mirror of
https://github.com/moons-14/dotfiles.git
synced 2026-10-05 23:18:11 +09:00
Update Nix binary cache / Build every host and publish new cache objects (push) Has been cancelled
58 lines
1.9 KiB
YAML
58 lines
1.9 KiB
YAML
name: Bootstrap Nix binary cache
|
|
on:
|
|
workflow_dispatch:
|
|
permissions:
|
|
contents: write
|
|
concurrency:
|
|
group: nix-release-cache-publisher
|
|
cancel-in-progress: false
|
|
jobs:
|
|
bootstrap:
|
|
name: Build every host and bootstrap the cache
|
|
runs-on: ubuntu-24.04
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
- name: Install Nix
|
|
uses: cachix/install-nix-action@v31
|
|
with:
|
|
extra_nix_config: |
|
|
experimental-features = nix-command flakes
|
|
accept-flake-config = true
|
|
- name: Prepare unsandboxed Nix builds
|
|
run: |
|
|
set -euo pipefail
|
|
if [[ -e /homeless-shelter ]]; then
|
|
if ((EUID == 0)); then
|
|
rm -rf --one-file-system -- /homeless-shelter
|
|
else
|
|
sudo -n rm -rf --one-file-system -- /homeless-shelter
|
|
fi
|
|
fi
|
|
- name: Build and publish the initial cache
|
|
env:
|
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
|
NIX_CACHE_PRIVATE_KEY: ${{ secrets.NIX_CACHE_PRIVATE_KEY }}
|
|
CACHE_MODE: bootstrap
|
|
CACHE_REPOSITORY: moons-14/dotfiles
|
|
CACHE_SERVER_URL: https://git.yutakobayashi.com
|
|
CACHE_API_SERVER_URL: ${{ vars.NIX_CACHE_API_SERVER_URL }}
|
|
CACHE_COMMIT: ${{ github.sha }}
|
|
CACHE_REF_NAME: ${{ github.ref_name }}
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
if [[ -z "${NIX_CACHE_PRIVATE_KEY:-}" ]]; then
|
|
echo "Repository secret NIX_CACHE_PRIVATE_KEY is required." >&2
|
|
exit 1
|
|
fi
|
|
|
|
key_file="${RUNNER_TEMP:-/tmp}/nix-cache-private-key"
|
|
umask 077
|
|
printf '%s\n' "$NIX_CACHE_PRIVATE_KEY" > "$key_file"
|
|
unset NIX_CACHE_PRIVATE_KEY
|
|
|
|
export NIX_CACHE_KEY_FILE="$key_file"
|
|
trap 'rm -f "$key_file"' EXIT
|
|
./.gitea/scripts/publish-nix-cache.sh
|