Files
Commonwealth-Online-Server/.github/workflows/open-gitea-pr.yml
T

107 lines
3.9 KiB
YAML

name: Open Gitea PR on merge to main
on:
push:
branches: [main]
workflow_dispatch:
permissions:
contents: read
issues: write
jobs:
open-gitea-pr:
if: github.event_name != 'push' || !contains(github.event.head_commit.message, '[deploy-runner-fleet-sync]')
runs-on: [self-hosted, Linux, X64, co-server-sync]
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
fetch-depth: 0
persist-credentials: false
- name: Push main to Gitea and open a pull request
env:
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
GITEA_HOST: git.zambazosmedia.group
GITEA_USER: nomad
GITEA_REPO: Commonwealth-Online/Commonwealth-Online-Server
SYNC_BRANCH: sync/from-github
run: |
set -euo pipefail
umask 077
if [ -z "${GITEA_TOKEN:-}" ]; then
echo "::error::Missing GITEA_TOKEN repository secret."
exit 1
fi
askpass="${RUNNER_TEMP}/gitea-askpass-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}.sh"
header_file="${RUNNER_TEMP}/gitea-header-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}"
response_file="${RUNNER_TEMP}/gitea-pr-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}.json"
cleanup() {
git remote remove gitea >/dev/null 2>&1 || true
rm -f -- "$askpass" "$header_file" "$response_file"
}
trap cleanup EXIT
cat > "$askpass" <<'EOF'
#!/usr/bin/env bash
case "$1" in
*Username*) printf '%s\n' "${GITEA_USER:?}" ;;
*Password*) printf '%s\n' "${GITEA_TOKEN:?}" ;;
*) exit 1 ;;
esac
EOF
chmod 700 "$askpass"
printf 'Authorization: token %s\n' "$GITEA_TOKEN" > "$header_file"
chmod 600 "$header_file"
export GIT_ASKPASS="$askpass"
export GIT_TERMINAL_PROMPT=0
git config user.name "github-sync"
git config user.email "github-sync@users.noreply.github.com"
git remote remove gitea >/dev/null 2>&1 || true
git remote add gitea "https://${GITEA_HOST}/${GITEA_REPO}.git"
git -c credential.helper= -c credential.useHttpPath=true \
push -f gitea "HEAD:refs/heads/${SYNC_BRANCH}"
http_code=$(curl -sS -o "$response_file" -w "%{http_code}" -X POST \
"https://${GITEA_HOST}/api/v1/repos/${GITEA_REPO}/pulls" \
-H "@${header_file}" \
-H "Content-Type: application/json" \
-d "{\"title\":\"Sync from GitHub main\",\"head\":\"${SYNC_BRANCH}\",\"base\":\"main\",\"body\":\"GitHub main was updated. Review and merge to land it on Gitea.\"}")
echo "Gitea pulls API returned HTTP ${http_code}"
cat "$response_file" || true
echo
if [ "$http_code" = "201" ]; then
echo "Opened a new Gitea pull request."
elif [ "$http_code" = "409" ] || grep -qiE "already exist|issue_exist" "$response_file"; then
echo "A Gitea PR from ${SYNC_BRANCH} is already open; it now has the latest commits."
else
echo "::error::Unexpected Gitea response (${http_code})."
exit 1
fi
deploy-runner-fleet:
name: One-shot runner fleet deployment via sync runner
if: github.event_name == 'push' && github.ref == 'refs/heads/main' && contains(github.event.head_commit.message, '[deploy-runner-fleet-sync]')
runs-on: [self-hosted, Linux, X64, co-server-sync]
concurrency:
group: one-shot-runner-fleet-deployment-sync
cancel-in-progress: false
timeout-minutes: 30
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
persist-credentials: false
- name: Deploy scheduler and runner fleet
shell: bash
env:
GH_STATUS_TOKEN: ${{ github.token }}
run: bash .github/ops/deploy-runner-fleet.sh