diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index cead32b..5efd695 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -39,6 +39,8 @@ jobs: docker run --rm \ -v "$PWD:/work" \ -w /work \ + `# $HOME persists on self-hosted runners: seed npm cache once, skip the tarball download after that.` \ + -v "$HOME/.npm:/root/.npm" \ node:22-alpine \ sh -lc 'npx --yes prettier@3.9.8 --check --ignore-unknown "$@"' sh "${prettier_files[@]}" @@ -51,11 +53,8 @@ jobs: - name: Lint Python with Ruff shell: bash run: | - docker run --rm \ - -v "$PWD:/work" \ - -w /work \ - ghcr.io/astral-sh/ruff:latest \ - check . + # Native: ruff ships in Arch repos, no container pull needed. + ruff check . lint-yaml: runs-on: [self-hosted, linux, arch, homelab] @@ -77,11 +76,8 @@ jobs: exit 0 fi - docker run --rm \ - -v "$PWD:/work" \ - -w /work \ - cytopia/yamllint:latest \ - -c .yamllint "${yaml_files[@]}" + # Native: yamllint ships in Arch repos, no container pull needed. + yamllint -c .yamllint "${yaml_files[@]}" lint-dockerfiles: runs-on: [self-hosted, linux, arch, homelab] @@ -92,6 +88,7 @@ jobs: - name: Lint Dockerfiles shell: bash run: | + # Stays in Docker: hadolint is AUR-only on Arch, container keeps the pin hermetic. mapfile -t dockerfiles < <( git ls-files ':(glob)**/Dockerfile' ':(glob)**/Dockerfile.*' ) @@ -117,6 +114,7 @@ jobs: - name: Validate Kubernetes manifests shell: bash run: | + # Stays in Docker: avoids a manual `pacman -S kubeconform` on every runner, pin stays hermetic. mapfile -t manifests < <( git ls-files ':(glob)**/k8s/**/*.yaml' ':(glob)**/k8s/**/*.yml' \ | grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$'