# gates — re-run this repo's gate entry point on every push, on a machine that does not care who # pushed or what they typed. # # *** THIS REPORTS. IT CANNOT REFUSE. *** # # felhom repos push straight to `main` with no pull request, so there is no merge for a status # check to stand at. The refusing half is `.githooks/pre-push`, which is local to a clone and which # `git push --no-verify` skips; this half is what notices when that happened. Neither half is the # whole thing, and both are named in documentation/backlog/OPEN-ITEMS.md R-168. # # NO `uses:` STEP ANYWHERE, deliberately: JavaScript actions need a node runtime in the runner, and # the runner is a host-mode container with python3 and git and nothing else (see # homelab-manifests/gitea-system/act-runner.yaml for why it is not privileged). Probe P3 measured # that a plain `git fetch` of the pushed SHA from the in-cluster Gitea service is enough. # # A failing run must reach a person — a detector nobody hears is the defect R-29 filed, rebuilt one # layer up. That is the last step, and it runs ONLY on failure. name: gates on: [push] jobs: gates: runs-on: felhom-gates steps: - name: Fetch the pushed commit run: | # Shallow, and pinned to the exact SHA that was pushed — not to the branch tip, which can # move under us if two pushes race. Probe P3 proved the two are equal when done this way. git init -q . git remote add origin http://gitea.gitea-system.svc.cluster.local:3000/admin/felhom.eu.git git fetch -q --depth 1 origin "$GITHUB_SHA" git checkout -q FETCH_HEAD echo "checked out $(git rev-parse HEAD)" - name: Run the gate entry point # The ONLY thing CI runs. No go build, no go test, no linting, no deploy — those are either # already reliably run by a person or none of CI's business. The exit code IS the result: # no `|| true`, no pipe that could swallow it. run: python3 scripts/repo_gates.py --fast