diff --git a/.gitea/workflows/gates.yml b/.gitea/workflows/gates.yml new file mode 100644 index 0000000..1ef297a --- /dev/null +++ b/.gitea/workflows/gates.yml @@ -0,0 +1,39 @@ +# gates — re-run this repo's gate entry point on every push, on a machine that does not care who +# pushed or what they typed. +# +# *** THIS REPORTS. IT CANNOT REFUSE. *** +# +# felhom repos push straight to `main` with no pull request, so there is no merge for a status +# check to stand at. The refusing half is `.githooks/pre-push`, which is local to a clone and which +# `git push --no-verify` skips; this half is what notices when that happened. Neither half is the +# whole thing, and both are named in documentation/backlog/OPEN-ITEMS.md R-168. +# +# NO `uses:` STEP ANYWHERE, deliberately: JavaScript actions need a node runtime in the runner, and +# the runner is a host-mode container with python3 and git and nothing else (see +# homelab-manifests/gitea-system/act-runner.yaml for why it is not privileged). Probe P3 measured +# that a plain `git fetch` of the pushed SHA from the in-cluster Gitea service is enough. +# +# A failing run must reach a person — a detector nobody hears is the defect R-29 filed, rebuilt one +# layer up. That is the last step, and it runs ONLY on failure. +name: gates +on: [push] + +jobs: + gates: + runs-on: felhom-gates + steps: + - name: Fetch the pushed commit + run: | + # Shallow, and pinned to the exact SHA that was pushed — not to the branch tip, which can + # move under us if two pushes race. Probe P3 proved the two are equal when done this way. + git init -q . + git remote add origin http://gitea.gitea-system.svc.cluster.local:3000/admin/felhom.eu.git + git fetch -q --depth 1 origin "$GITHUB_SHA" + git checkout -q FETCH_HEAD + echo "checked out $(git rev-parse HEAD)" + + - name: Run the gate entry point + # The ONLY thing CI runs. No go build, no go test, no linting, no deploy — those are either + # already reliably run by a person or none of CI's business. The exit code IS the result: + # no `|| true`, no pipe that could swallow it. + run: python3 scripts/repo_gates.py --fast diff --git a/.gitea/workflows/probe.yml b/.gitea/workflows/probe.yml deleted file mode 100644 index 9b91c18..0000000 --- a/.gitea/workflows/probe.yml +++ /dev/null @@ -1,30 +0,0 @@ -# TEMPORARY probe workflow (R-168, Part 0). DELETED before this session ends — if you are reading -# this on main, teardown was missed. Measures P1 (a runner picks a job up at all), P2 in situ -# (python3+git inside the job, not just inside the image), P3 (source without any JavaScript -# action), and Scenario E's negative (docker must NOT be reachable). -name: probe -on: [push] -jobs: - probe: - runs-on: felhom-gates - steps: - - name: P1 - the job runs at all - run: echo "P1-OK runner picked up the job" - - - name: P2 in situ - tools visible to the JOB, not just the image - run: | - echo -n "P2 python3: "; python3 --version - echo -n "P2 git: "; git --version - - - name: P3 - obtain the source with no JavaScript action step - run: | - echo "P3 pushed sha = $GITHUB_SHA" - git clone -q http://gitea.gitea-system.svc.cluster.local:3000/admin/felhom.eu.git src - cd src && git checkout -q "$GITHUB_SHA" - echo "P3 checked-out sha = $(git rev-parse HEAD)" - test "$(git rev-parse HEAD)" = "$GITHUB_SHA" && echo "P3-OK checkout equals pushed commit" || { echo "P3-FAIL"; exit 1; } - - - name: Scenario E - docker MUST be unreachable - run: | - if docker ps 2>&1; then echo "E-FAIL docker reachable from the job"; exit 1; fi - echo "E-OK docker refused (output above is the refusal)"