ci: run ruff and yamllint natively, cache npm

Ruff and yamllint ship in Arch repos, drop their container pulls. Prettier keeps the node container but mounts persistent npm cache. Hadolint and kubeconform stay containerized (AUR-only / hermetic pin).
This commit is contained in:
forust committed 2026-09-18 19:41:02 +02:00
1 parent ab386fc436
commit c9e6fc0e2b
1 file changed
+8 -10
+8 -10
View File
@@ -39,6 +39,8 @@ jobs:
docker run --rm \
-v "$PWD:/work" \
-w /work \
`# $HOME persists on self-hosted runners: seed npm cache once, skip the tarball download after that.` \
-v "$HOME/.npm:/root/.npm" \
node:22-alpine \
sh -lc 'npx --yes prettier@3.9.8 --check --ignore-unknown "$@"' sh "${prettier_files[@]}"
@@ -51,11 +53,8 @@ jobs:
- name: Lint Python with Ruff
shell: bash
run: |
docker run --rm \
-v "$PWD:/work" \
-w /work \
ghcr.io/astral-sh/ruff:latest \
check .
# Native: ruff ships in Arch repos, no container pull needed.
ruff check .
lint-yaml:
runs-on: [self-hosted, linux, arch, homelab]
@@ -77,11 +76,8 @@ jobs:
exit 0
fi
docker run --rm \
-v "$PWD:/work" \
-w /work \
cytopia/yamllint:latest \
-c .yamllint "${yaml_files[@]}"
# Native: yamllint ships in Arch repos, no container pull needed.
yamllint -c .yamllint "${yaml_files[@]}"
lint-dockerfiles:
runs-on: [self-hosted, linux, arch, homelab]
@@ -92,6 +88,7 @@ jobs:
- name: Lint Dockerfiles
shell: bash
run: |
# Stays in Docker: hadolint is AUR-only on Arch, container keeps the pin hermetic.
mapfile -t dockerfiles < <(
git ls-files ':(glob)**/Dockerfile' ':(glob)**/Dockerfile.*'
)
@@ -117,6 +114,7 @@ jobs:
- name: Validate Kubernetes manifests
shell: bash
run: |
# Stays in Docker: avoids a manual `pacman -S kubeconform` on every runner, pin stays hermetic.
mapfile -t manifests < <(
git ls-files ':(glob)**/k8s/**/*.yaml' ':(glob)**/k8s/**/*.yml' \
| grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$'