Files
schemas/.gitea/workflows/ci.yaml
T
argoyle 2e63eb00b3
schemas / vulnerabilities (push) Successful in 3m22s
schemas / check-release (push) Successful in 3m49s
schemas / check (push) Successful in 3m54s
Unbound Release / Check Preconditions (push) Successful in 48s
Unbound Release / Create Release (push) Skipped
Unbound Release / Generate Changelog and Handle PR (push) Successful in 46s
pre-commit / pre-commit (push) Successful in 2m34s
Unbound Release / Create Tag (push) Successful in 12s
Release / release (push) Successful in 2m11s
schemas / build (push) Successful in 15m1s
schemas / deploy-prod (push) Failing after 32s
fix: release to the Gitea API on its public URL (#997)
goreleaser's gitea_urls.api still pointed at the AWS in-cluster service (gitea-http.gitea.svc.cluster.local), which does not resolve from the Frostmoln runner. Use https://git.unbound.se/api/v1. Also drop RELEASE_TOKEN_FILE=/runner-secrets/release-token (the AWS runner mount); the Frostmoln runner exports RELEASE_TOKEN_FILE itself.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01Ma8eHhW59hLAJuLzBnLvUu
Reviewed-on: #997
2026-10-07 21:51:04 +00:00

99 lines
2.6 KiB
YAML

name: schemas
on:
push:
branches: [main]
tags:
- 'v*'
pull_request:
branches: [main]
workflow_dispatch:
inputs:
deploy_prod:
description: 'Deploy to production'
required: false
default: 'false'
type: boolean
jobs:
check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-go@v7
with:
go-version: 'stable'
- name: Generate and format check
run: |
go install mvdan.cc/gofumpt@latest
go install golang.org/x/tools/cmd/goimports@latest
go generate ./...
git diff --stat --exit-code
- name: Run tests
run: go test -race -coverprofile=coverage.txt ./...
vulnerabilities:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-go@v7
with:
go-version: 'stable'
- name: Check vulnerabilities
run: |
go install golang.org/x/vuln/cmd/govulncheck@latest
govulncheck ./...
check-release:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- uses: actions/setup-node@v7
with:
node-version: '24'
- uses: actions/setup-go@v7
with:
go-version: 'stable'
- name: Check goreleaser config
uses: goreleaser/goreleaser-action@v7
with:
version: '~> v2'
args: check
- name: Install goreleaser
uses: goreleaser/goreleaser-action@v7
with:
version: '~> v2'
install-only: true
# Without the runner's GOCACHEPROG (gobuildcache): goreleaser's parallel
# go builds contend for its per-entry locks and time out.
- name: Test release build
run: env -u GOCACHEPROG goreleaser release --snapshot --clean
build:
needs: [check, vulnerabilities, check-release]
runs-on: ubuntu-latest
env:
BUILDTOOLS_CONTENT: ${{ secrets.BUILDTOOLS_CONTENT }}
GITEA_REPOSITORY: ${{ gitea.repository }}
steps:
- uses: actions/checkout@v7
- uses: buildtool/setup-buildtools-action@v1
- name: Build and push
run: unset GITEA_TOKEN && build && push
deploy-prod:
needs: build
if: gitea.ref == 'refs/heads/main'
runs-on: ubuntu-latest
env:
BUILDTOOLS_CONTENT: ${{ secrets.BUILDTOOLS_CONTENT }}
GITEA_REPOSITORY: ${{ gitea.repository }}
environment: prod
steps:
- uses: actions/checkout@v7
- uses: buildtool/setup-buildtools-action@v1
- name: Deploy to production
run: deploy prod