Compare commits

..
22 Commits
Author SHA1 Message Date
gitea-actions 02b8ae8a72 chore: bump version [skip ci] 2026-09-17 15:49:56 +00:00
deac 53165c2d53 Merge pull request 'Add NPM_TOKEN support to node and test/npm actions' (#2) from STAT-133 into main
publish.yaml / publish (push) Successful in 4s
Reviewed-on: #2
2026-09-17 15:49:51 +00:00
deac 9df18983c3 STAT-133: Add NPM_TOKEN support to node and test/npm actions for private registry auth
npm ci fails with E401 when a consuming repo's package-lock.json pins a
package to the private Gitea npm registry, since these composite actions
never write an .npmrc or set a registry auth token. Add an optional
NPM_TOKEN input that writes .npmrc before install; existing consumers that
don't pass it are unaffected.
2026-09-17 11:48:24 -04:00
gitea-actions 3f7c00f1e7 chore: bump version [skip ci] 2026-09-10 00:04:58 +00:00
deac dcb3434b39 Merge pull request 'STAT-115-remove-check-shared-block: Remove claude/check-shared-block composite action' (#1) from STAT-115-remove-check-shared-block into main
publish.yaml / publish (push) Successful in 5s
Reviewed-on: #1
2026-09-10 00:04:51 +00:00
deac b865cdd697 STAT-115-remove-check-shared-block: Remove claude/check-shared-block composite action
Superseded by a live @../stat-tackler-claude/CLAUDE.md import, which
means there is no per-repo copy left to drift and nothing left to check
(part of STAT-115).

Claude-Session: https://claude.ai/code/session_01FS9R1ZEc8Vu7hg2PmzqbpP
2026-09-09 19:52:32 -04:00
gitea-actions 4300baaa19 chore: bump version [skip ci] 2026-09-09 22:53:59 +00:00
deac eef6d305dd STAT-115: Add claude/check-shared-block composite action (STAT-115)
publish.yaml / publish (push) Successful in 4s
Claude-Session: https://claude.ai/code/session_01FS9R1ZEc8Vu7hg2PmzqbpP
2026-09-09 18:46:40 -04:00
gitea-actions a9c5e56a24 chore: bump version [skip ci] 2026-08-21 19:03:47 +00:00
deac 4e765e5c64 add-promotion-gate-action: Add git/promotion-gate composite action
publish.yaml / publish (push) Successful in 4s
Enforces which source branches may merge into which target branches, configured via a rules input (one target:allowed,allowed per line, glob-capable). Empty rules (default) skips enforcement entirely, so repos can adopt it without immediately gating on rules they have not configured. Extracted for reuse across repos moving to a gitflow-style branch promotion model, starting with stat-tackler-api.
2026-08-21 14:57:03 -04:00
gitea-actions 50dc06f634 chore: bump version [skip ci] 2026-08-18 13:38:29 +00:00
deac 992d3630e9 ci: maintain a floating v1 major-version tag on release
publish.yaml / publish (push) Successful in 8s
Lets consumers pin actions to @v1 instead of an exact vX.Y.Z, so they
pick up fixes automatically without per-repo version bumps.
2026-08-18 09:38:15 -04:00
gitea-actions b8b5648d00 chore: bump version [skip ci] 2026-08-18 13:34:06 +00:00
deac 503c02b24c fix: skip commit/push in update_version when tag is unchanged
publish.yaml / publish (push) Successful in 8s
git commit was failing the step (and job) with "nothing to commit" when
the target tag already matched releases/versions.yaml, e.g. on a re-run
for the same commit SHA.
2026-08-18 09:33:33 -04:00
gitea-actions fce2468b2b chore: bump version [skip ci] 2026-06-05 21:25:12 +00:00
deac 30ff44c33b Merge branch 'main' of ssh://gitea.pixelparasol.com:4122/pixel-parasol-public/gitea-actions
/ publish (push) Successful in 7s
2026-06-05 17:24:54 -04:00
deac 11fd063f95 allow skip build artifact for node action 2026-06-05 17:24:49 -04:00
gitea-actions 70758f1d74 chore: bump version [skip ci] 2026-06-05 20:44:36 +00:00
deac 395bf58622 add additional args to test npm runs
/ publish (push) Successful in 7s
2026-06-05 16:44:27 -04:00
gitea-actions 358bf3b06f chore: bump version [skip ci] 2026-06-01 00:51:33 +00:00
deac 298834cd9f fix: remove kubeconfig cleanup from template and diff — kubeconfig must persist across pipeline steps
/ publish (push) Failing after 6s
2026-06-01 00:51:27 +00:00
deac a6dc98df0d fix: remove kubeconfig cleanup from template and diff — kubeconfig must persist across pipeline steps
/ publish (push) Successful in 7s
2026-06-01 00:51:26 +00:00
13 changed files with 163 additions and 13 deletions
+4 -1
View File
@@ -24,6 +24,9 @@ jobs:
git add VERSION git add VERSION
git diff --cached --quiet || git commit -m "chore: bump version [skip ci]" git diff --cached --quiet || git commit -m "chore: bump version [skip ci]"
version=$(cat VERSION) version=$(cat VERSION)
major="${version%%.*}"
git tag "v${version}" git tag "v${version}"
git tag -f "v${major}"
git push git push
git push --tags git push origin "refs/tags/v${version}"
git push --force origin "refs/tags/v${major}"
+1
View File
@@ -2,6 +2,7 @@ ACTIONS := \
docker \ docker \
node \ node \
git/create_tag \ git/create_tag \
git/promotion-gate \
helm/diff \ helm/diff \
helm/template \ helm/template \
helm/upgrade \ helm/upgrade \
+1
View File
@@ -15,6 +15,7 @@ Reusable composite actions for Gitea CI/CD pipelines.
| Action | Description | | Action | Description |
|---|---| |---|---|
| [git/create_tag](git/create_tag/README.md) | Create and push a git tag in the current repository | | [git/create_tag](git/create_tag/README.md) | Create and push a git tag in the current repository |
| [git/promotion-gate](git/promotion-gate/README.md) | Enforce which source branches may merge into which target branches |
### Helm ### Helm
+1 -1
View File
@@ -1 +1 @@
1.13.0 1.22.0
+21
View File
@@ -0,0 +1,21 @@
# Promotion Gate
<!-- action-docs-description source="action.yml" -->
## Description
Enforce which source branches may merge into which target branches
<!-- action-docs-description source="action.yml" -->
<!-- action-docs-inputs source="action.yml" -->
## Inputs
| name | description | required | default |
| --- | --- | --- | --- |
| `rules` | <p>One rule per line: "target:allowed1,allowed2,…". Targets not listed are unrestricted. Allowed entries may use a trailing glob, e.g. <code>hotfix-*</code>. Leave empty (default) to skip entirely.</p> | `false` | `""` |
<!-- action-docs-inputs source="action.yml" -->
<!-- action-docs-runs source="action.yml" -->
## Runs
This action is a `composite` action.
<!-- action-docs-runs source="action.yml" -->
+75
View File
@@ -0,0 +1,75 @@
name: Promotion Gate
description: Enforce which source branches may merge into which target branches
inputs:
rules:
description: |
One rule per line: "target:allowed1,allowed2,...". Targets not
listed are unrestricted. Allowed entries may use a trailing glob,
e.g. `hotfix-*`. Leave empty (default) to skip entirely.
default: ""
runs:
using: composite
steps:
- name: Check merge source is allowed for target branch
shell: sh
env:
BASE: ${{ gitea.event.pull_request.base.ref }}
HEAD: ${{ gitea.event.pull_request.head.ref }}
RULES: ${{ inputs.rules }}
run: |
if [ -z "$RULES" ]; then
echo "No promotion rules configured — skipping."
exit 0
fi
rc=0
found=0
oldIFS=$IFS
IFS='
'
set -f
set -- $RULES
set +f
IFS=$oldIFS
for line in "$@"; do
if [ -z "$line" ]; then
continue
fi
target=${line%%:*}
allowed=${line#*:}
if [ "$target" = "$line" ]; then
continue
fi
if [ "$BASE" = "$target" ]; then
found=1
matched=0
innerIFS=$IFS
IFS=','
for pat in $allowed; do
IFS=$innerIFS
case "$HEAD" in
$pat)
matched=1
;;
esac
IFS=','
done
IFS=$innerIFS
if [ "$matched" -eq 1 ]; then
echo "Allowed: '$HEAD' -> '$BASE' (matches: $allowed)"
else
echo "::error::$BASE only accepts merges from: $allowed — got '$HEAD'"
rc=1
fi
fi
done
if [ "$found" -eq 0 ]; then
echo "No promotion-source restriction configured for base '$BASE'"
fi
exit $rc
-5
View File
@@ -73,8 +73,3 @@ runs:
fi fi
helm dependency update "$CHART_PATH" helm dependency update "$CHART_PATH"
helm diff upgrade "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS --context 5 helm diff upgrade "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS --context 5
- name: Remove kubeconfig
if: always()
shell: sh
run: rm -f ~/.kube/config
-5
View File
@@ -68,8 +68,3 @@ runs:
fi fi
helm dependency update "$CHART_PATH" helm dependency update "$CHART_PATH"
helm template "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS helm template "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS
- name: Remove kubeconfig
if: always()
shell: sh
run: rm -f ~/.kube/config
+4
View File
@@ -38,5 +38,9 @@ runs:
git config user.email "gitea-actions@gitea.pixelparasol.com" git config user.email "gitea-actions@gitea.pixelparasol.com"
git config user.name "Gitea Actions" git config user.name "Gitea Actions"
git add releases/versions.yaml git add releases/versions.yaml
if git diff --cached --quiet; then
echo "No version change for ${{ inputs.service }}, skipping commit"
exit 0
fi
git commit -m "chore: update ${{ inputs.service }} to ${{ inputs.tag }}" git commit -m "chore: update ${{ inputs.service }} to ${{ inputs.tag }}"
git push git push
+2
View File
@@ -18,6 +18,8 @@ Install dependencies, build, and upload a build artifact
| `ARTIFACT_PATH` | <p>Path to upload as the artifact</p> | `false` | `dist` | | `ARTIFACT_PATH` | <p>Path to upload as the artifact</p> | `false` | `dist` |
| `COPY_PRISMA_ENGINE` | <p>Copy the Prisma query engine binaries into the build directory</p> | `false` | `false` | | `COPY_PRISMA_ENGINE` | <p>Copy the Prisma query engine binaries into the build directory</p> | `false` | `false` |
| `WORKING_DIRECTORY` | <p>Working directory for install, build, and artifact steps</p> | `false` | `.` | | `WORKING_DIRECTORY` | <p>Working directory for install, build, and artifact steps</p> | `false` | `.` |
| `UPLOAD_ARTIFACT` | <p>Whether to upload the build artifact</p> | `false` | `true` |
| `NPM_TOKEN` | <p>Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages.</p> | `false` | `""` |
<!-- action-docs-inputs source="action.yml" --> <!-- action-docs-inputs source="action.yml" -->
<!-- action-docs-runs source="action.yml" --> <!-- action-docs-runs source="action.yml" -->
+17
View File
@@ -22,6 +22,12 @@ inputs:
WORKING_DIRECTORY: WORKING_DIRECTORY:
description: "Working directory for install, build, and artifact steps" description: "Working directory for install, build, and artifact steps"
default: "." default: "."
UPLOAD_ARTIFACT:
description: "Whether to upload the build artifact"
default: "true"
NPM_TOKEN:
description: "Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages."
default: ""
runs: runs:
using: composite using: composite
@@ -33,6 +39,16 @@ runs:
with: with:
node-version-file: ${{ inputs.WORKING_DIRECTORY }}/package.json node-version-file: ${{ inputs.WORKING_DIRECTORY }}/package.json
- name: Configure private registry auth
if: inputs.NPM_TOKEN != ''
shell: sh
working-directory: ${{ inputs.WORKING_DIRECTORY }}
run: |
printf '%s\n%s\n' \
'@stat-tackler:registry=https://gitea.pixelparasol.com/api/packages/stat-tackler/npm/' \
'//gitea.pixelparasol.com/api/packages/stat-tackler/npm/:_authToken=${{ inputs.NPM_TOKEN }}' \
>> .npmrc
- name: Install - name: Install
shell: sh shell: sh
working-directory: ${{ inputs.WORKING_DIRECTORY }} working-directory: ${{ inputs.WORKING_DIRECTORY }}
@@ -56,6 +72,7 @@ runs:
cp node_modules/.prisma/client/libquery_engine-* build/prisma/ cp node_modules/.prisma/client/libquery_engine-* build/prisma/
- name: Upload Build Artifact - name: Upload Build Artifact
if: inputs.UPLOAD_ARTIFACT != 'false'
uses: actions/upload-artifact@v3 uses: actions/upload-artifact@v3
with: with:
name: ${{ inputs.ARTIFACT_NAME }} name: ${{ inputs.ARTIFACT_NAME }}
+20
View File
@@ -8,7 +8,9 @@ Composite action: install dependencies and run an npm test script.
|---|---|---| |---|---|---|
| `INSTALL_CMD` | Install command | `npm ci` | | `INSTALL_CMD` | Install command | `npm ci` |
| `TEST_SCRIPT` | npm script to run (must exist in `package.json`) | `test` | | `TEST_SCRIPT` | npm script to run (must exist in `package.json`) | `test` |
| `TEST_ARGS` | Additional arguments passed after `--` to the test script | `` |
| `WORKING_DIRECTORY` | Directory to run commands in | `.` | | `WORKING_DIRECTORY` | Directory to run commands in | `.` |
| `NPM_TOKEN` | Auth token for the private Gitea npm registry (`@stat-tackler` scope). Leave empty if the repo installs no private packages. | `` |
## Usage ## Usage
@@ -18,6 +20,24 @@ Composite action: install dependencies and run an npm test script.
TEST_SCRIPT: test:unit TEST_SCRIPT: test:unit
``` ```
With a private `@stat-tackler` package in `package.json`:
```yaml
- uses: stat-tackler/stat-tackler-infra/test/npm@main
with:
TEST_SCRIPT: test:unit
NPM_TOKEN: ${{ secrets.REGISTRY_READ_WRITE_AGENT }}
```
With extra args:
```yaml
- uses: stat-tackler/stat-tackler-infra/test/npm@main
with:
TEST_SCRIPT: test:coverage
TEST_ARGS: --silent --reporter=dot --test-timeout=30000
```
### Common test scripts by project ### Common test scripts by project
| Project | Script | Runner | | Project | Script | Runner |
+17 -1
View File
@@ -8,9 +8,15 @@ inputs:
TEST_SCRIPT: TEST_SCRIPT:
description: "npm script to run (must exist in package.json)" description: "npm script to run (must exist in package.json)"
default: "test" default: "test"
TEST_ARGS:
description: "Additional arguments to pass after -- to the test script"
default: ""
WORKING_DIRECTORY: WORKING_DIRECTORY:
description: "Directory to run commands in" description: "Directory to run commands in"
default: "." default: "."
NPM_TOKEN:
description: "Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages."
default: ""
runs: runs:
using: composite using: composite
@@ -29,6 +35,16 @@ runs:
key: node-modules-${{ hashFiles(format('{0}/package-lock.json', inputs.WORKING_DIRECTORY)) }} key: node-modules-${{ hashFiles(format('{0}/package-lock.json', inputs.WORKING_DIRECTORY)) }}
restore-keys: node-modules- restore-keys: node-modules-
- name: Configure private registry auth
if: inputs.NPM_TOKEN != ''
shell: sh
working-directory: ${{ inputs.WORKING_DIRECTORY }}
run: |
printf '%s\n%s\n' \
'@stat-tackler:registry=https://gitea.pixelparasol.com/api/packages/stat-tackler/npm/' \
'//gitea.pixelparasol.com/api/packages/stat-tackler/npm/:_authToken=${{ inputs.NPM_TOKEN }}' \
>> .npmrc
- name: Install - name: Install
shell: sh shell: sh
working-directory: ${{ inputs.WORKING_DIRECTORY }} working-directory: ${{ inputs.WORKING_DIRECTORY }}
@@ -37,4 +53,4 @@ runs:
- name: Test - name: Test
shell: sh shell: sh
working-directory: ${{ inputs.WORKING_DIRECTORY }} working-directory: ${{ inputs.WORKING_DIRECTORY }}
run: npm run ${{ inputs.TEST_SCRIPT }} run: npm run ${{ inputs.TEST_SCRIPT }}${{ inputs.TEST_ARGS != '' && format(' -- {0}', inputs.TEST_ARGS) || '' }}