Files
nixos-config/.gitea/workflows/ci.yml
T
jory ff31b21a74
CI / Flake check (aarch64-linux) (push) Successful in 32s
CI / Flake check (x86_64-linux) (push) Successful in 32s
CI / Pre-commit checks (x86_64-linux) (push) Successful in 10s
Harden server and add Nix-native CI + self-hosted Gitea Actions
- Add self-hosted Gitea Actions runner module (servers/hetzner/modules/services/gitea.nix)
- Add CI workflow (.gitea/workflows/ci.yml):
  - Flake check (x86_64-linux + aarch64-linux, eval-only)
  - Pre-commit checks (x86_64-linux only)
  - Gitea-native runner (no Docker); Nix from host PATH
  - NIX_CONFIG enables flakes + extra-platforms
- Remove redundant .github/workflows/ci.yml (shadows .gitea)
- Enable deadnix in pre-commit hooks (flake.nix), fix 38 files
- Add statix.toml disabling empty_pattern lint (nixpkgs standard)
- Format whole repo with alejandra (27 files)
- Fix CI nix-not-found: export /run/current-system/sw/bin in PATH
- Remove aarch64 from pre-commit matrix (no QEMU binfmt deployed yet)
2026-07-12 08:24:14 +02:00

85 lines
3.0 KiB
YAML

# Source: adapted from the official cachix/install-nix-action "Flakes CI workflow" example
# https://github.com/cachix/install-nix-action
# (README: "Flakes CI workflow with nix build and flake check")
# Every action used here (actions/checkout) is from an official GitHub repo.
#
# Adaptations for Gitea Actions:
# * runs-on: native - Gitea's self-hosted native runner. cachix/install-nix-action
# explicitly supports self-hosted runners, and this runner's host already provides
# Nix (Lix), so the installer step is omitted and flakes are enabled via NIX_CONFIG
# (identical to the action's `extra_nix_config: experimental-features = nix-command flakes`).
# * The native runner only puts its `hostPackages` on PATH, which does NOT include Nix.
# Each job therefore exports the host's system Nix (/run/current-system/sw/bin) onto
# PATH before invoking `nix`. This uses the host's actual Lix rather than installing a
# second Nix client that would mismatch the running Lix daemon.
# * Gitea context vars (gitea.workflow / gitea.head_ref / gitea.sha) for concurrency.
# * matrix over x86_64-linux + aarch64-linux for flake-check (--no-build, eval-only).
# Pre-commit checks run on x86_64-linux only: building aarch64 derivations needs
# QEMU binfmt (registered via boot.binfmt.emulatedSystems) + nix extra-platforms,
# which require a nixos-rebuild switch that hasn't been applied yet.
name: CI
on:
push:
branches: [main]
pull_request:
# Least-privilege by default; jobs opt into what they need.
permissions: {}
concurrency:
group: ${{ gitea.workflow }}-${{ gitea.head_ref || gitea.sha }}
cancel-in-progress: true
defaults:
run:
shell: bash
env:
NIX_CONFIG: |
experimental-features = nix-command flakes
extra-platforms = aarch64-linux
jobs:
flake-check:
name: Flake check (${{ matrix.system }})
runs-on: native
strategy:
fail-fast: false
matrix:
system:
- x86_64-linux
- aarch64-linux
timeout-minutes: 30
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Flake check (${{ matrix.system }})
run: |
export PATH=/run/current-system/sw/bin:$PATH
nix flake check --no-build --system ${{ matrix.system }}
pre-commit:
name: Pre-commit checks (${{ matrix.system }})
runs-on: native
strategy:
fail-fast: false
matrix:
# aarch64-linux omitted: building aarch64 derivations needs QEMU binfmt +
# extra-platforms; system hasn't been rebuilt to apply them yet.
system:
- x86_64-linux
timeout-minutes: 20
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Pre-commit checks (${{ matrix.system }})
run: |
export PATH=/run/current-system/sw/bin:$PATH
nix build .#checks.${{ matrix.system }}.pre-commit