migrate CI

AuthorKonata <konata@posteo.jp>
Date
Commit369e53c10e36c6e77b3e4a34c71294acec4c6f41
Parent54b015c
1 file changed, 21 insertions(+), 32 deletions(-)
▾M.hearthforge-ci.toml
@@ -40,7 +40,7 @@ name = "setup"
timeout = 900
run_sh = """
apt-get update -qq && apt-get install -y -qq --no-install-recommends \
podman-remote openjdk-21-jdk-headless > /dev/null
openjdk-21-jdk-headless > /dev/null
rustup component add rustfmt clippy
rustup target add wasm32-unknown-unknown
@@ -106,42 +106,31 @@ warn_on_fail = true
run_sh = "cd project/android && ./gradlew --no-daemon lintDebug"
# Packages what the build step made via the Containerfile's prebuilt stage.
# Needs CI_ENGINE_SOCKET=1 on the server and the CI secret REGISTRY_PASSWORD
# (admin password). Every run pushes the short sha and "edge". A tag run also
# pushes the tag and "latest".
# build_image builds it in a VM on the server and pushes it to this repo's
# registry. A branch run pushes the short sha and "edge". A tag run pushes
# the short sha, the tag and "latest". Tags cannot depend on the trigger, so
# run_if picks one of two image steps.
[[steps]]
name = "image"
engine_socket = true
timeout = 900
name = "image-files"
run_sh = """
cd project
mkdir -p ci-bin
cp "${CARGO_TARGET_DIR}/release/otserver" ci-bin/otserver
cp -r web/dist ci-bin/web
"""
echo "$REGISTRY_PASSWORD" | podman-remote login "${CI_REGISTRY%%/*}" -u admin --password-stdin
# A remote build sends a seccomp profile path that the server opens. The
# client's default path may not exist on the server, so ask the server.
prof=$(podman-remote info --format '{{.Host.Security.SECCOMPProfilePath}}' 2>/dev/null || true)
if [ -n "$prof" ]; then
seccomp="seccomp=$prof"
else
seccomp="seccomp=unconfined"
fi
img="$CI_REGISTRY:$CI_COMMIT_SHORT_SHA"
podman-remote build --security-opt "$seccomp" \
-f Containerfile -t "$img" --build-arg BIN_STAGE=prebuilt .
podman-remote push "$img"
[[steps]]
name = "image"
run_if = 'test -z "${CI_COMMIT_TAG}"'
timeout = 900
[steps.build_image]
args = { BIN_STAGE = "prebuilt" }
tags = ["$CI_COMMIT_SHORT_SHA", "edge"]
if [ -n "${CI_COMMIT_TAG:-}" ]; then
tags="$CI_COMMIT_TAG latest"
else
tags="edge"
fi
for t in $tags; do
podman-remote tag "$img" "$CI_REGISTRY:$t"
podman-remote push "$CI_REGISTRY:$t"
done
"""
[[steps]]
name = "image-release"
run_if = 'test -n "${CI_COMMIT_TAG}"'
timeout = 900
[steps.build_image]
args = { BIN_STAGE = "prebuilt" }
tags = ["$CI_COMMIT_SHORT_SHA", "$CI_COMMIT_TAG", "latest"]