Compare commits
6
Commits
STAT-115
...
53165c2d53
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
53165c2d53 | ||
|
|
9df18983c3 | ||
|
|
3f7c00f1e7 | ||
|
|
dcb3434b39 | ||
|
|
b865cdd697 | ||
|
|
4300baaa19 |
@@ -1,7 +1,6 @@
|
|||||||
ACTIONS := \
|
ACTIONS := \
|
||||||
docker \
|
docker \
|
||||||
node \
|
node \
|
||||||
claude/check-shared-block \
|
|
||||||
git/create_tag \
|
git/create_tag \
|
||||||
git/promotion-gate \
|
git/promotion-gate \
|
||||||
helm/diff \
|
helm/diff \
|
||||||
|
|||||||
@@ -4,12 +4,6 @@ Reusable composite actions for Gitea CI/CD pipelines.
|
|||||||
|
|
||||||
## Actions
|
## Actions
|
||||||
|
|
||||||
### Claude
|
|
||||||
|
|
||||||
| Action | Description |
|
|
||||||
|---|---|
|
|
||||||
| [claude/check-shared-block](claude/check-shared-block/README.md) | Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra |
|
|
||||||
|
|
||||||
### Docker
|
### Docker
|
||||||
|
|
||||||
| Action | Description |
|
| Action | Description |
|
||||||
|
|||||||
@@ -1,44 +0,0 @@
|
|||||||
# Check Shared CLAUDE.md Block
|
|
||||||
|
|
||||||
<!-- action-docs-description source="action.yml" -->
|
|
||||||
## Description
|
|
||||||
|
|
||||||
Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra
|
|
||||||
<!-- action-docs-description source="action.yml" -->
|
|
||||||
|
|
||||||
<!-- action-docs-inputs source="action.yml" -->
|
|
||||||
## Inputs
|
|
||||||
|
|
||||||
| name | description | required | default |
|
|
||||||
| --- | --- | --- | --- |
|
|
||||||
| `TARGET` | <p>Path to the CLAUDE.md file to check</p> | `false` | `CLAUDE.md` |
|
|
||||||
| `CANONICAL_URL` | <p>Raw URL of the canonical shared fragment</p> | `false` | `https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md` |
|
|
||||||
| `GITEA_TOKEN` | <p>Gitea token with read access to stat-tackler-infra, if it is private</p> | `false` | `""` |
|
|
||||||
<!-- action-docs-inputs source="action.yml" -->
|
|
||||||
|
|
||||||
<!-- action-docs-runs source="action.yml" -->
|
|
||||||
## Runs
|
|
||||||
|
|
||||||
This action is a `composite` action.
|
|
||||||
<!-- action-docs-runs source="action.yml" -->
|
|
||||||
|
|
||||||
## Running locally
|
|
||||||
|
|
||||||
The check logic has no dependency on the composite action wrapper beyond
|
|
||||||
`curl`, `awk`, and `diff` on `PATH`. From a repo's root:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
CANONICAL_URL=https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md \
|
|
||||||
TARGET=CLAUDE.md sh -c '
|
|
||||||
extract() { awk "/<!-- SHARED:BEGIN/{f=1} f{print} /SHARED:END -->/{f=0}" "$1"; }
|
|
||||||
tmp=$(mktemp)
|
|
||||||
curl -sfSL "$CANONICAL_URL" -o "$tmp"
|
|
||||||
extract "$tmp" > "$tmp.canon"
|
|
||||||
extract "$TARGET" > "$tmp.mine"
|
|
||||||
diff -u "$tmp.canon" "$tmp.mine" && echo "matches canonical"
|
|
||||||
rm -f "$tmp" "$tmp.canon" "$tmp.mine"
|
|
||||||
'
|
|
||||||
```
|
|
||||||
|
|
||||||
`GITEA_TOKEN` is only needed if `stat-tackler-infra` becomes private; it is
|
|
||||||
otherwise safe to omit.
|
|
||||||
@@ -1,75 +0,0 @@
|
|||||||
name: Check Shared CLAUDE.md Block
|
|
||||||
description: Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra
|
|
||||||
|
|
||||||
inputs:
|
|
||||||
TARGET:
|
|
||||||
description: "Path to the CLAUDE.md file to check"
|
|
||||||
default: "CLAUDE.md"
|
|
||||||
CANONICAL_URL:
|
|
||||||
description: "Raw URL of the canonical shared fragment"
|
|
||||||
default: "https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md"
|
|
||||||
GITEA_TOKEN:
|
|
||||||
description: "Gitea token with read access to stat-tackler-infra, if it is private"
|
|
||||||
default: ""
|
|
||||||
|
|
||||||
runs:
|
|
||||||
using: composite
|
|
||||||
steps:
|
|
||||||
- name: Checkout
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Check shared CLAUDE.md block
|
|
||||||
shell: sh
|
|
||||||
env:
|
|
||||||
TARGET: ${{ inputs.TARGET }}
|
|
||||||
CANONICAL_URL: ${{ inputs.CANONICAL_URL }}
|
|
||||||
GITEA_TOKEN: ${{ inputs.GITEA_TOKEN }}
|
|
||||||
run: |
|
|
||||||
set -e
|
|
||||||
|
|
||||||
if [ ! -f "$TARGET" ]; then
|
|
||||||
echo "::error::$TARGET not found"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
extract() {
|
|
||||||
# Everything between the markers, markers included.
|
|
||||||
awk '/<!-- SHARED:BEGIN/{f=1} f{print} /SHARED:END -->/{f=0}' "$1"
|
|
||||||
}
|
|
||||||
|
|
||||||
mine=$(extract "$TARGET")
|
|
||||||
if [ -z "$mine" ]; then
|
|
||||||
echo "::error::$TARGET has no SHARED:BEGIN/SHARED:END block."
|
|
||||||
echo "Copy it from $CANONICAL_URL"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
tmp=$(mktemp)
|
|
||||||
if [ -n "$GITEA_TOKEN" ]; then
|
|
||||||
curl -sfSL -H "Authorization: token $GITEA_TOKEN" "$CANONICAL_URL" -o "$tmp"
|
|
||||||
else
|
|
||||||
curl -sfSL "$CANONICAL_URL" -o "$tmp"
|
|
||||||
fi
|
|
||||||
|
|
||||||
theirs=$(extract "$tmp")
|
|
||||||
if [ -z "$theirs" ]; then
|
|
||||||
echo "::error::Could not read the canonical block from $CANONICAL_URL"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ "$mine" = "$theirs" ]; then
|
|
||||||
echo "Shared CLAUDE.md block matches the canonical copy."
|
|
||||||
rm -f "$tmp"
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "::error::The shared CLAUDE.md block has drifted from the canonical copy."
|
|
||||||
echo "Canonical: $CANONICAL_URL"
|
|
||||||
echo
|
|
||||||
echo "--- canonical"
|
|
||||||
echo "+++ $TARGET"
|
|
||||||
printf '%s\n' "$theirs" > "$tmp.canon"
|
|
||||||
printf '%s\n' "$mine" > "$tmp.mine"
|
|
||||||
diff -u "$tmp.canon" "$tmp.mine" || true
|
|
||||||
rm -f "$tmp" "$tmp.canon" "$tmp.mine"
|
|
||||||
exit 1
|
|
||||||
@@ -19,6 +19,7 @@ Install dependencies, build, and upload a build artifact
|
|||||||
| `COPY_PRISMA_ENGINE` | <p>Copy the Prisma query engine binaries into the build directory</p> | `false` | `false` |
|
| `COPY_PRISMA_ENGINE` | <p>Copy the Prisma query engine binaries into the build directory</p> | `false` | `false` |
|
||||||
| `WORKING_DIRECTORY` | <p>Working directory for install, build, and artifact steps</p> | `false` | `.` |
|
| `WORKING_DIRECTORY` | <p>Working directory for install, build, and artifact steps</p> | `false` | `.` |
|
||||||
| `UPLOAD_ARTIFACT` | <p>Whether to upload the build artifact</p> | `false` | `true` |
|
| `UPLOAD_ARTIFACT` | <p>Whether to upload the build artifact</p> | `false` | `true` |
|
||||||
|
| `NPM_TOKEN` | <p>Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages.</p> | `false` | `""` |
|
||||||
<!-- action-docs-inputs source="action.yml" -->
|
<!-- action-docs-inputs source="action.yml" -->
|
||||||
|
|
||||||
<!-- action-docs-runs source="action.yml" -->
|
<!-- action-docs-runs source="action.yml" -->
|
||||||
|
|||||||
@@ -25,6 +25,9 @@ inputs:
|
|||||||
UPLOAD_ARTIFACT:
|
UPLOAD_ARTIFACT:
|
||||||
description: "Whether to upload the build artifact"
|
description: "Whether to upload the build artifact"
|
||||||
default: "true"
|
default: "true"
|
||||||
|
NPM_TOKEN:
|
||||||
|
description: "Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages."
|
||||||
|
default: ""
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: composite
|
using: composite
|
||||||
@@ -36,6 +39,16 @@ runs:
|
|||||||
with:
|
with:
|
||||||
node-version-file: ${{ inputs.WORKING_DIRECTORY }}/package.json
|
node-version-file: ${{ inputs.WORKING_DIRECTORY }}/package.json
|
||||||
|
|
||||||
|
- name: Configure private registry auth
|
||||||
|
if: inputs.NPM_TOKEN != ''
|
||||||
|
shell: sh
|
||||||
|
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||||
|
run: |
|
||||||
|
printf '%s\n%s\n' \
|
||||||
|
'@stat-tackler:registry=https://gitea.pixelparasol.com/api/packages/stat-tackler/npm/' \
|
||||||
|
'//gitea.pixelparasol.com/api/packages/stat-tackler/npm/:_authToken=${{ inputs.NPM_TOKEN }}' \
|
||||||
|
>> .npmrc
|
||||||
|
|
||||||
- name: Install
|
- name: Install
|
||||||
shell: sh
|
shell: sh
|
||||||
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||||
|
|||||||
@@ -10,6 +10,7 @@ Composite action: install dependencies and run an npm test script.
|
|||||||
| `TEST_SCRIPT` | npm script to run (must exist in `package.json`) | `test` |
|
| `TEST_SCRIPT` | npm script to run (must exist in `package.json`) | `test` |
|
||||||
| `TEST_ARGS` | Additional arguments passed after `--` to the test script | `` |
|
| `TEST_ARGS` | Additional arguments passed after `--` to the test script | `` |
|
||||||
| `WORKING_DIRECTORY` | Directory to run commands in | `.` |
|
| `WORKING_DIRECTORY` | Directory to run commands in | `.` |
|
||||||
|
| `NPM_TOKEN` | Auth token for the private Gitea npm registry (`@stat-tackler` scope). Leave empty if the repo installs no private packages. | `` |
|
||||||
|
|
||||||
## Usage
|
## Usage
|
||||||
|
|
||||||
@@ -19,6 +20,15 @@ Composite action: install dependencies and run an npm test script.
|
|||||||
TEST_SCRIPT: test:unit
|
TEST_SCRIPT: test:unit
|
||||||
```
|
```
|
||||||
|
|
||||||
|
With a private `@stat-tackler` package in `package.json`:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- uses: stat-tackler/stat-tackler-infra/test/npm@main
|
||||||
|
with:
|
||||||
|
TEST_SCRIPT: test:unit
|
||||||
|
NPM_TOKEN: ${{ secrets.REGISTRY_READ_WRITE_AGENT }}
|
||||||
|
```
|
||||||
|
|
||||||
With extra args:
|
With extra args:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
|
|||||||
@@ -14,6 +14,9 @@ inputs:
|
|||||||
WORKING_DIRECTORY:
|
WORKING_DIRECTORY:
|
||||||
description: "Directory to run commands in"
|
description: "Directory to run commands in"
|
||||||
default: "."
|
default: "."
|
||||||
|
NPM_TOKEN:
|
||||||
|
description: "Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages."
|
||||||
|
default: ""
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: composite
|
using: composite
|
||||||
@@ -32,6 +35,16 @@ runs:
|
|||||||
key: node-modules-${{ hashFiles(format('{0}/package-lock.json', inputs.WORKING_DIRECTORY)) }}
|
key: node-modules-${{ hashFiles(format('{0}/package-lock.json', inputs.WORKING_DIRECTORY)) }}
|
||||||
restore-keys: node-modules-
|
restore-keys: node-modules-
|
||||||
|
|
||||||
|
- name: Configure private registry auth
|
||||||
|
if: inputs.NPM_TOKEN != ''
|
||||||
|
shell: sh
|
||||||
|
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||||
|
run: |
|
||||||
|
printf '%s\n%s\n' \
|
||||||
|
'@stat-tackler:registry=https://gitea.pixelparasol.com/api/packages/stat-tackler/npm/' \
|
||||||
|
'//gitea.pixelparasol.com/api/packages/stat-tackler/npm/:_authToken=${{ inputs.NPM_TOKEN }}' \
|
||||||
|
>> .npmrc
|
||||||
|
|
||||||
- name: Install
|
- name: Install
|
||||||
shell: sh
|
shell: sh
|
||||||
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||||
|
|||||||
Reference in New Issue
Block a user