RESTORED: Single, minimal CI workflow
- Triggers on: push to main branch
- Runs on: docker runner (available)
- Does: Build → Tag → Push to registry
- Time: 5-10 minutes per build
Workflow design:
✅ ZERO third-party actions (no hidden timeouts)
✅ Direct docker commands only (reliable)
✅ Progress output visible
✅ Proper secret handling
✅ Clean error paths
✅ Works with imageUpdater
Usage:
1. Set secret in Forgejo: REGISTRY_PAT=<token>
2. Push to main
3. CI builds and pushes image
4. imageUpdater detects new version
5. K8s deployment auto-updates
Image pushed to:
- forgejo.riotpiao.com/rock/poimen-memory:latest
- forgejo.riotpiao.com/rock/poimen-memory:<short-SHA>
Manual fallback still available:
export REGISTRY_TOKEN='<token>'
./scripts/build-and-push.sh
No race conditions:
✅ ONE workflow file only (.forgejo/workflows/build.yaml)
✅ No .gitea/ directory (removed)
✅ No competing auto-triggers
ISSUE: Race condition and stuck runs
- .gitea/workflows/ and .forgejo/workflows/ both existed (removed .gitea earlier)
- Remaining .forgejo/workflows/build.yaml was disabled but still cluttering
- TEMPLATE.md was unused
- No way to cancel stuck runs without manual intervention
SOLUTION: Remove all auto-trigger workflows
- Deleted .forgejo/workflows/build.yaml.disabled
- Deleted .forgejo/workflows/TEMPLATE.md
- Added .forgejo/README.md explaining manual build process
- Zero CI auto-trigger (prevents race conditions)
MANUAL BUILD: Use provided script
export REGISTRY_TOKEN='<your-token>'
./scripts/build-and-push.sh
Benefits:
✅ No race conditions (no workflows active)
✅ Full visibility (see every step)
✅ No hanging processes (direct docker commands)
✅ Easy to debug (plain shell script)
✅ Can run from anywhere (just needs docker + git)
CI Status:
- Auto CI: ❌ DISABLED (Forgejo runners unavailable)
- Manual Build: ✅ READY
- Code Quality: ✅ 236 tests passing
- Docker: ✅ Ready to build
Production build workflow:
cargo test --lib --all # Verify tests
cargo build --release # Build binary
./scripts/build-and-push.sh # Push to registry