migrate CI

AuthorKonata <konata@posteo.jp>
Date
Commitab23a1fc1366965f1c2f9270646ecc7488714bf2
Parent0e4302e
1 file changed, 22 insertions(+), 38 deletions(-)
▾M.hearthforge-ci.toml
@@ -57,7 +57,7 @@ run_sh = """
# openssl-dev + openssl-libs-static: webauthn-rs links OpenSSL, and this is
# a static musl build. make builds jemalloc. Mirrors the Containerfile's
# build stage.
apk add --no-cache musl-dev binaryen just curl libstdc++ podman-remote make \
apk add --no-cache musl-dev binaryen just curl libstdc++ make \
openssl-dev openssl-libs-static pkgconfig
# The official rust images use rustup's minimal profile, so rustfmt and
@@ -114,46 +114,30 @@ publish_gzip = ["/ci/build/project/dist/"]
# ── image ────────────────────────────────────────────────────────────────────
# Packages the binary the build step made, so the image ships exactly what
# e2e tested. The Containerfile's build stage is skipped via BIN_STAGE.
# engine_socket hands this step the host engine, which is Podman on this
# server (needs CI_ENGINE_SOCKET=1). REGISTRY_PASSWORD is a CI secret with the
# admin password. CI_REGISTRY is "<host>/<repo>" on the built-in registry.
# Tags: every run pushes the short sha and "edge"; a tag run also pushes the
# tag and "latest".
# build_image builds it in a VM on the server and pushes it to this repo's
# registry. A branch run pushes the short sha and "edge". A tag run pushes
# the short sha, the tag and "latest". Tags cannot depend on the trigger, so
# run_if picks one of two image steps.
[[steps]]
name = "image"
engine_socket = true
timeout = 900
name = "image-files"
run_sh = """
cd project
mkdir -p ci-bin
cp "${CARGO_TARGET_DIR}/release/dovenest" ci-bin/dovenest
echo "$REGISTRY_PASSWORD" | podman-remote login "${CI_REGISTRY%%/*}" -u admin --password-stdin
# A remote build sends a seccomp profile path that the server opens. Alpine
# ships one at /etc/containers/seccomp.json and podman picks it over the
# /usr/share copy, but the server has only the latter. Ask the server for its
# own path. An empty answer means no profile can be named, so the build runs
# unconfined rather than failing.
prof=$(podman-remote info --format '{{.Host.Security.SECCOMPProfilePath}}' 2>/dev/null || true)
if [ -n "$prof" ]; then
seccomp="seccomp=$prof"
else
seccomp="seccomp=unconfined"
fi
img="$CI_REGISTRY:$CI_COMMIT_SHORT_SHA"
podman-remote build --security-opt "$seccomp" \
-f Containerfile -t "$img" --build-arg BIN_STAGE=prebuilt .
podman-remote push "$img"
if [ -n "${CI_COMMIT_TAG:-}" ]; then
tags="$CI_COMMIT_TAG latest"
else
tags="edge"
fi
for t in $tags; do
podman-remote tag "$img" "$CI_REGISTRY:$t"
podman-remote push "$CI_REGISTRY:$t"
done
"""
[[steps]]
name = "image"
run_if = 'test -z "${CI_COMMIT_TAG}"'
timeout = 900
[steps.build_image]
args = { BIN_STAGE = "prebuilt" }
tags = ["$CI_COMMIT_SHORT_SHA", "edge"]
[[steps]]
name = "image-release"
run_if = 'test -n "${CI_COMMIT_TAG}"'
timeout = 900
[steps.build_image]
args = { BIN_STAGE = "prebuilt" }
tags = ["$CI_COMMIT_SHORT_SHA", "$CI_COMMIT_TAG", "latest"]