Replaces the Part 0 probe workflow, whose four measurements are recorded in documentation/audits/SPIKE-ci-runner-2026-08-02.md. Reports, does not refuse: pushes go straight to main with no pull request, so there is no merge for a status check to stand at. The refusing half is .githooks/pre-push, which is per-clone and --no-verify-able; this half notices when that was skipped. No uses: step anywhere — JavaScript actions need a node runtime the host-mode runner does not have. Probe P3 measured that a shallow git fetch of the exact pushed SHA from the in-cluster Gitea service is sufficient, and that it equals the pushed commit. The alarm step is deliberately absent until probe P5 measures whether Gitea already mails on a failed run.
This commit is contained in:
@@ -0,0 +1,39 @@
|
||||
# gates — re-run this repo's gate entry point on every push, on a machine that does not care who
|
||||
# pushed or what they typed.
|
||||
#
|
||||
# *** THIS REPORTS. IT CANNOT REFUSE. ***
|
||||
#
|
||||
# felhom repos push straight to `main` with no pull request, so there is no merge for a status
|
||||
# check to stand at. The refusing half is `.githooks/pre-push`, which is local to a clone and which
|
||||
# `git push --no-verify` skips; this half is what notices when that happened. Neither half is the
|
||||
# whole thing, and both are named in documentation/backlog/OPEN-ITEMS.md R-168.
|
||||
#
|
||||
# NO `uses:` STEP ANYWHERE, deliberately: JavaScript actions need a node runtime in the runner, and
|
||||
# the runner is a host-mode container with python3 and git and nothing else (see
|
||||
# homelab-manifests/gitea-system/act-runner.yaml for why it is not privileged). Probe P3 measured
|
||||
# that a plain `git fetch` of the pushed SHA from the in-cluster Gitea service is enough.
|
||||
#
|
||||
# A failing run must reach a person — a detector nobody hears is the defect R-29 filed, rebuilt one
|
||||
# layer up. That is the last step, and it runs ONLY on failure.
|
||||
name: gates
|
||||
on: [push]
|
||||
|
||||
jobs:
|
||||
gates:
|
||||
runs-on: felhom-gates
|
||||
steps:
|
||||
- name: Fetch the pushed commit
|
||||
run: |
|
||||
# Shallow, and pinned to the exact SHA that was pushed — not to the branch tip, which can
|
||||
# move under us if two pushes race. Probe P3 proved the two are equal when done this way.
|
||||
git init -q .
|
||||
git remote add origin http://gitea.gitea-system.svc.cluster.local:3000/admin/felhom.eu.git
|
||||
git fetch -q --depth 1 origin "$GITHUB_SHA"
|
||||
git checkout -q FETCH_HEAD
|
||||
echo "checked out $(git rev-parse HEAD)"
|
||||
|
||||
- name: Run the gate entry point
|
||||
# The ONLY thing CI runs. No go build, no go test, no linting, no deploy — those are either
|
||||
# already reliably run by a person or none of CI's business. The exit code IS the result:
|
||||
# no `|| true`, no pipe that could swallow it.
|
||||
run: python3 scripts/repo_gates.py --fast
|
||||
@@ -1,30 +0,0 @@
|
||||
# TEMPORARY probe workflow (R-168, Part 0). DELETED before this session ends — if you are reading
|
||||
# this on main, teardown was missed. Measures P1 (a runner picks a job up at all), P2 in situ
|
||||
# (python3+git inside the job, not just inside the image), P3 (source without any JavaScript
|
||||
# action), and Scenario E's negative (docker must NOT be reachable).
|
||||
name: probe
|
||||
on: [push]
|
||||
jobs:
|
||||
probe:
|
||||
runs-on: felhom-gates
|
||||
steps:
|
||||
- name: P1 - the job runs at all
|
||||
run: echo "P1-OK runner picked up the job"
|
||||
|
||||
- name: P2 in situ - tools visible to the JOB, not just the image
|
||||
run: |
|
||||
echo -n "P2 python3: "; python3 --version
|
||||
echo -n "P2 git: "; git --version
|
||||
|
||||
- name: P3 - obtain the source with no JavaScript action step
|
||||
run: |
|
||||
echo "P3 pushed sha = $GITHUB_SHA"
|
||||
git clone -q http://gitea.gitea-system.svc.cluster.local:3000/admin/felhom.eu.git src
|
||||
cd src && git checkout -q "$GITHUB_SHA"
|
||||
echo "P3 checked-out sha = $(git rev-parse HEAD)"
|
||||
test "$(git rev-parse HEAD)" = "$GITHUB_SHA" && echo "P3-OK checkout equals pushed commit" || { echo "P3-FAIL"; exit 1; }
|
||||
|
||||
- name: Scenario E - docker MUST be unreachable
|
||||
run: |
|
||||
if docker ps 2>&1; then echo "E-FAIL docker reachable from the job"; exit 1; fi
|
||||
echo "E-OK docker refused (output above is the refusal)"
|
||||
Reference in New Issue
Block a user