From f35df9c4d3348cfa08cacbb18f8f4c4115f3886c Mon Sep 17 00:00:00 2001 From: Rick Peters Date: Wed, 30 Sep 2026 08:11:24 +0200 Subject: [PATCH] feat(ci): sync the git.upriser.nl mirror on every push to main and every tag GitHub workflow calls the mirror-sync API so the Gitea build starts at once instead of at the mirror's 10 minute interval (secrets GIT_UPRISER_URL, GIT_UPRISER_TOKEN; retried; skipped on Gitea itself). The steamify-iso-release skill uses the renamed secret and workflows. --- .claude/skills/steamify-iso-release/SKILL.md | 12 ++++----- .claude/skills/wsl-build-host/SKILL.md | 2 +- .github/workflows/git-upriser-sync.yml | 26 ++++++++++++++++++++ 3 files changed, 33 insertions(+), 7 deletions(-) create mode 100644 .github/workflows/git-upriser-sync.yml diff --git a/.claude/skills/steamify-iso-release/SKILL.md b/.claude/skills/steamify-iso-release/SKILL.md index 95aa7ef..9f40faf 100644 --- a/.claude/skills/steamify-iso-release/SKILL.md +++ b/.claude/skills/steamify-iso-release/SKILL.md @@ -10,19 +10,19 @@ on git.upriser.nl, GitHub's link to it answers 200. ## The flow (one tag names everything) -1. **GitHub, `iso-release.yml`** (ISO repo `theupriser/steamify-cachyos-live-iso`, `workflow_dispatch` only): +1. **GitHub, `iso-1-github-tag.yml`** (ISO repo `theupriser/steamify-cachyos-live-iso`, `workflow_dispatch` only): takes Steamify's newest release (`X.Y.Z`), the time **now in UTC** and makes an **annotated tag** `vX.Y.Z-[dev.]YYYY.MM.DD-HHMM` plus a GitHub release with the changelog notes and the *direct* download link on Gitea. `dev.` and a pre-release on `feat/steamify` (test build), none on `master` (a release). GitHub is the only place that reads a clock. 2. **The mirror syncs** (git.upriser.nl is a pull mirror of GitHub, every 10 minutes): the tag arrives. -3. **Gitea, `steamify-iso.yml`** (`on: push: tags: ['v*']`, skipped on GitHub by `github.server_url`): parses the +3. **Gitea, `iso-2-gitea-build.yml`** (`on: push: tags: ['v*']`, skipped on GitHub by `github.server_url`): parses the tag, builds the ISO on the runner with exactly that Steamify (`STEAMIFY_VERSION`), the tag's time (label) and the tag without its `v` (`STEAMIFY_ISO_VERSION`: file name, boot menu, `/etc/steammachine-iso-build`), then attaches ISO + `.sha256` + `.sha1` + `.pkgs.txt` to the mirror's release for that tag (`akkuman/gitea-release-action`, the run's own token). Never overwrites a release that already has its ISO. -4. **Trigger:** by hand (*Actions -> Steamify ISO release (tag) -> Run workflow*, or - `gh workflow run iso-release.yml -R theupriser/steamify-cachyos-live-iso --ref feat/steamify`), or by a +4. **Trigger:** by hand (*Actions -> ISO 1/2 ยท Tag and release (GitHub) -> Run workflow*, or + `gh workflow run iso-1-github-tag.yml -R theupriser/steamify-cachyos-live-iso --ref feat/steamify`), or by a new Steamify release: `steamify-cachyos`' `bundle.yml` step "Start the Steamify ISO's release" (secret `ISO_DISPATCH_TOKEN` there: fine-grained token, only the ISO repo, *Actions: read and write*; without it the step is skipped). A push does **not** release (a build is 20 minutes and 3.2 GB). @@ -56,7 +56,7 @@ Total from a Steamify release to the ISO on Gitea: about 30 minutes (release, ta - Logs of a public repo's run are readable without login: `.../actions/runs//jobs//logs` (job numbers count up; re-runs get a new job number). Good for a monitor; no `gh` for Gitea. - Mirror sync is set to 10 min by the user with their own token; "Synchronize Now" or the API - (`POST /api/v1/repos//mirror-sync`) for now. `GITEA_TOKEN` (secret in the ISO repo) would make GitHub + (`POST /api/v1/repos//mirror-sync`) for now. `GIT_UPRISER_TOKEN` (secret in the ISO repo) would make GitHub trigger it; not needed. - **Build traps in the container:** `sudo mkarchiso` in `util-iso.sh` **drops environment variables**: it needs `sudo --preserve-env=STEAMIFY_ISO_VERSION,STEAMIFY_BUILD_STAMP` (the first Gitea ISO came out as @@ -94,7 +94,7 @@ if it ever vanishes, ship the file with Steamify. ## Checklist for a release 1. Steamify released? (`gh release list -R theupriser/steamify-cachyos`). The ISO gets the newest. -2. `gh workflow run iso-release.yml ... --ref feat/steamify` (test) or `--ref master` (release; master must have +2. `gh workflow run iso-1-github-tag.yml ... --ref feat/steamify` (test) or `--ref master` (release; master must have the workflows: it doesn't yet, `feat/steamify` is the ISO repo's working branch). 3. Watch: tag on Gitea (`.../api/v1/repos/theupriser/steamify-cachyos-live-iso/tags`), the run's log (above), then `curl -I -L` the GitHub link. Old test releases: delete on GitHub (`gh release delete diff --git a/.claude/skills/wsl-build-host/SKILL.md b/.claude/skills/wsl-build-host/SKILL.md index b4c11a2..228b42c 100644 --- a/.claude/skills/wsl-build-host/SKILL.md +++ b/.claude/skills/wsl-build-host/SKILL.md @@ -72,7 +72,7 @@ Wait in one background command, not a polling loop: Never start a build while `podman ps` shows one. Output: `/root/projects/steamify-cachyos-live-iso/out/desktop/steamify-cachyos-local-x86_64.iso` (a build by hand has no release tag, so it's named `local`, label `STEAMIFY__LOCAL`; releases are built on the Gitea -mirror from a GitHub tag, see the ISO repo's `iso-release.yml`) (from +mirror from a GitHub tag, see the ISO repo's `iso-1-github-tag.yml`) (from Windows Explorer: `\\wsl$\\root\projects\...`). The trailing `chown: missing operand` / "unknown error" is harmless. mksquashfs shows no progress in the log; the growing `build/iso/arch/x86_64/airootfs.sfs` diff --git a/.github/workflows/git-upriser-sync.yml b/.github/workflows/git-upriser-sync.yml new file mode 100644 index 0000000..e27b3be --- /dev/null +++ b/.github/workflows/git-upriser-sync.yml @@ -0,0 +1,26 @@ +name: Sync git.upriser.nl mirror + +# Trigger the Gitea pull-mirror immediately instead of waiting for its interval, +# so Gitea builds/releases the ISO right after main or a tag lands on GitHub. +on: + push: + branches: [main] + tags: ['*'] + workflow_dispatch: + +jobs: + sync: + # Gitea also reads .github/workflows on the mirror; only run on GitHub + if: github.server_url == 'https://github.com' + runs-on: ubuntu-latest + steps: + - name: Trigger mirror-sync + env: + GITEA_URL: ${{ secrets.GIT_UPRISER_URL }} + GIT_UPRISER_TOKEN: ${{ secrets.GIT_UPRISER_TOKEN }} + # Gitea "owner/repo"; defaults to the same path as on GitHub + GITEA_REPO: ${{ vars.GITEA_REPO || github.repository }} + run: | + curl --fail-with-body -sS --retry 5 --retry-delay 10 --retry-all-errors -X POST \ + -H "Authorization: token ${GIT_UPRISER_TOKEN}" \ + "${GITEA_URL%/}/api/v1/repos/${GITEA_REPO}/mirror-sync"