Move Gitea sync to isolated trusted runner and stop persisting token
This commit is contained in:
@@ -1,9 +1,5 @@
|
||||
name: Open Gitea PR on merge to main
|
||||
|
||||
# When main changes on GitHub (i.e. after a PR is merged here), push those
|
||||
# commits to a branch on Gitea and open a pull request there, so the same
|
||||
# change can be reviewed and landed on the Gitea side. One-way: GitHub -> Gitea.
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
@@ -14,15 +10,12 @@ permissions:
|
||||
|
||||
jobs:
|
||||
open-gitea-pr:
|
||||
# GitHub-hosted runners are billing-blocked for this org, so the hosted job
|
||||
# never started. Run on the self-hosted runner, which also has LAN access to
|
||||
# the Gitea host. This workflow only fires on push to main (never on PRs from
|
||||
# forks), so it is safe on the private runner.
|
||||
runs-on: [self-hosted, Linux, X64]
|
||||
runs-on: [self-hosted, Linux, X64, co-server-sync]
|
||||
steps:
|
||||
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
||||
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||
with:
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
|
||||
- name: Push main to Gitea and open a pull request
|
||||
env:
|
||||
@@ -33,38 +26,59 @@ jobs:
|
||||
SYNC_BRANCH: sync/from-github
|
||||
run: |
|
||||
set -euo pipefail
|
||||
umask 077
|
||||
|
||||
if [ -z "${GITEA_TOKEN:-}" ]; then
|
||||
echo "::error::Missing GITEA_TOKEN secret. Add a Gitea access token as a"
|
||||
echo "::error::repository secret named GITEA_TOKEN (Settings -> Secrets and"
|
||||
echo "::error::variables -> Actions -> New repository secret)."
|
||||
echo "::error::Missing GITEA_TOKEN repository secret."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
askpass="${RUNNER_TEMP}/gitea-askpass-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}.sh"
|
||||
header_file="${RUNNER_TEMP}/gitea-header-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}"
|
||||
response_file="${RUNNER_TEMP}/gitea-pr-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}.json"
|
||||
|
||||
cleanup() {
|
||||
git remote remove gitea >/dev/null 2>&1 || true
|
||||
rm -f -- "$askpass" "$header_file" "$response_file"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
cat > "$askpass" <<'EOF'
|
||||
#!/usr/bin/env bash
|
||||
case "$1" in
|
||||
*Username*) printf '%s\n' "${GITEA_USER:?}" ;;
|
||||
*Password*) printf '%s\n' "${GITEA_TOKEN:?}" ;;
|
||||
*) exit 1 ;;
|
||||
esac
|
||||
EOF
|
||||
chmod 700 "$askpass"
|
||||
printf 'Authorization: token %s\n' "$GITEA_TOKEN" > "$header_file"
|
||||
chmod 600 "$header_file"
|
||||
|
||||
export GIT_ASKPASS="$askpass"
|
||||
export GIT_TERMINAL_PROMPT=0
|
||||
|
||||
git config user.name "github-sync"
|
||||
git config user.email "github-sync@users.noreply.github.com"
|
||||
|
||||
# Mirror the current main onto a dedicated Gitea branch. Force is safe:
|
||||
# this branch is owned by the automation and only ever tracks GitHub main.
|
||||
git remote add gitea "https://${GITEA_USER}:${GITEA_TOKEN}@${GITEA_HOST}/${GITEA_REPO}.git"
|
||||
git remote remove gitea >/dev/null 2>&1 || true
|
||||
git remote add gitea "https://${GITEA_HOST}/${GITEA_REPO}.git"
|
||||
git push -f gitea "HEAD:refs/heads/${SYNC_BRANCH}"
|
||||
|
||||
# Open a PR on Gitea: sync/from-github -> main. If one is already open,
|
||||
# the push above has already updated it, so a 409 is success too.
|
||||
http_code=$(curl -sS -o /tmp/gitea_pr.json -w "%{http_code}" -X POST \
|
||||
http_code=$(curl -sS -o "$response_file" -w "%{http_code}" -X POST \
|
||||
"https://${GITEA_HOST}/api/v1/repos/${GITEA_REPO}/pulls" \
|
||||
-H "Authorization: token ${GITEA_TOKEN}" \
|
||||
-H "@${header_file}" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "{\"title\":\"Sync from GitHub main\",\"head\":\"${SYNC_BRANCH}\",\"base\":\"main\",\"body\":\"Automated: GitHub main was updated. Review and merge to land it on Gitea.\"}")
|
||||
-d "{\"title\":\"Sync from GitHub main\",\"head\":\"${SYNC_BRANCH}\",\"base\":\"main\",\"body\":\"GitHub main was updated. Review and merge to land it on Gitea.\"}")
|
||||
|
||||
echo "Gitea pulls API returned HTTP ${http_code}"
|
||||
cat /tmp/gitea_pr.json || true
|
||||
cat "$response_file" || true
|
||||
echo
|
||||
|
||||
if [ "${http_code}" = "201" ]; then
|
||||
if [ "$http_code" = "201" ]; then
|
||||
echo "Opened a new Gitea pull request."
|
||||
elif [ "${http_code}" = "409" ] || grep -qiE "already exist|issue_exist" /tmp/gitea_pr.json; then
|
||||
elif [ "$http_code" = "409" ] || grep -qiE "already exist|issue_exist" "$response_file"; then
|
||||
echo "A Gitea PR from ${SYNC_BRANCH} is already open; it now has the latest commits."
|
||||
else
|
||||
echo "::warning::Unexpected Gitea response (${http_code}). The branch was pushed;"
|
||||
echo "::warning::open the PR manually on Gitea if it did not appear."
|
||||
echo "::error::Unexpected Gitea response (${http_code})."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user