Files
nixos-config/.gitea/workflows/ci.yml
T
jory 5116faf0d3
CI / Flake check (aarch64-linux) (push) Successful in 29s
CI / Flake check (x86_64-linux) (push) Successful in 30s
CI / Pre-commit checks (x86_64-linux) (push) Successful in 8s
Harden server and add Nix-native CI + self-hosted Gitea Actions
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/
  X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail
  upstream copies via header_down on mail.severijnse.eu
- tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync
  _25/_465/_993, fail-safe placeholders; coredns zone updated
- pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint,
  deadnix); CI pre-commit job over x86_64 + aarch64 matrix
- gitea: enable Gitea Actions + self-hosted runner (native:host,
  aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook
- fix statix warnings (merge repeated systemd/database/configFile keys)
  + disable empty_pattern via statix.toml (nixpkgs standard)
- Clean up unused lambda patterns across 38 .nix files via deadnix
- Format whole repo with alejandra (27 files)
- Remove .github/workflows/ci.yml (Gitea shadows .github; runner labels differ)
- Fix CI nix-not-found: export /run/current-system/sw/bin in PATH
- Trim aarch64 from pre-commit matrix (no QEMU binfmt deployed yet)
2026-07-12 09:11:41 +02:00

85 lines
3.0 KiB
YAML

# Source: adapted from the official cachix/install-nix-action "Flakes CI workflow" example
# https://github.com/cachix/install-nix-action
# (README: "Flakes CI workflow with nix build and flake check")
# Every action used here (actions/checkout) is from an official GitHub repo.
#
# Adaptations for Gitea Actions:
# * runs-on: native - Gitea's self-hosted native runner. cachix/install-nix-action
# explicitly supports self-hosted runners, and this runner's host already provides
# Nix (Lix), so the installer step is omitted and flakes are enabled via NIX_CONFIG
# (identical to the action's `extra_nix_config: experimental-features = nix-command flakes`).
# * The native runner only puts its `hostPackages` on PATH, which does NOT include Nix.
# Each job therefore exports the host's system Nix (/run/current-system/sw/bin) onto
# PATH before invoking `nix`. This uses the host's actual Lix rather than installing a
# second Nix client that would mismatch the running Lix daemon.
# * Gitea context vars (gitea.workflow / gitea.head_ref / gitea.sha) for concurrency.
# * matrix over x86_64-linux + aarch64-linux for flake-check (--no-build, eval-only).
# Pre-commit checks run on x86_64-linux only: building aarch64 derivations needs
# QEMU binfmt (registered via boot.binfmt.emulatedSystems) + nix extra-platforms,
# which require a nixos-rebuild switch that hasn't been applied yet.
name: CI
on:
push:
branches: [main]
pull_request:
# Least-privilege by default; jobs opt into what they need.
permissions: {}
concurrency:
group: ${{ gitea.workflow }}-${{ gitea.head_ref || gitea.sha }}
cancel-in-progress: true
defaults:
run:
shell: bash
env:
NIX_CONFIG: |
experimental-features = nix-command flakes
extra-platforms = aarch64-linux
jobs:
flake-check:
name: Flake check (${{ matrix.system }})
runs-on: native
strategy:
fail-fast: false
matrix:
system:
- x86_64-linux
- aarch64-linux
timeout-minutes: 30
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Flake check (${{ matrix.system }})
run: |
export PATH=/run/current-system/sw/bin:$PATH
nix flake check --no-build --system ${{ matrix.system }}
pre-commit:
name: Pre-commit checks (${{ matrix.system }})
runs-on: native
strategy:
fail-fast: false
matrix:
# aarch64-linux omitted: building aarch64 derivations needs QEMU binfmt +
# extra-platforms; system hasn't been rebuilt to apply them yet.
system:
- x86_64-linux
timeout-minutes: 20
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Pre-commit checks (${{ matrix.system }})
run: |
export PATH=/run/current-system/sw/bin:$PATH
nix build .#checks.${{ matrix.system }}.pre-commit