5116faf0d3
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/ X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail upstream copies via header_down on mail.severijnse.eu - tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync _25/_465/_993, fail-safe placeholders; coredns zone updated - pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint, deadnix); CI pre-commit job over x86_64 + aarch64 matrix - gitea: enable Gitea Actions + self-hosted runner (native:host, aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook - fix statix warnings (merge repeated systemd/database/configFile keys) + disable empty_pattern via statix.toml (nixpkgs standard) - Clean up unused lambda patterns across 38 .nix files via deadnix - Format whole repo with alejandra (27 files) - Remove .github/workflows/ci.yml (Gitea shadows .github; runner labels differ) - Fix CI nix-not-found: export /run/current-system/sw/bin in PATH - Trim aarch64 from pre-commit matrix (no QEMU binfmt deployed yet)
85 lines
3.0 KiB
YAML
85 lines
3.0 KiB
YAML
# Source: adapted from the official cachix/install-nix-action "Flakes CI workflow" example
|
|
# https://github.com/cachix/install-nix-action
|
|
# (README: "Flakes CI workflow with nix build and flake check")
|
|
# Every action used here (actions/checkout) is from an official GitHub repo.
|
|
#
|
|
# Adaptations for Gitea Actions:
|
|
# * runs-on: native - Gitea's self-hosted native runner. cachix/install-nix-action
|
|
# explicitly supports self-hosted runners, and this runner's host already provides
|
|
# Nix (Lix), so the installer step is omitted and flakes are enabled via NIX_CONFIG
|
|
# (identical to the action's `extra_nix_config: experimental-features = nix-command flakes`).
|
|
# * The native runner only puts its `hostPackages` on PATH, which does NOT include Nix.
|
|
# Each job therefore exports the host's system Nix (/run/current-system/sw/bin) onto
|
|
# PATH before invoking `nix`. This uses the host's actual Lix rather than installing a
|
|
# second Nix client that would mismatch the running Lix daemon.
|
|
# * Gitea context vars (gitea.workflow / gitea.head_ref / gitea.sha) for concurrency.
|
|
# * matrix over x86_64-linux + aarch64-linux for flake-check (--no-build, eval-only).
|
|
# Pre-commit checks run on x86_64-linux only: building aarch64 derivations needs
|
|
# QEMU binfmt (registered via boot.binfmt.emulatedSystems) + nix extra-platforms,
|
|
# which require a nixos-rebuild switch that hasn't been applied yet.
|
|
|
|
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
|
|
# Least-privilege by default; jobs opt into what they need.
|
|
permissions: {}
|
|
|
|
concurrency:
|
|
group: ${{ gitea.workflow }}-${{ gitea.head_ref || gitea.sha }}
|
|
cancel-in-progress: true
|
|
|
|
defaults:
|
|
run:
|
|
shell: bash
|
|
|
|
env:
|
|
NIX_CONFIG: |
|
|
experimental-features = nix-command flakes
|
|
extra-platforms = aarch64-linux
|
|
|
|
jobs:
|
|
flake-check:
|
|
name: Flake check (${{ matrix.system }})
|
|
runs-on: native
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
system:
|
|
- x86_64-linux
|
|
- aarch64-linux
|
|
timeout-minutes: 30
|
|
steps:
|
|
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Flake check (${{ matrix.system }})
|
|
run: |
|
|
export PATH=/run/current-system/sw/bin:$PATH
|
|
nix flake check --no-build --system ${{ matrix.system }}
|
|
|
|
pre-commit:
|
|
name: Pre-commit checks (${{ matrix.system }})
|
|
runs-on: native
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
# aarch64-linux omitted: building aarch64 derivations needs QEMU binfmt +
|
|
# extra-platforms; system hasn't been rebuilt to apply them yet.
|
|
system:
|
|
- x86_64-linux
|
|
timeout-minutes: 20
|
|
steps:
|
|
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Pre-commit checks (${{ matrix.system }})
|
|
run: |
|
|
export PATH=/run/current-system/sw/bin:$PATH
|
|
nix build .#checks.${{ matrix.system }}.pre-commit
|