hearthforge-ci-template.toml
| 1 | # HearthForge CI Pipeline Template |
| 2 | # Place this file at .hearthforge-ci.toml in your repository root. |
| 3 | |
| 4 | image = "docker.io/debian:stable" |
| 5 | # Tools the image must provide: a POSIX shell at /bin/sh (or `shell` below), |
| 6 | # `sleep` for the container's main process, and `rm` + `mkdir` when a step |
| 7 | # uses `clear`. Any image with busybox or coreutils has them. Hearthforge does |
| 8 | # the checkout, [[copy]], and publish_* archives itself, so no git, tar, gzip, |
| 9 | # zstd or zip is needed inside the image. |
| 10 | work_dir = "/ci/build" |
| 11 | # Must be absolute. The image needs no git. HearthForge exports the commit |
| 12 | # and uploads it. No .git reaches the container, so `git describe` needs a |
| 13 | # step that fetches history itself. |
| 14 | clone_project_to = "/ci/build/project" |
| 15 | # shell = ["/bin/sh", "-c"] |
| 16 | shell_setup = "set -euo pipefail" |
| 17 | # timeout = 3600 # default per-step timeout in seconds |
| 18 | # cpu_limit = 2.0 # CPU cores limit |
| 19 | # memory_limit = "2g" # memory limit (k/m/g suffix) |
| 20 | # Caches persist between runs. An entry is a bare path, or a table with a |
| 21 | # max_size cap (k/m/g suffix). A capped cache is deleted after the run that |
| 22 | # takes it over, so the next run starts cold. Uncapped caches grow forever. |
| 23 | # cache = [ |
| 24 | # { path = "/root/.cargo", max_size = "8g" }, |
| 25 | # "/root/.npm", |
| 26 | # ] |
| 27 | # A cache path must not overlap clone_project_to, in either direction. The |
| 28 | # checkout is extracted over that directory. A `clear` step deletes it. |
| 29 | |
| 30 | [on] |
| 31 | push = ["main"] # trigger on push to these branches; use ["*"] for all |
| 32 | tag = false # trigger on tag push |
| 33 | # manual runs are always available from the UI |
| 34 | |
| 35 | [variables] |
| 36 | # [variables.MY_VAR] |
| 37 | # default = "hello" |
| 38 | # description = "A custom variable, overridable from the UI" |
| 39 | |
| 40 | # Files taken from another image before any step runs, like COPY --from. |
| 41 | # `to` is a directory and the source basename is kept, so the example below |
| 42 | # lands at /usr/local/bin/bun. HearthForge creates `to` when it is missing. |
| 43 | # Match the libc: an -alpine tag is musl and will not run on this glibc image. |
| 44 | # A "/." suffix on `from` copies the contents instead of the directory itself. |
| 45 | # |
| 46 | # [[copy]] |
| 47 | # image = "docker.io/oven/bun:1.4.0" |
| 48 | # from = "/usr/local/bin/bun" |
| 49 | # to = "/usr/local/bin" |
| 50 | |
| 51 | # Steps run in file order. Names are labels only, repeats are allowed. |
| 52 | |
| 53 | [[steps]] |
| 54 | name = "setup" |
| 55 | run_sh = "apt-get update -qq && apt-get install -y --no-install-recommends build-essential" |
| 56 | timeout = 180 |
| 57 | |
| 58 | [[steps]] |
| 59 | name = "lint" |
| 60 | run_sh = "make -C project lint" |
| 61 | # warn_on_fail marks the step "warning" instead of failing the run, and the |
| 62 | # steps after it still run. |
| 63 | # warn_on_fail = true |
| 64 | |
| 65 | [[steps]] |
| 66 | name = "build" |
| 67 | run_sh = "make -C project all" |
| 68 | |
| 69 | [[steps]] |
| 70 | name = "test" |
| 71 | # run_if is a shell expression; the step is skipped if it returns non-zero |
| 72 | # run_if = 'test -n "${CI_COMMIT_TAG}"' |
| 73 | run_sh = "make -C project test" |
| 74 | |
| 75 | [[steps]] |
| 76 | name = "package" |
| 77 | run_sh = "make -C project dist" |
| 78 | # Publish artifacts — these can appear in any step |
| 79 | # publish_file: copy a single file directly |
| 80 | # publish_file = ["/ci/build/project/dist/my-binary"] |
| 81 | # Archives are built by Hearthforge on the host; the image needs no tools. |
| 82 | # publish_gzip: create a .tar.gz archive |
| 83 | # publish_gzip = ["/ci/build/project/dist/"] |
| 84 | # publish_tar: create a plain .tar archive |
| 85 | # publish_tar = ["/ci/build/project/dist/"] |
| 86 | # publish_zip: create a .zip archive (symlinks are dropped) |
| 87 | # publish_zip = ["/ci/build/project/dist/"] |
| 88 | # publish_zstd: create a .tar.zst archive |
| 89 | # publish_zstd = ["/ci/build/project/dist/"] |
| 90 | |
| 91 | [[steps]] |
| 92 | name = "cleanup" |
| 93 | # always runs the step even when an earlier one failed. |
| 94 | always = true |
| 95 | run_sh = "rm -rf /ci/build/scratch" |
| 96 | |
| 97 | # [[steps]] |
| 98 | # name = "image" |
| 99 | # # build_image builds a Containerfile in a VM after run_sh and pushes the |
| 100 | # # image to this repository's registry, at <host>/<repo>[/<image>]:<tag>. |
| 101 | # # Any valid Containerfile works. The engine host needs /dev/kvm. |
| 102 | # [steps.build_image] |
| 103 | # context = "/ci/build/project" # directory in this container, default clone_project_to |
| 104 | # file = "Containerfile" # relative to context, default Containerfile or Dockerfile |
| 105 | # target = "runtime" # stage of a multi-stage build |
| 106 | # image = "web" # path below the repository's image name |
| 107 | # tags = ["$CI_COMMIT_SHORT_SHA", "$CI_COMMIT_TAG"] # $VARS expanded, empty results dropped |
| 108 | # secrets = ["NPM_TOKEN"] # CI secrets for RUN --mount=type=secret,id=NPM_TOKEN |
| 109 | # args = { VERSION = "$CI_COMMIT_REF_NAME" } # build args, $VARS expanded |
| 110 |