mirror of
https://github.com/moons-14/dotfiles.git
synced 2026-10-06 11:34:08 +09:00
delete
This commit is contained in:
@@ -1,150 +0,0 @@
|
||||
name: NixOS CI
|
||||
on:
|
||||
pull_request:
|
||||
branches:
|
||||
- main
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
permissions:
|
||||
contents: read
|
||||
concurrency:
|
||||
group: nixos-ci-${{ github.event.pull_request.number || github.run_id }}
|
||||
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
||||
jobs:
|
||||
validate:
|
||||
name: Validate flake
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 30
|
||||
outputs:
|
||||
hosts: ${{ steps.hosts.outputs.hosts }}
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
with:
|
||||
extra_nix_config: |
|
||||
experimental-features = nix-command flakes
|
||||
accept-flake-config = true
|
||||
access-tokens = github.com=${{ github.token }}
|
||||
- name: Check flake and evaluate all outputs
|
||||
run: nix flake check --all-systems --no-build --show-trace
|
||||
- name: Discover NixOS hosts
|
||||
id: hosts
|
||||
run: |
|
||||
hosts=$(nix eval --json '.#nixosConfigurations' --apply 'configs: builtins.attrNames configs')
|
||||
echo "hosts=$hosts" >> "$GITHUB_OUTPUT"
|
||||
echo "Discovered hosts: $hosts"
|
||||
build:
|
||||
name: Build ${{ matrix.host }}
|
||||
needs: validate
|
||||
if: ${{ needs.validate.outputs.hosts != '[]' }}
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 120
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
host: ${{ fromJSON(needs.validate.outputs.hosts) }}
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
with:
|
||||
extra_nix_config: |
|
||||
experimental-features = nix-command flakes
|
||||
accept-flake-config = true
|
||||
access-tokens = github.com=${{ github.token }}
|
||||
- name: Build NixOS system
|
||||
run: |
|
||||
nix build ".#nixosConfigurations.${{ matrix.host }}.config.system.build.toplevel" \
|
||||
--no-link \
|
||||
--print-build-logs \
|
||||
--show-trace
|
||||
report-main-status:
|
||||
name: Report main status
|
||||
needs:
|
||||
- validate
|
||||
- build
|
||||
if: ${{ always() && !cancelled() && github.event_name == 'push' && github.ref == 'refs/heads/main' }}
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
permissions:
|
||||
contents: read
|
||||
issues: write
|
||||
env:
|
||||
CI_FAILED: ${{ needs.validate.result == 'failure' || needs.build.result == 'failure' }}
|
||||
JOB_RESULTS: ${{ toJSON(needs) }}
|
||||
steps:
|
||||
- name: Create or resolve failure issue
|
||||
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
|
||||
with:
|
||||
script: |
|
||||
const owner = context.repo.owner;
|
||||
const repo = context.repo.repo;
|
||||
const title = "NixOS CI is failing on main";
|
||||
const marker = "<!-- nixos-ci-main-failure -->";
|
||||
const failed = process.env.CI_FAILED === "true";
|
||||
const jobs = JSON.parse(process.env.JOB_RESULTS);
|
||||
const failedJobs = Object.entries(jobs)
|
||||
.filter(([, job]) => job.result === "failure")
|
||||
.map(([name]) => `\`${name}\``)
|
||||
.join(", ");
|
||||
const runUrl = `${context.serverUrl}/${owner}/${repo}/actions/runs/${context.runId}`;
|
||||
const commitUrl = `${context.serverUrl}/${owner}/${repo}/commit/${context.sha}`;
|
||||
const issues = await github.paginate(github.rest.issues.listForRepo, {
|
||||
owner,
|
||||
repo,
|
||||
state: "open",
|
||||
per_page: 100,
|
||||
});
|
||||
const existing = issues.find(
|
||||
(issue) => !issue.pull_request && issue.title === title && issue.body?.includes(marker),
|
||||
);
|
||||
|
||||
if (failed) {
|
||||
const body = [
|
||||
marker,
|
||||
"The NixOS CI workflow failed after a push to `main`.",
|
||||
"",
|
||||
`- Failed jobs: ${failedJobs || "unknown"}`,
|
||||
`- Commit: [\`${context.sha.slice(0, 7)}\`](${commitUrl})`,
|
||||
`- Workflow run: [${context.runId}](${runUrl})`,
|
||||
"",
|
||||
"This issue is updated on subsequent failures and closed automatically after CI recovers.",
|
||||
].join("\n");
|
||||
|
||||
if (existing) {
|
||||
await github.rest.issues.update({
|
||||
owner,
|
||||
repo,
|
||||
issue_number: existing.number,
|
||||
body,
|
||||
});
|
||||
} else {
|
||||
await github.rest.issues.create({ owner, repo, title, body });
|
||||
}
|
||||
return;
|
||||
}
|
||||
|
||||
if (existing) {
|
||||
await github.rest.issues.createComment({
|
||||
owner,
|
||||
repo,
|
||||
issue_number: existing.number,
|
||||
body: `CI recovered in [workflow run ${context.runId}](${runUrl}).`,
|
||||
});
|
||||
await github.rest.issues.update({
|
||||
owner,
|
||||
repo,
|
||||
issue_number: existing.number,
|
||||
state: "closed",
|
||||
state_reason: "completed",
|
||||
});
|
||||
}
|
||||
@@ -1,31 +0,0 @@
|
||||
name: Renovate
|
||||
on:
|
||||
schedule:
|
||||
# Every day at 03:00 JST (18:00 UTC on the previous day).
|
||||
- cron: "0 18 * * *"
|
||||
workflow_dispatch:
|
||||
permissions:
|
||||
contents: read
|
||||
concurrency:
|
||||
group: renovate
|
||||
cancel-in-progress: false
|
||||
jobs:
|
||||
renovate:
|
||||
name: Update GitHub Actions dependencies
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 60
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
# Use a PAT or GitHub App token so Renovate PRs trigger the other workflows.
|
||||
- name: Run Renovate
|
||||
uses: renovatebot/github-action@3064367f740a1a91cca218698a63902689cce200 # v46.1.20
|
||||
with:
|
||||
renovate-version: 43.262.1
|
||||
token: ${{ secrets.RENOVATE_TOKEN }}
|
||||
env:
|
||||
LOG_LEVEL: info
|
||||
RENOVATE_PLATFORM: github
|
||||
RENOVATE_REPOSITORIES: ${{ github.repository }}
|
||||
@@ -1,106 +0,0 @@
|
||||
name: Update Flake Inputs
|
||||
on:
|
||||
schedule:
|
||||
# Every day at 03:30 JST (18:30 UTC on the previous day).
|
||||
- cron: "30 18 * * *"
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
input:
|
||||
description: Update only this flake input (empty updates all inputs)
|
||||
required: false
|
||||
type: string
|
||||
skip-delay:
|
||||
description: Update to the latest revision without the three-day delay
|
||||
required: false
|
||||
default: false
|
||||
type: boolean
|
||||
auto-merge:
|
||||
description: Enable auto-merge after required checks pass
|
||||
required: false
|
||||
default: true
|
||||
type: boolean
|
||||
permissions:
|
||||
contents: write
|
||||
pull-requests: write
|
||||
concurrency:
|
||||
group: update-flake-inputs
|
||||
cancel-in-progress: false
|
||||
jobs:
|
||||
discover:
|
||||
name: Discover flake inputs
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
outputs:
|
||||
matrix: ${{ steps.inputs.outputs.matrix }}
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Build update matrix
|
||||
id: inputs
|
||||
env:
|
||||
REQUESTED_INPUT: ${{ inputs.input }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
github_inputs="$(
|
||||
jq -c '
|
||||
. as $lock
|
||||
| [
|
||||
$lock.nodes.root.inputs
|
||||
| to_entries[]
|
||||
| .key as $name
|
||||
| (
|
||||
.value
|
||||
| if type == "array" then .[0] else . end
|
||||
) as $node
|
||||
| select($lock.nodes[$node].locked.type == "github")
|
||||
| $name
|
||||
]
|
||||
| sort
|
||||
' flake.lock
|
||||
)"
|
||||
|
||||
if [ -n "$REQUESTED_INPUT" ]; then
|
||||
if ! jq -e --arg input "$REQUESTED_INPUT" 'index($input) != null' <<< "$github_inputs" >/dev/null; then
|
||||
echo "::error::Unknown or unsupported flake input: $REQUESTED_INPUT"
|
||||
exit 1
|
||||
fi
|
||||
matrix="$(jq -cn --arg input "$REQUESTED_INPUT" '{input: [$input]}')"
|
||||
else
|
||||
matrix="$(jq -cn --argjson inputs "$github_inputs" '{input: $inputs}')"
|
||||
fi
|
||||
|
||||
echo "matrix=$matrix" >> "$GITHUB_OUTPUT"
|
||||
echo "Update matrix: $matrix"
|
||||
update:
|
||||
name: Update ${{ matrix.input }}
|
||||
needs: discover
|
||||
if: ${{ needs.discover.outputs.matrix != '{"input":[]}' }}
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 30
|
||||
strategy:
|
||||
fail-fast: false
|
||||
max-parallel: 4
|
||||
matrix: ${{ fromJSON(needs.discover.outputs.matrix) }}
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
fetch-depth: 0
|
||||
token: ${{ secrets.RENOVATE_TOKEN }}
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
with:
|
||||
extra_nix_config: |
|
||||
experimental-features = nix-command flakes
|
||||
accept-flake-config = true
|
||||
access-tokens = github.com=${{ secrets.RENOVATE_TOKEN }}
|
||||
- name: Update input
|
||||
uses: ./.github/actions/update-flake-input
|
||||
with:
|
||||
input-name: ${{ matrix.input }}
|
||||
github-token: ${{ secrets.RENOVATE_TOKEN }}
|
||||
skip-delay: ${{ github.event_name == 'workflow_dispatch' && inputs.skip-delay }}
|
||||
auto-merge: ${{ github.event_name != 'workflow_dispatch' || inputs.auto-merge }}
|
||||
Reference in New Issue
Block a user