Compare commits

..
Author SHA1 Message Date
renovate-bot Bot 53f1704369 chore(deps): update all patch updates
ci / checks (pull_request) Successful in 59s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 14s
2026-10-06 22:20:04 +00:00
forust 898463b759 Merge pull request 'refactor(ci): native VPS runner and durable incremental deploys' (#98) from codex/cicd-runner-deploy into main
ci / checks (push) Successful in 53s
renovate-ci / validate-renovate (push) Successful in 12s
ci / build (push) Successful in 1m44s
Reviewed-on: #98
2026-10-06 21:19:55 +00:00
5 changed files with 13 additions and 108 deletions

No files matched your search

+1 -3
View File
@@ -1,9 +1,7 @@
# Homelab CI/CD
The native Gitea runner runs on **vps**; production runs on **workstation**.
Compose, workflow, shell, Python, formatting, YAML, Dockerfile and Kubernetes
checks appear as separate jobs. Jobs run on `homelab:host`, one at a time; the
build waits for every check to pass. No job images or Kubernetes credentials
Jobs run on `homelab:host`, one at a time. No job images or Kubernetes credentials
are needed on the VPS. Builds use one pinned BuildKit helper container. CI and deploy are separate workflows.
## Runner installation
+9 -102
View File
@@ -12,13 +12,18 @@ concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
jobs:
compose:
name: Compose
checks:
runs-on: homelab
timeout-minutes: 15
timeout-minutes: 30
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Validate Compose files
shell: bash
run: |
@@ -47,37 +52,11 @@ jobs:
exit 1
fi
echo "checked ${#files[@]} Compose file(s)"
workflows:
name: Workflows
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh actionlint shellcheck)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Lint Gitea Actions workflows with actionlint
shell: bash
run: |
set -euo pipefail
actionlint -config-file .gitea/actionlint.yaml -color .gitea/workflows/*.yaml
shell:
name: Shell
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh shellcheck jq)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Lint shell scripts with ShellCheck
shell: bash
run: |
@@ -91,19 +70,6 @@ jobs:
fi
shellcheck --external-sources --source-path=SCRIPTDIR --severity=style "${scripts[@]}"
bash .gitea/tests/deploy-validation.sh
formatting:
name: Formatting
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh prettier)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Check formatting with Prettier
shell: bash
run: |
@@ -121,19 +87,6 @@ jobs:
fi
prettier --check --ignore-unknown "${prettier_files[@]}"
python:
name: Python and tests
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh ruff jq)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Lint and format-check Python with Ruff
shell: bash
run: |
@@ -141,19 +94,6 @@ jobs:
ruff check . .gitea/workflows
ruff format --check . .gitea/workflows
python3 -m unittest discover -s tests -v
yaml:
name: YAML
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh yamllint)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Lint YAML syntax
shell: bash
run: |
@@ -171,19 +111,6 @@ jobs:
fi
yamllint -c .yamllint "${yaml_files[@]}"
dockerfiles:
name: Dockerfiles
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh hadolint)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Lint Dockerfiles
shell: bash
run: |
@@ -199,19 +126,6 @@ jobs:
fi
hadolint -c .hadolint.yaml "${dockerfiles[@]}"
kubernetes:
name: Kubernetes
runs-on: homelab
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
- name: Prepare pinned tools
shell: bash
run: |
set -euo pipefail
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh kubeconform)"
echo "$tools_dir" >> "$GITHUB_PATH"
- name: Validate Kubernetes manifests against JSON schemas
shell: bash
run: |
@@ -234,14 +148,7 @@ jobs:
"${manifests[@]}"
build:
needs:
- compose
- workflows
- shell
- formatting
- python
- yaml
- dockerfiles
- kubernetes
- checks
if: github.event_name != 'pull_request' && github.ref == 'refs/heads/main'
runs-on: homelab
timeout-minutes: 60
+1 -1
View File
@@ -14,7 +14,7 @@ ACTIONLINT_VERSION="1.7.7"
SHELLCHECK_VERSION="0.11.0"
KUBECONFORM_VERSION="0.8.0"
PRETTIER_VERSION="3.8.1"
RUFF_VERSION="0.16.8"
RUFF_VERSION="0.16.10"
YAMLLINT_VERSION="1.38.0"
HADOLINT_VERSION="2.14.0"
# pip-audit reads the advisory database over the network, so a floating version
+1 -1
View File
@@ -1,6 +1,6 @@
services:
traefik:
image: traefik:v3.7.13
image: traefik:v3.7.14
container_name: traefik
restart: unless-stopped
command:
+1 -1
View File
@@ -3,7 +3,7 @@ hostNetwork: false
image:
registry: docker.io/library
repository: traefik
tag: v3.7.13
tag: v3.7.14
securityContext:
capabilities: