Harden server and add Nix-native CI + self-hosted Gitea Actions
CI / Flake check (aarch64-linux) (push) Successful in 32s
CI / Flake check (x86_64-linux) (push) Successful in 32s
CI / Pre-commit checks (x86_64-linux) (push) Successful in 10s

- Add self-hosted Gitea Actions runner module (servers/hetzner/modules/services/gitea.nix)
- Add CI workflow (.gitea/workflows/ci.yml):
  - Flake check (x86_64-linux + aarch64-linux, eval-only)
  - Pre-commit checks (x86_64-linux only)
  - Gitea-native runner (no Docker); Nix from host PATH
  - NIX_CONFIG enables flakes + extra-platforms
- Remove redundant .github/workflows/ci.yml (shadows .gitea)
- Enable deadnix in pre-commit hooks (flake.nix), fix 38 files
- Add statix.toml disabling empty_pattern lint (nixpkgs standard)
- Format whole repo with alejandra (27 files)
- Fix CI nix-not-found: export /run/current-system/sw/bin in PATH
- Remove aarch64 from pre-commit matrix (no QEMU binfmt deployed yet)
This commit is contained in:
2026-07-12 01:45:33 +02:00
parent 7ed54e51a2
commit ff31b21a74
41 changed files with 104 additions and 292 deletions
+6 -6
View File
@@ -35,14 +35,14 @@
statix = {
enable = true;
# hardware-configuration.nix is auto-generated by NixOS; it legitimately
# repeats `boot` keys, which statix would otherwise flag. Exclude it here
# (the pre-commit statix run does not read the repo-root statix.toml).
# repeats `boot` keys, which statix would otherwise flag. Exclude it here.
settings.ignore = ["hardware-configuration.nix"];
# Lint config (statix.toml at repo root). Disables `empty_pattern`, which
# flags the standard NixOS `{ ... }:` module pattern that nixpkgs likewise
# permits.
settings.config = "./statix.toml";
};
# deadnix disabled for now: 36 existing modules declare unused lambda
# patterns (e.g. `config`/`lib`/`pkgs`/`inputs` in args). Re-enable once
# that cleanup lands so `nix build .#checks.<system>.pre-commit` stays green.
deadnix.enable = false;
deadnix.enable = true;
actionlint.enable = true;
trim-trailing-whitespace.enable = true;
end-of-file-fixer.enable = true;