659912e0af
CI workflow gates on nixfmt formatting and evaluates all three host toplevels (aarch64 evaluates without emulation; no full builds in CI). renovate.json enables the nix manager and weekly lockFileMaintenance for flake.lock, plus grouped github-actions updates (Renovate matches .gitea/workflows). A self-hosted Renovate workflow runs it on Gitea, since Gitea has no built-in Renovate; it needs a RENOVATE_TOKEN secret.
38 lines
1.1 KiB
YAML
38 lines
1.1 KiB
YAML
# Flake CI: formatting gate + evaluation of every host configuration.
|
|
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
|
|
jobs:
|
|
flake:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Install Nix
|
|
uses: cachix/install-nix-action@v30
|
|
with:
|
|
extra_nix_config: |
|
|
experimental-features = nix-command flakes
|
|
accept-flake-config = true
|
|
|
|
- name: Check formatting
|
|
run: nix build --print-build-logs '.#checks.x86_64-linux.formatting'
|
|
|
|
# Evaluate (not build) each host's toplevel so eval errors fail CI cheaply.
|
|
# aarch64 hosts evaluate fine on an x86_64 runner; only building would need
|
|
# emulation, which we deliberately avoid here.
|
|
- name: Evaluate host configurations
|
|
run: |
|
|
set -euo pipefail
|
|
for host in lyrathorpe-mbp lyrathorpe-x1c emmathorpe-edaas; do
|
|
echo "::group::eval $host"
|
|
nix eval --raw ".#nixosConfigurations.$host.config.system.build.toplevel.drvPath"
|
|
echo
|
|
echo "::endgroup::"
|
|
done
|