Merge pull request #26 from G-A-R-D-E-N/chore/harden-selfhosted-runner
Acceptance (end-to-end TCP) / End-to-end TCP acceptance (push) Canceled after 0s
Acceptance (end-to-end TCP) / End-to-end TCP acceptance (pull_request) Canceled after 0s
CSharp Server Gate / Repository policy, C# build and test (push) Canceled after 0s
GNS Transport Bridge / Linux native GNS bridge (push) Canceled after 0s
CSharp Server Gate / Repository policy, C# build and test (pull_request) Canceled after 0s
GNS Transport Bridge / Linux native GNS bridge (pull_request) Canceled after 0s
Host GUI (Avalonia) / Build Avalonia host (push) Canceled after 0s
Host GUI (Avalonia) / Build Avalonia host (pull_request) Canceled after 0s
Acceptance (end-to-end TCP) / End-to-end TCP acceptance (push) Canceled after 0s
Acceptance (end-to-end TCP) / End-to-end TCP acceptance (pull_request) Canceled after 0s
CSharp Server Gate / Repository policy, C# build and test (push) Canceled after 0s
GNS Transport Bridge / Linux native GNS bridge (push) Canceled after 0s
CSharp Server Gate / Repository policy, C# build and test (pull_request) Canceled after 0s
GNS Transport Bridge / Linux native GNS bridge (pull_request) Canceled after 0s
Host GUI (Avalonia) / Build Avalonia host (push) Canceled after 0s
Host GUI (Avalonia) / Build Avalonia host (pull_request) Canceled after 0s
Chore/harden selfhosted runner
This commit is contained in:
@@ -1,11 +1,5 @@
|
|||||||
name: Acceptance (end-to-end TCP)
|
name: Acceptance (end-to-end TCP)
|
||||||
|
|
||||||
# Issue #15 acceptance matrix, executed end-to-end: stands up the real
|
|
||||||
# AuthoritativeServer behind the real TCP transport on a loopback port and drives
|
|
||||||
# real client sockets through it. If the runner cannot bind a loopback listener,
|
|
||||||
# the harness prints SKIP and exits 0 (it still runs for real on dev machines and
|
|
||||||
# the NAS runner).
|
|
||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
paths:
|
paths:
|
||||||
@@ -17,17 +11,22 @@ on:
|
|||||||
- ".github/workflows/acceptance.yml"
|
- ".github/workflows/acceptance.yml"
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
acceptance:
|
acceptance:
|
||||||
name: End-to-end TCP acceptance
|
name: End-to-end TCP acceptance
|
||||||
runs-on: [self-hosted, Linux, X64]
|
runs-on: [self-hosted, Linux, X64, co-server]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
|
||||||
- name: Enforce repository runtime policy
|
- name: Enforce repository runtime policy
|
||||||
run: bash server/scripts/verify-no-legacy-runtime.sh
|
run: bash server/scripts/verify-no-legacy-runtime.sh
|
||||||
|
|
||||||
- uses: actions/setup-dotnet@v4
|
- uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9
|
||||||
env:
|
env:
|
||||||
DOTNET_INSTALL_DIR: ${{ runner.tool_cache }}/dotnet
|
DOTNET_INSTALL_DIR: ${{ runner.tool_cache }}/dotnet
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -5,20 +5,22 @@ on:
|
|||||||
pull_request:
|
pull_request:
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build-and-test:
|
build-and-test:
|
||||||
name: Repository policy, C# build and test
|
name: Repository policy, C# build and test
|
||||||
runs-on: [self-hosted, Linux, X64]
|
runs-on: [self-hosted, Linux, X64, co-server]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
|
||||||
- name: Enforce repository runtime policy
|
- name: Enforce repository runtime policy
|
||||||
run: bash server/scripts/verify-no-legacy-runtime.sh
|
run: bash server/scripts/verify-no-legacy-runtime.sh
|
||||||
|
|
||||||
- uses: actions/setup-dotnet@v4
|
- uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9
|
||||||
# The runner user cannot write to system /usr/share/dotnet; install the
|
|
||||||
# pinned SDK into a runner-writable, cached path instead. runner.* context
|
|
||||||
# is only valid at step scope, not job-level env.
|
|
||||||
env:
|
env:
|
||||||
DOTNET_INSTALL_DIR: ${{ runner.tool_cache }}/dotnet
|
DOTNET_INSTALL_DIR: ${{ runner.tool_cache }}/dotnet
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -10,14 +10,19 @@ on:
|
|||||||
- "server/native_transport/**"
|
- "server/native_transport/**"
|
||||||
- ".github/workflows/gns-transport.yml"
|
- ".github/workflows/gns-transport.yml"
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
linux:
|
linux:
|
||||||
name: Linux native GNS bridge
|
name: Linux native GNS bridge
|
||||||
runs-on: [self-hosted, Linux, X64]
|
runs-on: [self-hosted, Linux, X64, co-server]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
|
||||||
- name: Verify build dependencies (pre-provisioned on the self-hosted runner)
|
- name: Verify build dependencies
|
||||||
run: |
|
run: |
|
||||||
missing=0
|
missing=0
|
||||||
for tool in cmake ninja protoc; do
|
for tool in cmake ninja protoc; do
|
||||||
|
|||||||
@@ -11,16 +11,19 @@ on:
|
|||||||
- ".github/workflows/host.yml"
|
- ".github/workflows/host.yml"
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build Avalonia host
|
name: Build Avalonia host
|
||||||
runs-on: [self-hosted, Linux, X64]
|
runs-on: [self-hosted, Linux, X64, co-server]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
|
||||||
- uses: actions/setup-dotnet@v4
|
- uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9
|
||||||
# The runner user cannot write to system /usr/share/dotnet; install the
|
|
||||||
# pinned SDK into a runner-writable, cached path instead.
|
|
||||||
env:
|
env:
|
||||||
DOTNET_INSTALL_DIR: ${{ runner.tool_cache }}/dotnet
|
DOTNET_INSTALL_DIR: ${{ runner.tool_cache }}/dotnet
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -1,9 +1,5 @@
|
|||||||
name: Open Gitea PR on merge to main
|
name: Open Gitea PR on merge to main
|
||||||
|
|
||||||
# When main changes on GitHub (i.e. after a PR is merged here), push those
|
|
||||||
# commits to a branch on Gitea and open a pull request there, so the same
|
|
||||||
# change can be reviewed and landed on the Gitea side. One-way: GitHub -> Gitea.
|
|
||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches: [main]
|
branches: [main]
|
||||||
@@ -14,15 +10,12 @@ permissions:
|
|||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
open-gitea-pr:
|
open-gitea-pr:
|
||||||
# GitHub-hosted runners are billing-blocked for this org, so the hosted job
|
runs-on: [self-hosted, Linux, X64, co-server-sync]
|
||||||
# never started. Run on the self-hosted runner, which also has LAN access to
|
|
||||||
# the Gitea host. This workflow only fires on push to main (never on PRs from
|
|
||||||
# forks), so it is safe on the private runner.
|
|
||||||
runs-on: [self-hosted, Linux, X64]
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
|
persist-credentials: false
|
||||||
|
|
||||||
- name: Push main to Gitea and open a pull request
|
- name: Push main to Gitea and open a pull request
|
||||||
env:
|
env:
|
||||||
@@ -33,38 +26,60 @@ jobs:
|
|||||||
SYNC_BRANCH: sync/from-github
|
SYNC_BRANCH: sync/from-github
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
umask 077
|
||||||
|
|
||||||
if [ -z "${GITEA_TOKEN:-}" ]; then
|
if [ -z "${GITEA_TOKEN:-}" ]; then
|
||||||
echo "::error::Missing GITEA_TOKEN secret. Add a Gitea access token as a"
|
echo "::error::Missing GITEA_TOKEN repository secret."
|
||||||
echo "::error::repository secret named GITEA_TOKEN (Settings -> Secrets and"
|
|
||||||
echo "::error::variables -> Actions -> New repository secret)."
|
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
git config user.name "github-sync"
|
askpass="${RUNNER_TEMP}/gitea-askpass-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}.sh"
|
||||||
|
header_file="${RUNNER_TEMP}/gitea-header-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}"
|
||||||
|
response_file="${RUNNER_TEMP}/gitea-pr-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}.json"
|
||||||
|
|
||||||
|
cleanup() {
|
||||||
|
git remote remove gitea >/dev/null 2>&1 || true
|
||||||
|
rm -f -- "$askpass" "$header_file" "$response_file"
|
||||||
|
}
|
||||||
|
trap cleanup EXIT
|
||||||
|
|
||||||
|
cat > "$askpass" <<'EOF'
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
case "$1" in
|
||||||
|
*Username*) printf '%s\n' "${GITEA_USER:?}" ;;
|
||||||
|
*Password*) printf '%s\n' "${GITEA_TOKEN:?}" ;;
|
||||||
|
*) exit 1 ;;
|
||||||
|
esac
|
||||||
|
EOF
|
||||||
|
chmod 700 "$askpass"
|
||||||
|
printf 'Authorization: token %s\n' "$GITEA_TOKEN" > "$header_file"
|
||||||
|
chmod 600 "$header_file"
|
||||||
|
|
||||||
|
export GIT_ASKPASS="$askpass"
|
||||||
|
export GIT_TERMINAL_PROMPT=0
|
||||||
|
|
||||||
|
git config user.name "github-sync"
|
||||||
git config user.email "github-sync@users.noreply.github.com"
|
git config user.email "github-sync@users.noreply.github.com"
|
||||||
|
git remote remove gitea >/dev/null 2>&1 || true
|
||||||
|
git remote add gitea "https://${GITEA_HOST}/${GITEA_REPO}.git"
|
||||||
|
git -c credential.helper= -c credential.useHttpPath=true \
|
||||||
|
push -f gitea "HEAD:refs/heads/${SYNC_BRANCH}"
|
||||||
|
|
||||||
# Mirror the current main onto a dedicated Gitea branch. Force is safe:
|
http_code=$(curl -sS -o "$response_file" -w "%{http_code}" -X POST \
|
||||||
# this branch is owned by the automation and only ever tracks GitHub main.
|
|
||||||
git remote add gitea "https://${GITEA_USER}:${GITEA_TOKEN}@${GITEA_HOST}/${GITEA_REPO}.git"
|
|
||||||
git push -f gitea "HEAD:refs/heads/${SYNC_BRANCH}"
|
|
||||||
|
|
||||||
# Open a PR on Gitea: sync/from-github -> main. If one is already open,
|
|
||||||
# the push above has already updated it, so a 409 is success too.
|
|
||||||
http_code=$(curl -sS -o /tmp/gitea_pr.json -w "%{http_code}" -X POST \
|
|
||||||
"https://${GITEA_HOST}/api/v1/repos/${GITEA_REPO}/pulls" \
|
"https://${GITEA_HOST}/api/v1/repos/${GITEA_REPO}/pulls" \
|
||||||
-H "Authorization: token ${GITEA_TOKEN}" \
|
-H "@${header_file}" \
|
||||||
-H "Content-Type: application/json" \
|
-H "Content-Type: application/json" \
|
||||||
-d "{\"title\":\"Sync from GitHub main\",\"head\":\"${SYNC_BRANCH}\",\"base\":\"main\",\"body\":\"Automated: GitHub main was updated. Review and merge to land it on Gitea.\"}")
|
-d "{\"title\":\"Sync from GitHub main\",\"head\":\"${SYNC_BRANCH}\",\"base\":\"main\",\"body\":\"GitHub main was updated. Review and merge to land it on Gitea.\"}")
|
||||||
|
|
||||||
echo "Gitea pulls API returned HTTP ${http_code}"
|
echo "Gitea pulls API returned HTTP ${http_code}"
|
||||||
cat /tmp/gitea_pr.json || true
|
cat "$response_file" || true
|
||||||
echo
|
echo
|
||||||
|
|
||||||
if [ "${http_code}" = "201" ]; then
|
if [ "$http_code" = "201" ]; then
|
||||||
echo "Opened a new Gitea pull request."
|
echo "Opened a new Gitea pull request."
|
||||||
elif [ "${http_code}" = "409" ] || grep -qiE "already exist|issue_exist" /tmp/gitea_pr.json; then
|
elif [ "$http_code" = "409" ] || grep -qiE "already exist|issue_exist" "$response_file"; then
|
||||||
echo "A Gitea PR from ${SYNC_BRANCH} is already open; it now has the latest commits."
|
echo "A Gitea PR from ${SYNC_BRANCH} is already open; it now has the latest commits."
|
||||||
else
|
else
|
||||||
echo "::warning::Unexpected Gitea response (${http_code}). The branch was pushed;"
|
echo "::error::Unexpected Gitea response (${http_code})."
|
||||||
echo "::warning::open the PR manually on Gitea if it did not appear."
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -1,37 +1,34 @@
|
|||||||
name: Publish Host (Avalonia)
|
name: Publish Host (Avalonia)
|
||||||
|
|
||||||
# Produces self-contained, single-file Server Host binaries for Windows and
|
|
||||||
# Linux. No .NET runtime is required on the target machine. Runs on demand and
|
|
||||||
# on version tags; each build is uploaded as a workflow artifact.
|
|
||||||
|
|
||||||
on:
|
on:
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
push:
|
push:
|
||||||
tags:
|
tags:
|
||||||
- "host-v*"
|
- "host-v*"
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
publish:
|
publish:
|
||||||
name: Publish ${{ matrix.rid }}
|
name: Publish ${{ matrix.rid }}
|
||||||
runs-on: [self-hosted, Linux, X64]
|
runs-on: [self-hosted, Linux, X64, co-server]
|
||||||
strategy:
|
strategy:
|
||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
rid: [win-x64, linux-x64]
|
rid: [win-x64, linux-x64]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
|
||||||
- uses: actions/setup-dotnet@v4
|
- uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9
|
||||||
# The runner user cannot write to system /usr/share/dotnet; install the
|
|
||||||
# pinned SDK into a runner-writable, cached path instead.
|
|
||||||
env:
|
env:
|
||||||
DOTNET_INSTALL_DIR: ${{ runner.tool_cache }}/dotnet
|
DOTNET_INSTALL_DIR: ${{ runner.tool_cache }}/dotnet
|
||||||
with:
|
with:
|
||||||
dotnet-version: "8.0.x"
|
dotnet-version: "8.0.x"
|
||||||
|
|
||||||
- name: Publish single-file self-contained
|
- name: Publish single-file self-contained
|
||||||
# Untrimmed on purpose: the host uses reflection-based Avalonia bindings,
|
|
||||||
# which the trimmer would strip.
|
|
||||||
run: >
|
run: >
|
||||||
dotnet publish host/CommonwealthOnline.Host.csproj
|
dotnet publish host/CommonwealthOnline.Host.csproj
|
||||||
-c Release
|
-c Release
|
||||||
@@ -44,8 +41,9 @@ jobs:
|
|||||||
--nologo
|
--nologo
|
||||||
|
|
||||||
- name: Upload artifact
|
- name: Upload artifact
|
||||||
uses: actions/upload-artifact@v4
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
|
||||||
with:
|
with:
|
||||||
name: CommonwealthOnline.Host-${{ matrix.rid }}
|
name: CommonwealthOnline.Host-${{ matrix.rid }}
|
||||||
path: out/${{ matrix.rid }}/
|
path: out/${{ matrix.rid }}/
|
||||||
if-no-files-found: error
|
if-no-files-found: error
|
||||||
|
retention-days: 7
|
||||||
|
|||||||
Reference in New Issue
Block a user