Compare commits
6
Commits
4300baaa19
...
v1.22.0
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
02b8ae8a72 | ||
|
|
53165c2d53 | ||
|
|
9df18983c3 | ||
|
|
3f7c00f1e7 | ||
|
|
dcb3434b39 | ||
|
|
b865cdd697 |
@@ -1,7 +1,6 @@
|
||||
ACTIONS := \
|
||||
docker \
|
||||
node \
|
||||
claude/check-shared-block \
|
||||
git/create_tag \
|
||||
git/promotion-gate \
|
||||
helm/diff \
|
||||
|
||||
@@ -4,12 +4,6 @@ Reusable composite actions for Gitea CI/CD pipelines.
|
||||
|
||||
## Actions
|
||||
|
||||
### Claude
|
||||
|
||||
| Action | Description |
|
||||
|---|---|
|
||||
| [claude/check-shared-block](claude/check-shared-block/README.md) | Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra |
|
||||
|
||||
### Docker
|
||||
|
||||
| Action | Description |
|
||||
|
||||
@@ -1,44 +0,0 @@
|
||||
# Check Shared CLAUDE.md Block
|
||||
|
||||
<!-- action-docs-description source="action.yml" -->
|
||||
## Description
|
||||
|
||||
Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra
|
||||
<!-- action-docs-description source="action.yml" -->
|
||||
|
||||
<!-- action-docs-inputs source="action.yml" -->
|
||||
## Inputs
|
||||
|
||||
| name | description | required | default |
|
||||
| --- | --- | --- | --- |
|
||||
| `TARGET` | <p>Path to the CLAUDE.md file to check</p> | `false` | `CLAUDE.md` |
|
||||
| `CANONICAL_URL` | <p>Raw URL of the canonical shared fragment</p> | `false` | `https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md` |
|
||||
| `GITEA_TOKEN` | <p>Gitea token with read access to stat-tackler-infra, if it is private</p> | `false` | `""` |
|
||||
<!-- action-docs-inputs source="action.yml" -->
|
||||
|
||||
<!-- action-docs-runs source="action.yml" -->
|
||||
## Runs
|
||||
|
||||
This action is a `composite` action.
|
||||
<!-- action-docs-runs source="action.yml" -->
|
||||
|
||||
## Running locally
|
||||
|
||||
The check logic has no dependency on the composite action wrapper beyond
|
||||
`curl`, `awk`, and `diff` on `PATH`. From a repo's root:
|
||||
|
||||
```bash
|
||||
CANONICAL_URL=https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md \
|
||||
TARGET=CLAUDE.md sh -c '
|
||||
extract() { awk "/<!-- SHARED:BEGIN/{f=1} f{print} /SHARED:END -->/{f=0}" "$1"; }
|
||||
tmp=$(mktemp)
|
||||
curl -sfSL "$CANONICAL_URL" -o "$tmp"
|
||||
extract "$tmp" > "$tmp.canon"
|
||||
extract "$TARGET" > "$tmp.mine"
|
||||
diff -u "$tmp.canon" "$tmp.mine" && echo "matches canonical"
|
||||
rm -f "$tmp" "$tmp.canon" "$tmp.mine"
|
||||
'
|
||||
```
|
||||
|
||||
`GITEA_TOKEN` is only needed if `stat-tackler-infra` becomes private; it is
|
||||
otherwise safe to omit.
|
||||
@@ -1,75 +0,0 @@
|
||||
name: Check Shared CLAUDE.md Block
|
||||
description: Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra
|
||||
|
||||
inputs:
|
||||
TARGET:
|
||||
description: "Path to the CLAUDE.md file to check"
|
||||
default: "CLAUDE.md"
|
||||
CANONICAL_URL:
|
||||
description: "Raw URL of the canonical shared fragment"
|
||||
default: "https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md"
|
||||
GITEA_TOKEN:
|
||||
description: "Gitea token with read access to stat-tackler-infra, if it is private"
|
||||
default: ""
|
||||
|
||||
runs:
|
||||
using: composite
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Check shared CLAUDE.md block
|
||||
shell: sh
|
||||
env:
|
||||
TARGET: ${{ inputs.TARGET }}
|
||||
CANONICAL_URL: ${{ inputs.CANONICAL_URL }}
|
||||
GITEA_TOKEN: ${{ inputs.GITEA_TOKEN }}
|
||||
run: |
|
||||
set -e
|
||||
|
||||
if [ ! -f "$TARGET" ]; then
|
||||
echo "::error::$TARGET not found"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
extract() {
|
||||
# Everything between the markers, markers included.
|
||||
awk '/<!-- SHARED:BEGIN/{f=1} f{print} /SHARED:END -->/{f=0}' "$1"
|
||||
}
|
||||
|
||||
mine=$(extract "$TARGET")
|
||||
if [ -z "$mine" ]; then
|
||||
echo "::error::$TARGET has no SHARED:BEGIN/SHARED:END block."
|
||||
echo "Copy it from $CANONICAL_URL"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
tmp=$(mktemp)
|
||||
if [ -n "$GITEA_TOKEN" ]; then
|
||||
curl -sfSL -H "Authorization: token $GITEA_TOKEN" "$CANONICAL_URL" -o "$tmp"
|
||||
else
|
||||
curl -sfSL "$CANONICAL_URL" -o "$tmp"
|
||||
fi
|
||||
|
||||
theirs=$(extract "$tmp")
|
||||
if [ -z "$theirs" ]; then
|
||||
echo "::error::Could not read the canonical block from $CANONICAL_URL"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ "$mine" = "$theirs" ]; then
|
||||
echo "Shared CLAUDE.md block matches the canonical copy."
|
||||
rm -f "$tmp"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
echo "::error::The shared CLAUDE.md block has drifted from the canonical copy."
|
||||
echo "Canonical: $CANONICAL_URL"
|
||||
echo
|
||||
echo "--- canonical"
|
||||
echo "+++ $TARGET"
|
||||
printf '%s\n' "$theirs" > "$tmp.canon"
|
||||
printf '%s\n' "$mine" > "$tmp.mine"
|
||||
diff -u "$tmp.canon" "$tmp.mine" || true
|
||||
rm -f "$tmp" "$tmp.canon" "$tmp.mine"
|
||||
exit 1
|
||||
@@ -19,6 +19,7 @@ Install dependencies, build, and upload a build artifact
|
||||
| `COPY_PRISMA_ENGINE` | <p>Copy the Prisma query engine binaries into the build directory</p> | `false` | `false` |
|
||||
| `WORKING_DIRECTORY` | <p>Working directory for install, build, and artifact steps</p> | `false` | `.` |
|
||||
| `UPLOAD_ARTIFACT` | <p>Whether to upload the build artifact</p> | `false` | `true` |
|
||||
| `NPM_TOKEN` | <p>Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages.</p> | `false` | `""` |
|
||||
<!-- action-docs-inputs source="action.yml" -->
|
||||
|
||||
<!-- action-docs-runs source="action.yml" -->
|
||||
|
||||
@@ -25,6 +25,9 @@ inputs:
|
||||
UPLOAD_ARTIFACT:
|
||||
description: "Whether to upload the build artifact"
|
||||
default: "true"
|
||||
NPM_TOKEN:
|
||||
description: "Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages."
|
||||
default: ""
|
||||
|
||||
runs:
|
||||
using: composite
|
||||
@@ -36,6 +39,16 @@ runs:
|
||||
with:
|
||||
node-version-file: ${{ inputs.WORKING_DIRECTORY }}/package.json
|
||||
|
||||
- name: Configure private registry auth
|
||||
if: inputs.NPM_TOKEN != ''
|
||||
shell: sh
|
||||
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||
run: |
|
||||
printf '%s\n%s\n' \
|
||||
'@stat-tackler:registry=https://gitea.pixelparasol.com/api/packages/stat-tackler/npm/' \
|
||||
'//gitea.pixelparasol.com/api/packages/stat-tackler/npm/:_authToken=${{ inputs.NPM_TOKEN }}' \
|
||||
>> .npmrc
|
||||
|
||||
- name: Install
|
||||
shell: sh
|
||||
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||
|
||||
@@ -10,6 +10,7 @@ Composite action: install dependencies and run an npm test script.
|
||||
| `TEST_SCRIPT` | npm script to run (must exist in `package.json`) | `test` |
|
||||
| `TEST_ARGS` | Additional arguments passed after `--` to the test script | `` |
|
||||
| `WORKING_DIRECTORY` | Directory to run commands in | `.` |
|
||||
| `NPM_TOKEN` | Auth token for the private Gitea npm registry (`@stat-tackler` scope). Leave empty if the repo installs no private packages. | `` |
|
||||
|
||||
## Usage
|
||||
|
||||
@@ -19,6 +20,15 @@ Composite action: install dependencies and run an npm test script.
|
||||
TEST_SCRIPT: test:unit
|
||||
```
|
||||
|
||||
With a private `@stat-tackler` package in `package.json`:
|
||||
|
||||
```yaml
|
||||
- uses: stat-tackler/stat-tackler-infra/test/npm@main
|
||||
with:
|
||||
TEST_SCRIPT: test:unit
|
||||
NPM_TOKEN: ${{ secrets.REGISTRY_READ_WRITE_AGENT }}
|
||||
```
|
||||
|
||||
With extra args:
|
||||
|
||||
```yaml
|
||||
|
||||
@@ -14,6 +14,9 @@ inputs:
|
||||
WORKING_DIRECTORY:
|
||||
description: "Directory to run commands in"
|
||||
default: "."
|
||||
NPM_TOKEN:
|
||||
description: "Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages."
|
||||
default: ""
|
||||
|
||||
runs:
|
||||
using: composite
|
||||
@@ -32,6 +35,16 @@ runs:
|
||||
key: node-modules-${{ hashFiles(format('{0}/package-lock.json', inputs.WORKING_DIRECTORY)) }}
|
||||
restore-keys: node-modules-
|
||||
|
||||
- name: Configure private registry auth
|
||||
if: inputs.NPM_TOKEN != ''
|
||||
shell: sh
|
||||
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||
run: |
|
||||
printf '%s\n%s\n' \
|
||||
'@stat-tackler:registry=https://gitea.pixelparasol.com/api/packages/stat-tackler/npm/' \
|
||||
'//gitea.pixelparasol.com/api/packages/stat-tackler/npm/:_authToken=${{ inputs.NPM_TOKEN }}' \
|
||||
>> .npmrc
|
||||
|
||||
- name: Install
|
||||
shell: sh
|
||||
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||
|
||||
Reference in New Issue
Block a user