feat(ci): sync the git.upriser.nl mirror on every push to main and every tag

GitHub workflow calls the mirror-sync API so the Gitea build starts at once instead of at the mirror's 10 minute interval (secrets GIT_UPRISER_URL, GIT_UPRISER_TOKEN; retried; skipped on Gitea itself). The steamify-iso-release skill uses the renamed secret and workflows.
This commit is contained in:
theupriser committed 2026-09-30 08:11:24 +02:00
1 parent 85657a3183
commit f35df9c4d3
3 files changed
+33 -7

No files matched your search

+6 -6
View File
@@ -10,19 +10,19 @@ on git.upriser.nl, GitHub's link to it answers 200.
## The flow (one tag names everything) ## The flow (one tag names everything)
1. **GitHub, `iso-release.yml`** (ISO repo `theupriser/steamify-cachyos-live-iso`, `workflow_dispatch` only): 1. **GitHub, `iso-1-github-tag.yml`** (ISO repo `theupriser/steamify-cachyos-live-iso`, `workflow_dispatch` only):
takes Steamify's newest release (`X.Y.Z`), the time **now in UTC** and makes an **annotated tag** takes Steamify's newest release (`X.Y.Z`), the time **now in UTC** and makes an **annotated tag**
`vX.Y.Z-[dev.]YYYY.MM.DD-HHMM` plus a GitHub release with the changelog notes and the *direct* download link `vX.Y.Z-[dev.]YYYY.MM.DD-HHMM` plus a GitHub release with the changelog notes and the *direct* download link
on Gitea. `dev.` and a pre-release on `feat/steamify` (test build), none on `master` (a release). on Gitea. `dev.` and a pre-release on `feat/steamify` (test build), none on `master` (a release).
GitHub is the only place that reads a clock. GitHub is the only place that reads a clock.
2. **The mirror syncs** (git.upriser.nl is a pull mirror of GitHub, every 10 minutes): the tag arrives. 2. **The mirror syncs** (git.upriser.nl is a pull mirror of GitHub, every 10 minutes): the tag arrives.
3. **Gitea, `steamify-iso.yml`** (`on: push: tags: ['v*']`, skipped on GitHub by `github.server_url`): parses the 3. **Gitea, `iso-2-gitea-build.yml`** (`on: push: tags: ['v*']`, skipped on GitHub by `github.server_url`): parses the
tag, builds the ISO on the runner with exactly that Steamify (`STEAMIFY_VERSION`), the tag's time (label) and tag, builds the ISO on the runner with exactly that Steamify (`STEAMIFY_VERSION`), the tag's time (label) and
the tag without its `v` (`STEAMIFY_ISO_VERSION`: file name, boot menu, `/etc/steammachine-iso-build`), then the tag without its `v` (`STEAMIFY_ISO_VERSION`: file name, boot menu, `/etc/steammachine-iso-build`), then
attaches ISO + `.sha256` + `.sha1` + `.pkgs.txt` to the mirror's release for that tag attaches ISO + `.sha256` + `.sha1` + `.pkgs.txt` to the mirror's release for that tag
(`akkuman/gitea-release-action`, the run's own token). Never overwrites a release that already has its ISO. (`akkuman/gitea-release-action`, the run's own token). Never overwrites a release that already has its ISO.
4. **Trigger:** by hand (*Actions -> Steamify ISO release (tag) -> Run workflow*, or 4. **Trigger:** by hand (*Actions -> ISO 1/2 · Tag and release (GitHub) -> Run workflow*, or
`gh workflow run iso-release.yml -R theupriser/steamify-cachyos-live-iso --ref feat/steamify`), or by a `gh workflow run iso-1-github-tag.yml -R theupriser/steamify-cachyos-live-iso --ref feat/steamify`), or by a
new Steamify release: `steamify-cachyos`' `bundle.yml` step "Start the Steamify ISO's release" (secret new Steamify release: `steamify-cachyos`' `bundle.yml` step "Start the Steamify ISO's release" (secret
`ISO_DISPATCH_TOKEN` there: fine-grained token, only the ISO repo, *Actions: read and write*; without it the `ISO_DISPATCH_TOKEN` there: fine-grained token, only the ISO repo, *Actions: read and write*; without it the
step is skipped). A push does **not** release (a build is 20 minutes and 3.2 GB). step is skipped). A push does **not** release (a build is 20 minutes and 3.2 GB).
@@ -56,7 +56,7 @@ Total from a Steamify release to the ISO on Gitea: about 30 minutes (release, ta
- Logs of a public repo's run are readable without login: `.../actions/runs/<run>/jobs/<job>/logs` (job numbers - Logs of a public repo's run are readable without login: `.../actions/runs/<run>/jobs/<job>/logs` (job numbers
count up; re-runs get a new job number). Good for a monitor; no `gh` for Gitea. count up; re-runs get a new job number). Good for a monitor; no `gh` for Gitea.
- Mirror sync is set to 10 min by the user with their own token; "Synchronize Now" or the API - Mirror sync is set to 10 min by the user with their own token; "Synchronize Now" or the API
(`POST /api/v1/repos/<repo>/mirror-sync`) for now. `GITEA_TOKEN` (secret in the ISO repo) would make GitHub (`POST /api/v1/repos/<repo>/mirror-sync`) for now. `GIT_UPRISER_TOKEN` (secret in the ISO repo) would make GitHub
trigger it; not needed. trigger it; not needed.
- **Build traps in the container:** `sudo mkarchiso` in `util-iso.sh` **drops environment variables**: - **Build traps in the container:** `sudo mkarchiso` in `util-iso.sh` **drops environment variables**:
it needs `sudo --preserve-env=STEAMIFY_ISO_VERSION,STEAMIFY_BUILD_STAMP` (the first Gitea ISO came out as it needs `sudo --preserve-env=STEAMIFY_ISO_VERSION,STEAMIFY_BUILD_STAMP` (the first Gitea ISO came out as
@@ -94,7 +94,7 @@ if it ever vanishes, ship the file with Steamify.
## Checklist for a release ## Checklist for a release
1. Steamify released? (`gh release list -R theupriser/steamify-cachyos`). The ISO gets the newest. 1. Steamify released? (`gh release list -R theupriser/steamify-cachyos`). The ISO gets the newest.
2. `gh workflow run iso-release.yml ... --ref feat/steamify` (test) or `--ref master` (release; master must have 2. `gh workflow run iso-1-github-tag.yml ... --ref feat/steamify` (test) or `--ref master` (release; master must have
the workflows: it doesn't yet, `feat/steamify` is the ISO repo's working branch). the workflows: it doesn't yet, `feat/steamify` is the ISO repo's working branch).
3. Watch: tag on Gitea (`.../api/v1/repos/theupriser/steamify-cachyos-live-iso/tags`), the run's log (above), 3. Watch: tag on Gitea (`.../api/v1/repos/theupriser/steamify-cachyos-live-iso/tags`), the run's log (above),
then `curl -I -L` the GitHub link. Old test releases: delete on GitHub (`gh release delete <tag> then `curl -I -L` the GitHub link. Old test releases: delete on GitHub (`gh release delete <tag>
+1 -1
View File
@@ -72,7 +72,7 @@ Wait in one background command, not a polling loop:
Never start a build while `podman ps` shows one. Output: Never start a build while `podman ps` shows one. Output:
`/root/projects/steamify-cachyos-live-iso/out/desktop/steamify-cachyos-local-x86_64.iso` (a build by hand `/root/projects/steamify-cachyos-live-iso/out/desktop/steamify-cachyos-local-x86_64.iso` (a build by hand
has no release tag, so it's named `local`, label `STEAMIFY_<version>_LOCAL`; releases are built on the Gitea has no release tag, so it's named `local`, label `STEAMIFY_<version>_LOCAL`; releases are built on the Gitea
mirror from a GitHub tag, see the ISO repo's `iso-release.yml`) (from mirror from a GitHub tag, see the ISO repo's `iso-1-github-tag.yml`) (from
Windows Explorer: `\\wsl$\<distro>\root\projects\...`). The trailing Windows Explorer: `\\wsl$\<distro>\root\projects\...`). The trailing
`chown: missing operand` / "unknown error" is harmless. mksquashfs shows no `chown: missing operand` / "unknown error" is harmless. mksquashfs shows no
progress in the log; the growing `build/iso/arch/x86_64/airootfs.sfs` progress in the log; the growing `build/iso/arch/x86_64/airootfs.sfs`
+26
View File
@@ -0,0 +1,26 @@
name: Sync git.upriser.nl mirror
# Trigger the Gitea pull-mirror immediately instead of waiting for its interval,
# so Gitea builds/releases the ISO right after main or a tag lands on GitHub.
on:
push:
branches: [main]
tags: ['*']
workflow_dispatch:
jobs:
sync:
# Gitea also reads .github/workflows on the mirror; only run on GitHub
if: github.server_url == 'https://github.com'
runs-on: ubuntu-latest
steps:
- name: Trigger mirror-sync
env:
GITEA_URL: ${{ secrets.GIT_UPRISER_URL }}
GIT_UPRISER_TOKEN: ${{ secrets.GIT_UPRISER_TOKEN }}
# Gitea "owner/repo"; defaults to the same path as on GitHub
GITEA_REPO: ${{ vars.GITEA_REPO || github.repository }}
run: |
curl --fail-with-body -sS --retry 5 --retry-delay 10 --retry-all-errors -X POST \
-H "Authorization: token ${GIT_UPRISER_TOKEN}" \
"${GITEA_URL%/}/api/v1/repos/${GITEA_REPO}/mirror-sync"