gitea
Update Nix binary cache / Build every host and publish new cache objects (push) Has been cancelled

This commit is contained in:
2026-07-14 20:23:43 +09:00
parent b5c49ffa79
commit 39beedefc8
5 changed files with 784 additions and 0 deletions
+46
View File
@@ -0,0 +1,46 @@
name: Bootstrap Nix binary cache
on:
workflow_dispatch:
permissions:
contents: write
concurrency:
group: nix-release-cache-publisher
cancel-in-progress: false
jobs:
bootstrap:
name: Build every host and bootstrap the cache
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Install Nix
uses: cachix/install-nix-action@v31
with:
extra_nix_config: |
experimental-features = nix-command flakes
accept-flake-config = true
- name: Build and publish the initial cache
env:
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
NIX_CACHE_PRIVATE_KEY: ${{ secrets.NIX_CACHE_PRIVATE_KEY }}
CACHE_MODE: bootstrap
CACHE_REPOSITORY: moons-14/dotfiles
CACHE_SERVER_URL: https://git.yutakobayashi.com
CACHE_COMMIT: ${{ github.sha }}
CACHE_REF_NAME: ${{ github.ref_name }}
run: |
set -euo pipefail
if [[ -z "${NIX_CACHE_PRIVATE_KEY:-}" ]]; then
echo "Repository secret NIX_CACHE_PRIVATE_KEY is required." >&2
exit 1
fi
key_file="${RUNNER_TEMP:-/tmp}/nix-cache-private-key"
umask 077
printf '%s\n' "$NIX_CACHE_PRIVATE_KEY" > "$key_file"
unset NIX_CACHE_PRIVATE_KEY
export NIX_CACHE_KEY_FILE="$key_file"
trap 'rm -f "$key_file"' EXIT
./.gitea/scripts/publish-nix-cache.sh