environment: APK_REPO: alpine/v3.22/bigbes/x86_64 BOOTSTRAP_REV: 779ad9f174ea5ab7e755f6df0ec9e5912d67dd16 BUILD_SUBMITTER: git.sr.ht CORE_VER: 0.84.5 GIT_REF: refs/heads/master REPO: sr-ht-spec S3_BUCKET: repo S3_ENDPOINT: https://s3.bigb.es image: alpine/edge packages: - abuild - curl - go - git - rclone - sassc - minify secrets: - apk-ci-s3 - 7dde4219-0783-4581-a67d-c94749de3600 - 0e5b3530-6f19-4f30-9b73-9339dd382e46 sources: - "https://git.srht.bigb.es/~bigbes/sr-ht-spec#a4d8cc52e917cf1db07c876e8b36654dcf28741b" submitter: git.sr.ht: allow-refs: - refs/heads/master tasks: - cacher: | # S3-backed CI cache helper (go.bigb.es/cacher), dogfooded from its own # published release — the same bootstrap the bencher/ci-cacher builds use. # First task, so the scss assembly below can already use the cache. mkdir -p ~/.local/bin curl -sSL "https://bigbes.pages.srht.bigb.es/ci-cacher/cacher-linux-amd64" \ -o ~/.local/bin/cacher chmod +x ~/.local/bin/cacher echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.buildenv export PATH="$HOME/.local/bin:$PATH" cacher init \ --endpoint https://s3.bigb.es \ --region garage \ --bucket docker-cache \ --prefix sr-ht-spec/deps \ --key-file ~/.s3-cache-key-id \ --secret-file ~/.s3-cache-key-secret - scss: | # No apk ships the shared sourcehut SCSS partials, so assemble them the # way core.sr.ht's `make install-scss` would: its own scss/ plus the # Bootstrap 4 submodule. `make css` runs sassc -I against this tree. # The assembled tree is cached keyed by the two pins — on a hit this # task touches neither git.sr.ht nor github.com, so their outages can't # fail the build. KEY_SCSS="scss/${CORE_VER}-${BOOTSTRAP_REV}.tar.zst" if ! cacher dir download "$KEY_SCSS" ~/scss; then git clone --depth 1 --branch "$CORE_VER" \ https://git.sr.ht/~sircmpwn/core.sr.ht /tmp/core mkdir -p ~/scss/bootstrap cp /tmp/core/scss/*.scss /tmp/core/scss/*.css ~/scss/ git init -q /tmp/bootstrap git -C /tmp/bootstrap remote add origin https://github.com/twbs/bootstrap git -C /tmp/bootstrap fetch -q --depth 1 origin "$BOOTSTRAP_REV" git -C /tmp/bootstrap checkout -q FETCH_HEAD cp -r /tmp/bootstrap/scss ~/scss/bootstrap/scss cacher dir upload "$KEY_SCSS" ~/scss fi sudo mkdir -p /usr/share/sourcehut sudo cp -r ~/scss /usr/share/sourcehut/scss - keygen: | # abuild insists on signing what it builds, but this key is deliberately # throwaway: generated per build, dies with the VM, trusted by nothing. # Clients verify against the index instead, which is rebuilt and signed on # phoebe by the garage stack's apk-mirror service — it indexes this repo # with --allow-untrusted precisely because of this. # # -i installs the public half into /etc/apk/keys. Without it abuild's own # final "update the local repository index" step dies with UNTRUSTED # signature, after having built the package perfectly well. SUDO=sudo abuild-keygen -a -n -i -q - version: | cd "$REPO" ver="0.0.$(git rev-list --count HEAD)" sed -i "s/^pkgver=.*/pkgver=$ver/" APKBUILD echo "export PKGVER=$ver" >> ~/.buildenv echo "building $ver" - cache_restore: | # Restore the Go module and build caches, both keyed by go.sum: the # dependency tree dominates compile time, and it only changes when go.sum # does. A miss is just a cold build, never an error. KEY_MOD=$(cacher key "gomod/{hash}.tar.zst" --hash-from "$REPO/go.sum") KEY_GOC=$(cacher key "gocache/{hash}.tar.zst" --hash-from "$REPO/go.sum") echo "export KEY_MOD=$KEY_MOD KEY_GOC=$KEY_GOC" >> ~/.buildenv # abuild redirects the Go caches into its throwaway $tmpdir (and an # upstream typo slaves GOMODCACHE to GOCACHE), so env exports here can't # stick — the APKBUILD's build() re-pins both to these home locations. cacher dir download "$KEY_MOD" ~/go/pkg/mod || true cacher dir download "$KEY_GOC" ~/.cache/go-build || true - build: | cd "$REPO" # -d: makedepends are already installed via `packages:` above. REPODEST=$HOME/packages abuild -d find "$HOME/packages" -name '*.apk' - cache_save: | # Seed the caches only when this go.sum has no entry yet — on a hit the # tarballs are already up there and re-uploading identical bytes is waste. cacher exists "$KEY_MOD" || cacher dir upload "$KEY_MOD" ~/go/pkg/mod cacher exists "$KEY_GOC" || cacher dir upload "$KEY_GOC" ~/.cache/go-build - publish: | set +x # never echo the S3 credentials into the build log . ~/.apk-ci.env export RCLONE_CONFIG_GARAGE_TYPE=s3 export RCLONE_CONFIG_GARAGE_PROVIDER=Other export RCLONE_CONFIG_GARAGE_ENDPOINT="$S3_ENDPOINT" export RCLONE_CONFIG_GARAGE_REGION=garage export RCLONE_CONFIG_GARAGE_FORCE_PATH_STYLE=true export RCLONE_CONFIG_GARAGE_ACCESS_KEY_ID="$APK_CI_S3_ACCESS_KEY" export RCLONE_CONFIG_GARAGE_SECRET_ACCESS_KEY="$APK_CI_S3_SECRET_KEY" set -x # Upload only; never delete. Old versions stay so a pinned deployment can # always be rebuilt — the same reason the upstream mirror is append-only. find "$HOME/packages" -name '*.apk' -print | while read -r f; do rclone copyto "$f" "garage:$S3_BUCKET/$APK_REPO/$(basename "$f")" echo "uploaded $(basename "$f")" done echo "published; apk-mirror on phoebe re-indexes within 15 minutes"