refactor(ci): name the ISO workflows after their order and host, secrets for the mirror's URL and token

- iso-release.yml -> iso-1-github-tag.yml (ISO 1/2: tag and release, GitHub)
- steamify-iso.yml -> iso-2-gitea-build.yml (ISO 2/2: build and publish, Gitea)
- the mirror sync takes its URL and token from GIT_UPRISER_URL / GIT_UPRISER_TOKEN and retries
- docs and comments follow the new names
This commit is contained in:
theupriser committed 2026-09-30 08:11:31 +02:00
1 parent f408f70e76
commit 44354f99fa
6 files changed
+16 -16

No files matched your search

+1 -1
View File
@@ -12,7 +12,7 @@ concurrency:
jobs:
build:
# CachyOS's plain ISO and its quicktest matrix: only in CachyOS's own repo, not in this fork
# (the Steamify ISO is steamify-iso.yml).
# (the Steamify ISO is iso-2-gitea-build.yml).
if: github.repository == 'CachyOS/CachyOS-Live-ISO'
runs-on: ubuntu-latest
container:
@@ -1,11 +1,11 @@
# The Steamify ISO's release, step 1 of 2 (GitHub): names it and creates its tag and a release with the notes.
# The Gitea mirror (git.upriser.nl) gets the tag with its next sync (triggered here when GITEA_TOKEN is set),
# builds the ISO on that tag and attaches it to its own release for it (steamify-iso.yml). The ISO lives there:
# The Gitea mirror (git.upriser.nl) gets the tag with its next sync (triggered here when GIT_UPRISER_TOKEN is set),
# builds the ISO on that tag and attaches it to its own release for it (iso-2-gitea-build.yml). The ISO lives there:
# GitHub releases take at most 2 GB per file, the ISO is bigger, and a release on the mirror only survives its
# syncs when its tag comes from here.
# Name: the Steamify version the ISO gets (its newest release) plus the time (UTC, GitHub's clock when the release starts):
# master releases v<steamify>-<YYYY.MM.DD>-<HHMM>, feat/steamify a pre-release v<steamify>-dev.<...>.
name: Steamify ISO release (tag)
name: ISO 1/2 · Tag and release (GitHub)
# Started by a new Steamify release (its bundle.yml, secret ISO_DISPATCH_TOKEN) or by hand (Run workflow,
# on master for a release, on feat/steamify for a test build); not by every push.
@@ -16,7 +16,7 @@ permissions:
contents: write
env:
GITEA_URL: https://git.upriser.nl
GITEA_URL: ${{ secrets.GIT_UPRISER_URL }}
GITEA_REPO: theupriser/steamify-cachyos-live-iso
jobs:
@@ -38,7 +38,7 @@ jobs:
else
tag="v$steamify-dev.$stamp" pre="--prerelease" name="CachyOS with Steamify Live ISO $steamify (test build $stamp UTC)"
fi
# The ISO's file on the mirror is named after the tag (steamify-iso.yml, profiledef.sh), so its
# The ISO's file on the mirror is named after the tag (iso-2-gitea-build.yml, profiledef.sh), so its
# download link is known now.
file="steamify-cachyos-${tag#v}-x86_64.iso" dl="$GITEA_URL/$GITEA_REPO/releases/download/$tag"
# The Steamify section of CHANGELOG.md ("## CachyOS with Steamify Live ISO"), without its heading.
@@ -59,11 +59,11 @@ jobs:
echo "Released $tag"
# Optional: sync the mirror at once instead of at its interval (a Gitea token with repository write
# access as the secret GITEA_TOKEN).
# access as the secret GIT_UPRISER_TOKEN).
- name: Sync the Gitea mirror
env:
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
GIT_UPRISER_TOKEN: ${{ secrets.GIT_UPRISER_TOKEN }}
run: |
if [ -z "$GITEA_TOKEN" ]; then echo "No GITEA_TOKEN: the mirror picks the tag up at its next sync."; exit 0; fi
curl -fsS -X POST -H "Authorization: token $GITEA_TOKEN" "$GITEA_URL/api/v1/repos/$GITEA_REPO/mirror-sync" &&
if [ -z "$GIT_UPRISER_TOKEN" ]; then echo "No GIT_UPRISER_TOKEN: the mirror picks the tag up at its next sync."; exit 0; fi
curl -fsS --retry 5 --retry-delay 10 --retry-all-errors -X POST -H "Authorization: token $GIT_UPRISER_TOKEN" "$GITEA_URL/api/v1/repos/$GITEA_REPO/mirror-sync" &&
echo "Mirror sync started"
@@ -1,12 +1,12 @@
# The Steamify ISO's release, step 2 of 2 (the Gitea mirror, git.upriser.nl, on its own runner): builds the
# ISO for a release tag that iso-release.yml created on GitHub (it comes in with the mirror's sync, and a
# ISO for a release tag that iso-1-github-tag.yml created on GitHub (it comes in with the mirror's sync, and a
# release on the mirror only survives its syncs when its tag comes from GitHub), then attaches the ISO, its
# checksums and package list to the mirror's release for that tag. The tag names the Steamify version and
# the time: v<steamify>-<YYYY.MM.DD>-<HHMM> (master) or v<steamify>-dev.<...> (feat/steamify, a pre-release);
# the ISO gets exactly that Steamify release, and its label the same moment. GitHub skips it.
# The runner needs privileged containers (archiso mounts loop devices) and ~20 GB of disk; Gitea's
# [repository.release] FILE_MAX_SIZE must allow the ISO (default 2 GB).
name: Steamify ISO (Gitea release)
name: ISO 2/2 · Build and publish (Gitea)
on:
push: