From 5bbf1d42e91f33f733cbe9f1d762ba1d028d28c6 Mon Sep 17 00:00:00 2001 From: moons Date: Wed, 29 Jul 2026 10:19:59 +0900 Subject: [PATCH] ci --- .github/actions/check-nixos/action.yaml | 27 +++++++++++++ .github/actions/setup-nix/action.yaml | 22 +++++++++++ .github/workflows/nixos.yaml | 51 +++++++++++++++++++++++++ .github/workflows/update-flake.yaml | 48 +++++++++++++++++++++++ 4 files changed, 148 insertions(+) create mode 100644 .github/actions/check-nixos/action.yaml create mode 100644 .github/actions/setup-nix/action.yaml create mode 100644 .github/workflows/nixos.yaml create mode 100644 .github/workflows/update-flake.yaml diff --git a/.github/actions/check-nixos/action.yaml b/.github/actions/check-nixos/action.yaml new file mode 100644 index 0000000..cae4036 --- /dev/null +++ b/.github/actions/check-nixos/action.yaml @@ -0,0 +1,27 @@ +# Reference: https://github.com/ryoppippi/dotfiles/blob/main/.github/workflows/nix-build.yaml +name: Check NixOS configurations +description: Build every NixOS configuration and the Registry tests +runs: + using: composite + steps: + - name: Build every NixOS configuration + shell: bash + run: | + set -euo pipefail + + mapfile -t hosts < <( + nix eval --raw .#nixosConfigurations \ + --apply 'configs: builtins.concatStringsSep "\n" (builtins.attrNames configs)' + ) + + installables=(.#checks.x86_64-linux.registry) + for host in "${hosts[@]}"; do + installables+=(".#nixosConfigurations.${host}.config.system.build.toplevel") + done + + nix build \ + --keep-going \ + --no-link \ + --print-build-logs \ + --show-trace \ + "${installables[@]}" diff --git a/.github/actions/setup-nix/action.yaml b/.github/actions/setup-nix/action.yaml new file mode 100644 index 0000000..eae5b0b --- /dev/null +++ b/.github/actions/setup-nix/action.yaml @@ -0,0 +1,22 @@ +# Reference: https://github.com/ryoppippi/dotfiles/blob/main/.github/actions/setup-nix/action.yaml +name: Setup Nix +description: Install Nix and cache the Nix store +runs: + using: composite + steps: + - name: Allow unprivileged user namespaces + if: runner.os == 'Linux' + shell: bash + run: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 2>/dev/null || true + - name: Install Nix + uses: nixbuild/nix-quick-install-action@9f63be77f412a248c9d9a65a4c82cf066cdf8f0c # v35 + with: + nix_conf: | + accept-flake-config = true + max-jobs = auto + - name: Cache Nix store + uses: nix-community/cache-nix-action@7df957e333c1e5da7721f60227dbba6d06080569 # v7.0.2 + with: + primary-key: nix-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('flake.lock') }} + restore-prefixes-first-match: nix-${{ runner.os }}-${{ runner.arch }}- + gc-max-store-size-linux: 4G diff --git a/.github/workflows/nixos.yaml b/.github/workflows/nixos.yaml new file mode 100644 index 0000000..734dfa2 --- /dev/null +++ b/.github/workflows/nixos.yaml @@ -0,0 +1,51 @@ +# Reference: https://github.com/ryoppippi/dotfiles/blob/main/.github/workflows/nix-build.yaml +name: "CI: NixOS" +on: + push: + branches: + - main + paths: + - flake.nix + - flake.lock + - "flake/**" + - "hosts/**" + - "libs/**" + - "modules/**" + - "overlays/**" + - "shells/**" + - "tests/**" + - ".github/actions/check-nixos/**" + - ".github/actions/setup-nix/**" + - ".github/workflows/nixos.yaml" + pull_request: + paths: + - flake.nix + - flake.lock + - "flake/**" + - "hosts/**" + - "libs/**" + - "modules/**" + - "overlays/**" + - "shells/**" + - "tests/**" + - ".github/actions/check-nixos/**" + - ".github/actions/setup-nix/**" + - ".github/workflows/nixos.yaml" + workflow_dispatch: +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true +permissions: + contents: read +jobs: + check: + name: Check all NixOS configurations + runs-on: ubuntu-latest + timeout-minutes: 120 + steps: + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - name: Setup Nix + uses: ./.github/actions/setup-nix + - name: Check NixOS configurations + uses: ./.github/actions/check-nixos diff --git a/.github/workflows/update-flake.yaml b/.github/workflows/update-flake.yaml new file mode 100644 index 0000000..1c8a76b --- /dev/null +++ b/.github/workflows/update-flake.yaml @@ -0,0 +1,48 @@ +# Reference: https://github.com/ryoppippi/dotfiles/blob/main/.github/workflows/update-flake.yaml +name: "Bot: Update flake inputs" +on: + schedule: + - cron: "0 6 * * *" + workflow_dispatch: +concurrency: + group: ${{ github.workflow }} + cancel-in-progress: false +permissions: + contents: write + pull-requests: write +jobs: + update: + name: Update and validate flake inputs + runs-on: ubuntu-latest + timeout-minutes: 120 + steps: + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - name: Setup Nix + uses: ./.github/actions/setup-nix + - name: Update flake inputs + id: update + run: | + nix flake update + if git diff --quiet -- flake.lock; then + echo 'changed=false' >> "$GITHUB_OUTPUT" + else + echo 'changed=true' >> "$GITHUB_OUTPUT" + fi + - name: Check updated NixOS configurations + if: steps.update.outputs.changed == 'true' + uses: ./.github/actions/check-nixos + - name: Create update pull request + if: steps.update.outputs.changed == 'true' + uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 + with: + token: ${{ secrets.GITHUB_TOKEN }} + add-paths: flake.lock + branch: automation/update-flake-lock + delete-branch: true + commit-message: "flake: update inputs" + title: "flake: update inputs" + body: | + Automated update of `flake.lock`. + + The updated inputs passed the Registry tests and a build of every NixOS configuration.