From 51677ae18454ffe54c4058b22c25f2a0e3338b5b Mon Sep 17 00:00:00 2001 From: mr-forust Date: Fri, 18 Sep 2026 22:18:59 +0200 Subject: [PATCH] ci: run all lint jobs natively without docker --- .gitea/workflows/ci.yaml | 25 +++---------------------- 1 file changed, 3 insertions(+), 22 deletions(-) diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index 5efd695..d017a83 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -7,7 +7,6 @@ on: pull_request: workflow_dispatch: -# Fast pushes on a branch cancel superseded runs; main is never cancelled. concurrency: group: ci-${{ github.ref }} cancel-in-progress: ${{ github.ref != 'refs/heads/main' }} @@ -36,13 +35,7 @@ jobs: exit 0 fi - docker run --rm \ - -v "$PWD:/work" \ - -w /work \ - `# $HOME persists on self-hosted runners: seed npm cache once, skip the tarball download after that.` \ - -v "$HOME/.npm:/root/.npm" \ - node:22-alpine \ - sh -lc 'npx --yes prettier@3.9.8 --check --ignore-unknown "$@"' sh "${prettier_files[@]}" + prettier --check --ignore-unknown "${prettier_files[@]}" lint-ruff: runs-on: [self-hosted, linux, arch, homelab] @@ -53,7 +46,6 @@ jobs: - name: Lint Python with Ruff shell: bash run: | - # Native: ruff ships in Arch repos, no container pull needed. ruff check . lint-yaml: @@ -76,7 +68,6 @@ jobs: exit 0 fi - # Native: yamllint ships in Arch repos, no container pull needed. yamllint -c .yamllint "${yaml_files[@]}" lint-dockerfiles: @@ -88,7 +79,6 @@ jobs: - name: Lint Dockerfiles shell: bash run: | - # Stays in Docker: hadolint is AUR-only on Arch, container keeps the pin hermetic. mapfile -t dockerfiles < <( git ls-files ':(glob)**/Dockerfile' ':(glob)**/Dockerfile.*' ) @@ -98,12 +88,7 @@ jobs: exit 0 fi - docker run --rm \ - -v "$PWD:/work" \ - -w /work \ - --entrypoint hadolint \ - hadolint/hadolint:latest-debian \ - -c .hadolint.yaml "${dockerfiles[@]}" + hadolint -c .hadolint.yaml "${dockerfiles[@]}" validate: runs-on: [self-hosted, linux, arch, homelab] @@ -114,7 +99,6 @@ jobs: - name: Validate Kubernetes manifests shell: bash run: | - # Stays in Docker: avoids a manual `pacman -S kubeconform` on every runner, pin stays hermetic. mapfile -t manifests < <( git ls-files ':(glob)**/k8s/**/*.yaml' ':(glob)**/k8s/**/*.yml' \ | grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$' @@ -125,10 +109,7 @@ jobs: exit 0 fi - docker run --rm \ - -v "$PWD:/work" \ - -w /work \ - ghcr.io/yannh/kubeconform:latest \ + kubeconform \ -strict \ -ignore-missing-schemas \ -summary \