From dc760eb58e238af820fe56ba360f1744d0d4bc09 Mon Sep 17 00:00:00 2001 From: tegwick Date: Sat, 4 Jul 2026 12:49:06 +0200 Subject: [PATCH] Add Forgejo Actions workflow templates and repo promotion helper Canonical ci-smoke, container-build-push, and multirepo build templates for railiance01 runners. Documents adoption path for tier 1-3 repos. --- .forgejo/workflows/ci-smoke.yaml | 29 ++++++++ docs/forgejo-actions-workflow-templates.md | 66 +++++++++++++++++++ tools/promote-repo-to-forgejo.sh | 51 ++++++++++++++ workflows/ci-smoke.yaml | 29 ++++++++ workflows/container-build-push-multirepo.yaml | 61 +++++++++++++++++ workflows/container-build-push.yaml | 48 ++++++++++++++ 6 files changed, 284 insertions(+) create mode 100644 .forgejo/workflows/ci-smoke.yaml create mode 100644 docs/forgejo-actions-workflow-templates.md create mode 100755 tools/promote-repo-to-forgejo.sh create mode 100644 workflows/ci-smoke.yaml create mode 100644 workflows/container-build-push-multirepo.yaml create mode 100644 workflows/container-build-push.yaml diff --git a/.forgejo/workflows/ci-smoke.yaml b/.forgejo/workflows/ci-smoke.yaml new file mode 100644 index 0000000..bd44c56 --- /dev/null +++ b/.forgejo/workflows/ci-smoke.yaml @@ -0,0 +1,29 @@ +# Canonical CI smoke template (tier 1 routing drill). +# Copy to: .forgejo/workflows/ci-smoke.yaml in consumer repos. +name: CI Smoke + +on: + push: + branches: + - main + workflow_dispatch: + +jobs: + host-smoke: + runs-on: self-hosted + steps: + - name: Routing probe (host runner) + run: | + set -eu + echo "repository=${GITHUB_REPOSITORY:-unknown}" + echo "sha=${GITHUB_SHA:-unknown}" + echo "runner=${RUNNER_NAME:-unknown}" + uname -a + + container-smoke: + runs-on: ubuntu-latest + steps: + - name: Routing probe (container label) + run: | + set -eu + echo "container-smoke ok for ${GITHUB_REPOSITORY:-unknown}" \ No newline at end of file diff --git a/docs/forgejo-actions-workflow-templates.md b/docs/forgejo-actions-workflow-templates.md new file mode 100644 index 0000000..79e6795 --- /dev/null +++ b/docs/forgejo-actions-workflow-templates.md @@ -0,0 +1,66 @@ +# Forgejo Actions Workflow Templates + +Date: 2026-07-04 +Owner: `railiance-enablement` (S4) +Workplans: `RAIL-HO-WP-0005-T08`, `CUST-WP-0054-T04` + +## Purpose + +Canonical, copy-ready Forgejo Actions workflows for the railiance01 runner +substrate (`railiance01-build-01`, ADR-004). Forgejo/Gitea Actions on our +runners do **not** support `actions/checkout@v4` on the non-root host runner; +use **archive checkout** via `wget` instead. + +Templates live in `workflows/` at repo root. Consumer repos copy into +`.forgejo/workflows/` and adjust `IMAGE_NAME` / `EXTRA_REPOS` as needed. + +## Runner labels + +| Label | Use | +| --- | --- | +| `self-hosted` | Host runner routing smoke, lightweight probes | +| `ubuntu-latest` | Container-isolated smoke (label routing) | +| `container-build` | DinD image build + registry push | + +Org secrets (set on `coulomb` org): `REGISTRY_USER`, `REGISTRY_TOKEN`. + +## Templates + +| File | Tier | When to use | +| --- | ---: | --- | +| `workflows/ci-smoke.yaml` | 1 | Git+CI routing drill; infra/docs repos | +| `workflows/container-build-push.yaml` | 2 | Single-repo `Dockerfile` image publish | +| `workflows/container-build-push-multirepo.yaml` | 3 prep | Docker build with named contexts (e.g. `state-hub` + `hub-core`) | + +## Adoption + +```bash +mkdir -p .forgejo/workflows +cp /path/to/railiance-enablement/workflows/ci-smoke.yaml .forgejo/workflows/ +# For images: +cp /path/to/railiance-enablement/workflows/container-build-push.yaml .forgejo/workflows/image.yaml +# Edit IMAGE_NAME=coulomb/ +git add .forgejo/workflows && git commit -m "Add Forgejo CI from enablement templates" +git push origin main +``` + +## Proven consumers + +| Repo | Template | Evidence | +| --- | --- | --- | +| `coulomb/glas-harness` | `ci-smoke` (in-repo) | Tier 1 pilot | +| `coulomb/key-cape` | `container-build-push` (in-repo) | Tier 2 pilot | +| `coulomb/railiance-*` | `ci-smoke` | Tier 2.5 promotion (2026-07-04) | + +## Constraints + +- Do not use `actions/checkout@v4` on `self-hosted` / `container-build` runners. +- Static `docker` binary via wget; runner image is non-root and cannot `apk add`. +- Reusable `workflow_call` across repos is not relied on; copy templates instead. +- Runner substrate and labels: `railiance-forge/docs/ci-runner-actions-gitops-ownership.md`. + +## References + +- `the-custodian/docs/forgejo-repo-migration-pilot-glas-harness.md` +- `railiance-apps/docs/forgejo-on-railiance01.md` +- `docs/adr/ADR-004-forgejo-in-cluster-actions-runner.md` (in `railiance-infra`) \ No newline at end of file diff --git a/tools/promote-repo-to-forgejo.sh b/tools/promote-repo-to-forgejo.sh new file mode 100755 index 0000000..106816c --- /dev/null +++ b/tools/promote-repo-to-forgejo.sh @@ -0,0 +1,51 @@ +#!/usr/bin/env bash +# Promote a coulomb repo to Forgejo (tier 2.5): mirror, flip remotes, add ci-smoke. +set -euo pipefail + +REPO="${1:?usage: promote-repo-to-forgejo.sh [repo-path]}" +REPO_PATH="${2:-$HOME/${REPO}}" +ORG=coulomb +FORGEJO_API="${FORGEJO_API:-https://forgejo.coulomb.social/api/v1}" +TOKEN_FILE="${FORGEJO_TOKEN_FILE:-/tmp/forgejo-tegwick-api-token}" +TEMPLATE="${PROMOTE_CI_TEMPLATE:-$HOME/railiance-enablement/workflows/ci-smoke.yaml}" + +if [[ ! -f "${TOKEN_FILE}" ]]; then + echo "Missing API token at ${TOKEN_FILE}" >&2 + exit 1 +fi +TOKEN=$(cat "${TOKEN_FILE}") +AUTH=(-H "Authorization: token ${TOKEN}") + +code=$(curl -sS -o /dev/null -w '%{http_code}' "${AUTH[@]}" "${FORGEJO_API}/repos/${ORG}/${REPO}") +if [[ "${code}" == "404" ]]; then + echo "==> Creating ${ORG}/${REPO} on Forgejo" + curl -fsS -X POST "${FORGEJO_API}/orgs/${ORG}/repos" "${AUTH[@]}" \ + -H "Content-Type: application/json" \ + -d "{\"name\":\"${REPO}\",\"private\":false,\"auto_init\":false}" >/dev/null +elif [[ "${code}" == "200" ]]; then + echo "==> ${ORG}/${REPO} already exists on Forgejo" +else + echo "Unexpected API status ${code} for ${ORG}/${REPO}" >&2 + exit 1 +fi + +cd "${REPO_PATH}" + +mkdir -p .forgejo/workflows +if [[ ! -f .forgejo/workflows/ci-smoke.yaml ]]; then + cp "${TEMPLATE}" .forgejo/workflows/ci-smoke.yaml + git add .forgejo/workflows/ci-smoke.yaml + git commit -m "Add Forgejo CI smoke workflow (enablement template)" +fi + +if git remote get-url origin 2>/dev/null | grep -q forgejo-remote; then + echo "==> Remotes already on Forgejo" +else + git remote rename origin gitea + git remote add origin "forgejo-remote:${ORG}/${REPO}.git" + echo "==> Remotes: origin=forgejo-remote, gitea=legacy" +fi + +echo "==> Pushing ${REPO_PATH} to Forgejo" +git push -u origin main +echo "==> Promoted ${REPO}" \ No newline at end of file diff --git a/workflows/ci-smoke.yaml b/workflows/ci-smoke.yaml new file mode 100644 index 0000000..bd44c56 --- /dev/null +++ b/workflows/ci-smoke.yaml @@ -0,0 +1,29 @@ +# Canonical CI smoke template (tier 1 routing drill). +# Copy to: .forgejo/workflows/ci-smoke.yaml in consumer repos. +name: CI Smoke + +on: + push: + branches: + - main + workflow_dispatch: + +jobs: + host-smoke: + runs-on: self-hosted + steps: + - name: Routing probe (host runner) + run: | + set -eu + echo "repository=${GITHUB_REPOSITORY:-unknown}" + echo "sha=${GITHUB_SHA:-unknown}" + echo "runner=${RUNNER_NAME:-unknown}" + uname -a + + container-smoke: + runs-on: ubuntu-latest + steps: + - name: Routing probe (container label) + run: | + set -eu + echo "container-smoke ok for ${GITHUB_REPOSITORY:-unknown}" \ No newline at end of file diff --git a/workflows/container-build-push-multirepo.yaml b/workflows/container-build-push-multirepo.yaml new file mode 100644 index 0000000..3fbda0b --- /dev/null +++ b/workflows/container-build-push-multirepo.yaml @@ -0,0 +1,61 @@ +# Multi-repo Docker build template for tier-3 prep (e.g. state-hub + hub-core). +# Copy to: .forgejo/workflows/image.yaml and set PRIMARY_REPO + EXTRA_REPOS. +# Uses archive checkout (no actions/checkout; non-root runner has no git). +# Dockerfile must reference named contexts, e.g.: +# COPY --from=hub_core_src pyproject.toml /tmp/hub-core/pyproject.toml +name: Build and Publish Multi-Context Image + +on: + push: + branches: + - main + paths: + - ".forgejo/workflows/image.yaml" + - "Dockerfile" + workflow_dispatch: + +env: + REGISTRY: forgejo.coulomb.social + IMAGE_NAME: coulomb/REPLACE_ME + DOCKER_HOST: tcp://127.0.0.1:2375 + # Space-separated coulomb/repo@context_name entries for extra build contexts. + # Example: "coulomb/hub-core@hub_core_src" + EXTRA_REPOS: "coulomb/hub-core@hub_core_src" + +jobs: + build-and-push: + runs-on: container-build + steps: + - name: Build and push image + env: + REGISTRY_USER: ${{ secrets.REGISTRY_USER }} + REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }} + run: | + set -eu + REF="${GITHUB_SHA:-main}" + mkdir -p buildctx "${HOME}/bin" + wget -qO /tmp/primary.tar.gz \ + "https://forgejo.coulomb.social/${GITHUB_REPOSITORY}/archive/${REF}.tar.gz" + tar xzf /tmp/primary.tar.gz -C buildctx --strip-components=1 + BUILD_ARGS=() + for spec in ${EXTRA_REPOS}; do + repo="${spec%@*}" + ctx="${spec#*@}" + extra_ref="${REF}" + wget -qO "/tmp/${ctx}.tar.gz" \ + "https://forgejo.coulomb.social/${repo}/archive/${extra_ref}.tar.gz" + mkdir -p "/tmp/ctx-${ctx}" + tar xzf "/tmp/${ctx}.tar.gz" -C "/tmp/ctx-${ctx}" --strip-components=1 + BUILD_ARGS+=(--build-context "${ctx}=/tmp/ctx-${ctx}") + done + wget -qO- https://download.docker.com/linux/static/stable/x86_64/docker-27.3.1.tgz \ + | tar xz --strip-components=1 -C "${HOME}/bin" docker/docker + export PATH="${HOME}/bin:${PATH}" + echo "${REGISTRY_TOKEN}" | docker login "${REGISTRY}" -u "${REGISTRY_USER}" --password-stdin + SHORT="${REF:0:7}" + IMAGE="${REGISTRY}/${IMAGE_NAME}" + docker build "${BUILD_ARGS[@]}" \ + -t "${IMAGE}:latest" -t "${IMAGE}:main-${SHORT}" buildctx + docker push "${IMAGE}:latest" + docker push "${IMAGE}:main-${SHORT}" + echo "pushed ${IMAGE}:latest and ${IMAGE}:main-${SHORT}" \ No newline at end of file diff --git a/workflows/container-build-push.yaml b/workflows/container-build-push.yaml new file mode 100644 index 0000000..423c2b3 --- /dev/null +++ b/workflows/container-build-push.yaml @@ -0,0 +1,48 @@ +# Canonical single-repo image build template (tier 2). +# Copy to: .forgejo/workflows/image.yaml and set IMAGE_NAME. +# Requires org secrets: REGISTRY_USER, REGISTRY_TOKEN +# Runner label: container-build (DinD sidecar on railiance01-build-01) +name: Build and Publish Container Image + +on: + push: + branches: + - main + paths: + - ".forgejo/workflows/image.yaml" + - "Dockerfile" + - "src/**" + workflow_dispatch: + +env: + REGISTRY: forgejo.coulomb.social + # Set per repo, e.g. coulomb/key-cape + IMAGE_NAME: coulomb/REPLACE_ME + DOCKER_HOST: tcp://127.0.0.1:2375 + +jobs: + build-and-push: + runs-on: container-build + steps: + - name: Build and push image + env: + REGISTRY_USER: ${{ secrets.REGISTRY_USER }} + REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }} + run: | + set -eu + REF="${GITHUB_SHA:-main}" + mkdir -p buildctx "${HOME}/bin" + wget -qO /tmp/repo.tar.gz \ + "https://forgejo.coulomb.social/${GITHUB_REPOSITORY}/archive/${REF}.tar.gz" + tar xzf /tmp/repo.tar.gz -C buildctx --strip-components=1 + wget -qO- https://download.docker.com/linux/static/stable/x86_64/docker-27.3.1.tgz \ + | tar xz --strip-components=1 -C "${HOME}/bin" docker/docker + export PATH="${HOME}/bin:${PATH}" + docker version + echo "${REGISTRY_TOKEN}" | docker login "${REGISTRY}" -u "${REGISTRY_USER}" --password-stdin + SHORT="${REF:0:7}" + IMAGE="${REGISTRY}/${IMAGE_NAME}" + docker build -t "${IMAGE}:latest" -t "${IMAGE}:main-${SHORT}" buildctx + docker push "${IMAGE}:latest" + docker push "${IMAGE}:main-${SHORT}" + echo "pushed ${IMAGE}:latest and ${IMAGE}:main-${SHORT}" \ No newline at end of file