Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7e78f3c96e |
No files matched your search
@@ -1,7 +1,9 @@
|
|||||||
# Homelab CI/CD
|
# Homelab CI/CD
|
||||||
|
|
||||||
The native Gitea runner runs on **vps**; production runs on **workstation**.
|
The native Gitea runner runs on **vps**; production runs on **workstation**.
|
||||||
Jobs run on `homelab:host`, one at a time. No job images or Kubernetes credentials
|
Compose, workflow, shell, Python, formatting, YAML, Dockerfile and Kubernetes
|
||||||
|
checks appear as separate jobs. Jobs run on `homelab:host`, one at a time; the
|
||||||
|
build waits for every check to pass. No job images or Kubernetes credentials
|
||||||
are needed on the VPS. Builds use one pinned BuildKit helper container. CI and deploy are separate workflows.
|
are needed on the VPS. Builds use one pinned BuildKit helper container. CI and deploy are separate workflows.
|
||||||
|
|
||||||
## Runner installation
|
## Runner installation
|
||||||
|
|||||||
+102
-9
@@ -12,18 +12,13 @@ concurrency:
|
|||||||
group: ci-${{ github.ref }}
|
group: ci-${{ github.ref }}
|
||||||
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
|
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
|
||||||
jobs:
|
jobs:
|
||||||
checks:
|
compose:
|
||||||
|
name: Compose
|
||||||
runs-on: homelab
|
runs-on: homelab
|
||||||
timeout-minutes: 30
|
timeout-minutes: 15
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
- name: Prepare pinned tools
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh)"
|
|
||||||
echo "$tools_dir" >> "$GITHUB_PATH"
|
|
||||||
- name: Validate Compose files
|
- name: Validate Compose files
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
@@ -52,11 +47,37 @@ jobs:
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
echo "checked ${#files[@]} Compose file(s)"
|
echo "checked ${#files[@]} Compose file(s)"
|
||||||
|
workflows:
|
||||||
|
name: Workflows
|
||||||
|
runs-on: homelab
|
||||||
|
timeout-minutes: 15
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
|
- name: Prepare pinned tools
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh actionlint shellcheck)"
|
||||||
|
echo "$tools_dir" >> "$GITHUB_PATH"
|
||||||
- name: Lint Gitea Actions workflows with actionlint
|
- name: Lint Gitea Actions workflows with actionlint
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
actionlint -config-file .gitea/actionlint.yaml -color .gitea/workflows/*.yaml
|
actionlint -config-file .gitea/actionlint.yaml -color .gitea/workflows/*.yaml
|
||||||
|
shell:
|
||||||
|
name: Shell
|
||||||
|
runs-on: homelab
|
||||||
|
timeout-minutes: 15
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
|
- name: Prepare pinned tools
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh shellcheck jq)"
|
||||||
|
echo "$tools_dir" >> "$GITHUB_PATH"
|
||||||
- name: Lint shell scripts with ShellCheck
|
- name: Lint shell scripts with ShellCheck
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
@@ -70,6 +91,19 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
shellcheck --external-sources --source-path=SCRIPTDIR --severity=style "${scripts[@]}"
|
shellcheck --external-sources --source-path=SCRIPTDIR --severity=style "${scripts[@]}"
|
||||||
bash .gitea/tests/deploy-validation.sh
|
bash .gitea/tests/deploy-validation.sh
|
||||||
|
formatting:
|
||||||
|
name: Formatting
|
||||||
|
runs-on: homelab
|
||||||
|
timeout-minutes: 15
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
|
- name: Prepare pinned tools
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh prettier)"
|
||||||
|
echo "$tools_dir" >> "$GITHUB_PATH"
|
||||||
- name: Check formatting with Prettier
|
- name: Check formatting with Prettier
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
@@ -87,6 +121,19 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
prettier --check --ignore-unknown "${prettier_files[@]}"
|
prettier --check --ignore-unknown "${prettier_files[@]}"
|
||||||
|
python:
|
||||||
|
name: Python and tests
|
||||||
|
runs-on: homelab
|
||||||
|
timeout-minutes: 15
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
|
- name: Prepare pinned tools
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh ruff jq)"
|
||||||
|
echo "$tools_dir" >> "$GITHUB_PATH"
|
||||||
- name: Lint and format-check Python with Ruff
|
- name: Lint and format-check Python with Ruff
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
@@ -94,6 +141,19 @@ jobs:
|
|||||||
ruff check . .gitea/workflows
|
ruff check . .gitea/workflows
|
||||||
ruff format --check . .gitea/workflows
|
ruff format --check . .gitea/workflows
|
||||||
python3 -m unittest discover -s tests -v
|
python3 -m unittest discover -s tests -v
|
||||||
|
yaml:
|
||||||
|
name: YAML
|
||||||
|
runs-on: homelab
|
||||||
|
timeout-minutes: 15
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
|
- name: Prepare pinned tools
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh yamllint)"
|
||||||
|
echo "$tools_dir" >> "$GITHUB_PATH"
|
||||||
- name: Lint YAML syntax
|
- name: Lint YAML syntax
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
@@ -111,6 +171,19 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
yamllint -c .yamllint "${yaml_files[@]}"
|
yamllint -c .yamllint "${yaml_files[@]}"
|
||||||
|
dockerfiles:
|
||||||
|
name: Dockerfiles
|
||||||
|
runs-on: homelab
|
||||||
|
timeout-minutes: 15
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
|
- name: Prepare pinned tools
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh hadolint)"
|
||||||
|
echo "$tools_dir" >> "$GITHUB_PATH"
|
||||||
- name: Lint Dockerfiles
|
- name: Lint Dockerfiles
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
@@ -126,6 +199,19 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
hadolint -c .hadolint.yaml "${dockerfiles[@]}"
|
hadolint -c .hadolint.yaml "${dockerfiles[@]}"
|
||||||
|
kubernetes:
|
||||||
|
name: Kubernetes
|
||||||
|
runs-on: homelab
|
||||||
|
timeout-minutes: 15
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
|
- name: Prepare pinned tools
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
tools_dir="$(bash .gitea/workflows/install-ci-tools.sh kubeconform)"
|
||||||
|
echo "$tools_dir" >> "$GITHUB_PATH"
|
||||||
- name: Validate Kubernetes manifests against JSON schemas
|
- name: Validate Kubernetes manifests against JSON schemas
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
@@ -148,7 +234,14 @@ jobs:
|
|||||||
"${manifests[@]}"
|
"${manifests[@]}"
|
||||||
build:
|
build:
|
||||||
needs:
|
needs:
|
||||||
- checks
|
- compose
|
||||||
|
- workflows
|
||||||
|
- shell
|
||||||
|
- formatting
|
||||||
|
- python
|
||||||
|
- yaml
|
||||||
|
- dockerfiles
|
||||||
|
- kubernetes
|
||||||
if: github.event_name != 'pull_request' && github.ref == 'refs/heads/main'
|
if: github.event_name != 'pull_request' && github.ref == 'refs/heads/main'
|
||||||
runs-on: homelab
|
runs-on: homelab
|
||||||
timeout-minutes: 60
|
timeout-minutes: 60
|
||||||
|
|||||||
Reference in new issue
Block a user