.hearthforge-ci.toml
⎇
Raw
1# HearthForge CI for filebrowser-ng.
2# Steps run in file order, in one container, sharing /ci/build.
3# The steps call the `just` recipes that already live in the repo.
4
5image = "docker.io/rust:1.90-bookworm"
6work_dir = "/ci/build"
7clone_project_to = "/ci/build/project"
8
9# The rust image ships bash. /bin/sh is dash and has no `pipefail`.
10shell = ["/bin/bash", "-c"]
11shell_setup = "set -euo pipefail"
12
13timeout = 5400
14memory_limit = "6g"
15
16# Without these every run recompiles the whole dependency tree from scratch.
17cache = [
18 "/usr/local/cargo/registry",
19 "/ci/build/project/target",
20 "/root/.bun/install/cache",
21]
22
23[on]
24push = ["master"]
25tag = true
26
27[variables]
28
29 [variables.TRUNK_VERSION]
30 default = "0.21.14"
31 description = "Trunk release that builds the wasm frontend. Matches the Containerfile."
32
33 [variables.BUN_VERSION]
34 default = "1.4.0"
35 description = "Bun release that bundles web/cm6.js. Matches the Containerfile."
36
37# ── toolchain ────────────────────────────────────────────────────────────────
38# The rust image has cargo only. The build also needs the wasm target, just,
39# bun and trunk. binaryen supplies wasm-opt, so trunk does not download one.
40[setup]
41timeout = 900
42run_sh = """
43apt-get update -qq
44apt-get install -y --no-install-recommends binaryen unzip
45
46rustup target add wasm32-unknown-unknown
47
48curl -fsSL https://just.systems/install.sh | bash -s -- --to /usr/local/bin
49
50# BUN_INSTALL controls the prefix, so the binary lands in /usr/local/bin.
51curl -fsSL https://bun.sh/install | BUN_INSTALL=/usr/local bash -s "bun-v${BUN_VERSION}"
52
53# Pinned and checksum-checked, same as the Containerfile. This is the gnu
54# build, not the musl one, because the image is Debian.
55url="https://github.com/trunk-rs/trunk/releases/download/v${TRUNK_VERSION}/trunk-x86_64-unknown-linux-gnu.tar.gz"
56curl -fsSL -o /tmp/trunk.tar.gz "$url"
57curl -fsSL "$url.sha256" | awk '{print $1 " /tmp/trunk.tar.gz"}' | sha256sum -c -
58tar xzf /tmp/trunk.tar.gz -C /usr/local/bin
59rm -f /tmp/trunk.tar.gz
60
61just --version && bun --version && trunk --version
62"""
63
64# ── checks ───────────────────────────────────────────────────────────────────
65# `just lint` is cargo fmt --check plus clippy with warnings denied.
66[lint]
67run_sh = "cd project && just lint"
68
69# `just test` covers server and api-types. The web crate has its own tests.
70[test]
71run_sh = "cd project && just test && cargo test -p web"
72
73# ── build ────────────────────────────────────────────────────────────────────
74# `just build` bundles CodeMirror, builds the frontend, stages it into
75# server/dist and links the single binary with the `embedded` feature.
76[build]
77timeout = 2400
78run_sh = "cd project && just build"
79publish_file = ["/ci/build/project/target/release/filebrowser-ng"]
80
81# `just e2e` would rebuild the frontend. The build step already staged
82# server/dist, so run the embedded suite against it directly.
83[e2e]
84run_sh = "cd project && cargo test -p server --features embedded"
85
86# ── release ──────────────────────────────────────────────────────────────────
87# Tags only. Ships the binary under a versioned name.
88[release]
89run_if = 'test -n "${CI_COMMIT_TAG}"'
90run_sh = """
91cd project
92install -Dm755 target/release/filebrowser-ng \
93 "dist/filebrowser-ng-${CI_COMMIT_TAG}-x86_64-linux-gnu"
94"""
95publish_gzip = ["/ci/build/project/dist/"]
96