Compare commits

..
Author SHA1 Message Date
forust 7e78f3c96e refactor(ci): split checks into visible jobs
renovate-ci / validate-renovate (push) Skipped
2026-10-06 23:22:05 +02:00
3 changed files with 106 additions and 11 deletions

No files matched your search

+3 -1
View File
@@ -1,7 +1,9 @@
# Homelab CI/CD
The native Gitea runner runs on **vps**; production runs on **workstation**.
Jobs run on `homelab:host`, one at a time. No job images or Kubernetes credentials
Compose, workflow, shell, Python, formatting, YAML, Dockerfile and Kubernetes
checks appear as separate jobs. Jobs run on `homelab:host`, one at a time; the
build waits for every check to pass. No job images or Kubernetes credentials
are needed on the VPS. Builds use one pinned BuildKit helper container. CI and deploy are separate workflows.
## Runner installation
+102 -9
View File
@@ -12,18 +12,13 @@ concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
jobs:
checks:
compose:
name: Compose
runs-on: homelab
timeout-minutes: 30
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Validate Compose files
shell: bash
run: |
@@ -52,11 +47,37 @@ jobs:
exit 1
fi
echo "checked ${#files[@]} Compose file(s)"
workflows:
name: Workflows
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh actionlint shellcheck)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Lint Gitea Actions workflows with actionlint
shell: bash
run: |
set -euo pipefail
actionlint -config-file .gitea/actionlint.yaml -color .gitea/workflows/*.yaml
shell:
name: Shell
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh shellcheck jq)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Lint shell scripts with ShellCheck
shell: bash
run: |
@@ -70,6 +91,19 @@ jobs:
fi
shellcheck --external-sources --source-path=SCRIPTDIR --severity=style "${scripts[@]}"
bash .gitea/tests/deploy-validation.sh
formatting:
name: Formatting
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh prettier)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Check formatting with Prettier
shell: bash
run: |
@@ -87,6 +121,19 @@ jobs:
fi
prettier --check --ignore-unknown "${prettier_files[@]}"
python:
name: Python and tests
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh ruff jq)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Lint and format-check Python with Ruff
shell: bash
run: |
@@ -94,6 +141,19 @@ jobs:
ruff check . .gitea/workflows
ruff format --check . .gitea/workflows
python3 -m unittest discover -s tests -v
yaml:
name: YAML
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh yamllint)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Lint YAML syntax
shell: bash
run: |
@@ -111,6 +171,19 @@ jobs:
fi
yamllint -c .yamllint "${yaml_files[@]}"
dockerfiles:
name: Dockerfiles
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh hadolint)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Lint Dockerfiles
shell: bash
run: |
@@ -126,6 +199,19 @@ jobs:
fi
hadolint -c .hadolint.yaml "${dockerfiles[@]}"
kubernetes:
name: Kubernetes
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh kubeconform)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Validate Kubernetes manifests against JSON schemas
shell: bash
run: |
@@ -148,7 +234,14 @@ jobs:
"${manifests[@]}"
build:
needs:
- checks
- compose
- workflows
- shell
- formatting
- python
- yaml
- dockerfiles
- kubernetes
if: github.event_name != 'pull_request' && github.ref == 'refs/heads/main'
runs-on: homelab
timeout-minutes: 60
+1 -1
View File
@@ -324,7 +324,7 @@ HELM_RELEASES=(
"victoria-operator|victoriametrics/victoria-metrics-operator|prometheus|0.68.1|prometheus-stack/k8s/victoria-operator-values.yaml|prometheus-stack/k8s/active"
"loki|grafana/loki|prometheus|7.3.0|loki/k8s/loki-values.yaml|loki/k8s/active"
"alloy|grafana/alloy|prometheus|1.12.1|loki/k8s/alloy-values.yaml|loki/k8s/active"
"reloader|stakater/reloader|reloader|2.2.18|reloader/k8s/reloader-values.yaml|reloader/k8s/active"
"reloader|stakater/reloader|reloader|2.2.17|reloader/k8s/reloader-values.yaml|reloader/k8s/active"
)
# "name url" for the Helm repository hosting a chart, empty if unknown.