Files
nixfiles/.gitea/workflows/ci.yaml
Renovate Bot bd613ef07f
CI / flake (push) Skipped
renovate/stability-days Updates have not met minimum release age requirement
CI / flake (pull_request) Successful in 4m13s
chore(deps): update gitea actions to 13d8dd5
2026-08-13 15:01:13 +00:00

115 lines
5.1 KiB
YAML

# Flake CI. Formatting (treefmt) runs on *every* PR; the heavier Nix work
# (deadnix/statix/pre-commit lints + per-host evaluation) runs only when the
# change can affect it.
name: CI
# Deliberately no `paths:` filter. This job is a required status check on main,
# and a path-filtered workflow is *skipped* (never runs) for PRs that touch no
# matching file -- which leaves the required check pending forever and blocks the
# merge (e.g. a .renovaterc.json-only change). So the workflow always runs and
# always reports.
#
# Two tiers of checks:
# * Formatting always runs. treefmt covers Markdown, YAML, and JSON as well as
# Nix and shell, so a docs- or config-only PR must be format-checked too. It
# is cheap (no host evaluation).
# * The heavy steps (full `nix flake check` + host evals) run only when a .nix
# file, flake.lock, or this workflow changed; otherwise they skip and the job
# still passes, keeping the required check green-reportable.
on:
push:
branches: [main]
pull_request:
jobs:
flake:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
# Full history so the detect step can diff the PR against its base.
fetch-depth: 0
# Decide whether the *heavy* Nix steps need to run. On a pull_request, diff
# against the base for files that can affect them: any .nix, the lockfile,
# or this workflow. On any other event (push to main) always run. The
# formatting step below is unaffected -- it always runs.
- name: Detect Nix-relevant changes
id: detect
run: |
set -euo pipefail
if [ "${{ github.event_name }}" != "pull_request" ]; then
echo "Event ${{ github.event_name }}: running full checks."
echo "run=true" >> "$GITHUB_OUTPUT"
exit 0
fi
base='${{ github.event.pull_request.base.sha }}'
head='${{ github.event.pull_request.head.sha }}'
changed=$(git diff --name-only "$base...$head")
echo "Changed files:"
echo "$changed"
if echo "$changed" | grep -Eq '(\.nix$|^flake\.lock$|^\.gitea/workflows/ci\.yaml$)'; then
echo "Nix-relevant changes found: running heavy checks."
echo "run=true" >> "$GITHUB_OUTPUT"
else
echo "No Nix-relevant changes: heavy checks skip (formatting still runs)."
echo "run=false" >> "$GITHUB_OUTPUT"
fi
# Nix drives the formatting check, so install it unconditionally.
- name: Install Nix
uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31
with:
extra_nix_config: |
experimental-features = nix-command flakes
accept-flake-config = true
substituters = https://cache.nixos.org https://nix-community.cachix.org
trusted-public-keys = cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY= nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=
# Always run: treefmt formats Markdown/YAML/JSON (docs + config) as well as
# Nix and shell, so documentation-only PRs are format-checked too. This is
# the cheap gate (no host evaluation) and pre-builds the `formatting`
# derivation that the flake check below reuses from cache.
- name: Formatting check
run: nix build --print-build-logs '.#checks.x86_64-linux.formatting'
# Runs every flake check: treefmt formatting, deadnix, statix, and the
# pre-commit hooks (so a --no-verify commit can't ship unlinted).
- name: Flake check
if: steps.detect.outputs.run == 'true'
run: nix flake check --print-build-logs
# Evaluate (not build) each host's toplevel so eval errors fail CI cheaply.
# aarch64 / darwin hosts evaluate fine on an x86_64 runner; only building
# would need emulation, which we deliberately avoid here.
#
# Host lists are discovered from the flake (attrNames of
# nixos/darwinConfigurations) rather than hard-coded, so adding or removing
# a host needs no change to this workflow.
- name: Evaluate NixOS host configurations
if: steps.detect.outputs.run == 'true'
run: |
set -euo pipefail
hosts=$(nix eval --raw '.#nixosConfigurations' \
--apply 'cfgs: builtins.concatStringsSep "\n" (builtins.attrNames cfgs)')
for host in $hosts; do
echo "::group::eval $host"
nix eval --raw ".#nixosConfigurations.$host.config.system.build.toplevel.drvPath"
echo
echo "::endgroup::"
done
- name: Evaluate Darwin host configurations
if: steps.detect.outputs.run == 'true'
run: |
set -euo pipefail
hosts=$(nix eval --raw '.#darwinConfigurations' \
--apply 'cfgs: builtins.concatStringsSep "\n" (builtins.attrNames cfgs)')
for host in $hosts; do
echo "::group::eval $host"
nix eval --raw ".#darwinConfigurations.$host.config.system.build.toplevel.drvPath"
echo
echo "::endgroup::"
done