
||||||
1. Push to main
|
|
||||||
2. Forgejo CI triggers (30s delay)
|
|
||||||
3. Build starts (~3-5 min)
|
|
||||||
4. Image pushed to registry
|
|
||||||
5. imageUpdater detects new version
|
|
||||||
6. K8s deployment updated (via ArgoCD or controller)
|
|
||||||
|
|
||||||
## Deployment Trigger
|
|
||||||
|
|
||||||
Once image is pushed, imageUpdater can:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
# ArgoCD Image Updater strategy
|
|
||||||
apiVersion: argoproj.io/v1alpha1
|
|
||||||
kind: ApplicationSet
|
|
||||||
metadata:
|
|
||||||
name: memory-auto-update
|
|
||||||
spec:
|
|
||||||
generators:
|
|
||||||
- image:
|
|
||||||
registrySelector:
|
|
||||||
registry: forgejo.riotpiao.com/rock/poimen-memory
|
|
||||||
tagSelector:
|
|
||||||
pattern: "^latest$|^[0-9a-f]{7}$"
|
|
||||||
template:
|
|
||||||
spec:
|
|
||||||
source:
|
|
||||||
image: forgejo.riotpiao.com/rock/poimen-memory:latest
|
|
||||||
```
|
|
||||||
|
|
||||||
Or use external webhook to trigger K8s deployment rollout.
|
|
||||||
|
|
||||||
## Troubleshooting
|
|
||||||
|
|
||||||
**CI Hanging?**
|
|
||||||
- Check Forgejo runner logs
|
|
||||||
- Verify `REGISTRY_PAT` secret is set
|
|
||||||
- Verify docker socket is accessible in runner
|
|
||||||
|
|
||||||
**Login Failed?**
|
|
||||||
- Verify `REGISTRY_HOST` secret
|
|
||||||
- Check credentials in Vault
|
|
||||||
|
|
||||||
**Build Failed?**
|
|
||||||
- Check: `cargo test --lib --all` locally
|
|
||||||
- Check: `docker build .` works locally
|
|
||||||
- Review build output in Forgejo Actions tab
|
|
||||||
|
|
||||||
## Files
|
|
||||||
|
|
||||||
- `.forgejo/workflows/build.yaml` ← **Production workflow**
|
|
||||||
- `.forgejo/README.md` ← This file
|
|
||||||
- `./Dockerfile` ← Multi-stage Rust build
|
|
||||||
- `./scripts/build-and-push.sh` ← Manual fallback
|
|
||||||
# CI Test Trigger
|
|
||||||
@@ -1,52 +0,0 @@
|
|||||||
name: Build and Push Memory Service
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build-and-push:
|
|
||||||
name: Build and Push Image
|
|
||||||
# Use 'rust' runner (not 'docker')
|
|
||||||
# Available runners in Forgejo: golang, rust, node
|
|
||||||
# rust runner provides: Rust 1.83-bookworm + Docker-in-Docker for image builds
|
|
||||||
runs-on: rust
|
|
||||||
steps:
|
|
||||||
- name: Checkout code
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Get commit info
|
|
||||||
id: info
|
|
||||||
run: |
|
|
||||||
SHORT_SHA=$(git rev-parse --short HEAD)
|
|
||||||
COMMIT_MSG=$(git log -1 --pretty=%B | head -1)
|
|
||||||
echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT
|
|
||||||
echo "commit_msg=${COMMIT_MSG}" >> $GITHUB_OUTPUT
|
|
||||||
echo "Building: ${SHORT_SHA} - ${COMMIT_MSG}"
|
|
||||||
|
|
||||||
- name: Docker login
|
|
||||||
run: |
|
|
||||||
echo "${{ secrets.REGISTRY_PAT }}" | \
|
|
||||||
docker login -u rock --password-stdin forgejo.riotpiao.com
|
|
||||||
|
|
||||||
- name: Build image
|
|
||||||
run: |
|
|
||||||
docker build \
|
|
||||||
--tag forgejo.riotpiao.com/rock/poimen-memory:${{ steps.info.outputs.short_sha }} \
|
|
||||||
--tag forgejo.riotpiao.com/rock/poimen-memory:latest \
|
|
||||||
.
|
|
||||||
echo "✅ Image built successfully"
|
|
||||||
|
|
||||||
- name: Push image
|
|
||||||
run: |
|
|
||||||
docker push forgejo.riotpiao.com/rock/poimen-memory:${{ steps.info.outputs.short_sha }}
|
|
||||||
docker push forgejo.riotpiao.com/rock/poimen-memory:latest
|
|
||||||
echo "✅ Image pushed successfully"
|
|
||||||
echo "Image: forgejo.riotpiao.com/rock/poimen-memory:latest"
|
|
||||||
|
|
||||||
- name: Cleanup
|
|
||||||
if: always()
|
|
||||||
run: |
|
|
||||||
docker logout forgejo.riotpiao.com || true
|
|
||||||
echo "✅ Cleanup complete"
|
|
||||||
Reference in New Issue
Block a user