~bigbes/sr-ht-compare

ref: 0b9a8233d3735b5c609c92af5f0ac16d95c5e261 sr-ht-compare/.build.yml -rw-r--r-- 4.8 KiB
0b9a8233 — bigbes deps: sr-ht-ecore whose middleware reports panics through slog 10 days ago
                                                                                
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
image: alpine/edge
packages:
  - abuild
  - curl
  - go
  - git
  - rclone
secrets:
  # File secret `apk-ci-s3`, installed at ~/.apk-ci.env, containing
  # APK_CI_S3_ACCESS_KEY / APK_CI_S3_SECRET_KEY for the Garage `repo` bucket.
  - apk-ci-s3
  # S3 credentials for the cacher CI cache (Garage `docker-cache` bucket),
  # same pair the bencher and ci-cacher builds use.
  - 7dde4219-0783-4581-a67d-c94749de3600   # ~/.s3-cache-key-id
  - 0e5b3530-6f19-4f30-9b73-9339dd382e46   # ~/.s3-cache-key-secret
sources:
  - https://git.srht.bigb.es/~bigbes/sr-ht-compare
environment:
  REPO: sr-ht-compare
  APK_REPO: alpine/v3.22/bigbes/x86_64
  S3_BUCKET: repo
  S3_ENDPOINT: https://s3.bigb.es
submitter:
  git.sr.ht:
    allow-refs:
      - refs/heads/master
tasks:
  - keygen: |
      # abuild insists on signing what it builds, but this key is deliberately
      # throwaway: generated per build, dies with the VM, trusted by nothing.
      # Clients verify against the index instead, which is rebuilt and signed on
      # phoebe by the garage stack's apk-mirror service — it indexes this repo
      # with --allow-untrusted precisely because of this.
      #
      # -i installs the public half into /etc/apk/keys. Without it abuild's own
      # final "update the local repository index" step dies with UNTRUSTED
      # signature, after having built the package perfectly well.
      SUDO=sudo abuild-keygen -a -n -i -q
  - version: |
      cd "$REPO"
      ver="0.0.$(git rev-list --count HEAD)"
      sed -i "s/^pkgver=.*/pkgver=$ver/" APKBUILD
      echo "export PKGVER=$ver" >> ~/.buildenv
      echo "building $ver"
  - cacher: |
      # S3-backed CI cache helper (go.bigb.es/cacher), dogfooded from its own
      # published release — the same bootstrap the bencher/ci-cacher builds use.
      mkdir -p ~/.local/bin
      curl -sSL "https://bigbes.pages.srht.bigb.es/ci-cacher/cacher-linux-amd64" \
        -o ~/.local/bin/cacher
      chmod +x ~/.local/bin/cacher
      echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.buildenv
      export PATH="$HOME/.local/bin:$PATH"
      cacher init \
        --endpoint    https://s3.bigb.es \
        --region      garage \
        --bucket      docker-cache \
        --prefix      sr-ht-compare/deps \
        --key-file    ~/.s3-cache-key-id \
        --secret-file ~/.s3-cache-key-secret
  - cache_restore: |
      # Restore the Go module and build caches, both keyed by go.sum: the
      # dependency tree dominates compile time, and it only changes when go.sum
      # does. A miss is just a cold build, never an error.
      KEY_MOD=$(cacher key "gomod/{hash}.tar.zst" --hash-from "$REPO/go.sum")
      KEY_GOC=$(cacher key "gocache/{hash}.tar.zst" --hash-from "$REPO/go.sum")
      echo "export KEY_MOD=$KEY_MOD KEY_GOC=$KEY_GOC" >> ~/.buildenv
      # abuild redirects the Go caches into its throwaway $tmpdir (and an
      # upstream typo slaves GOMODCACHE to GOCACHE), so env exports here can't
      # stick — the APKBUILD's build() re-pins both to these home locations.
      cacher dir download "$KEY_MOD" ~/go/pkg/mod || true
      cacher dir download "$KEY_GOC" ~/.cache/go-build || true
  - build: |
      cd "$REPO"
      # -d: makedepends are already installed via `packages:` above, so skip
      # abuild's own dependency resolution (which would want to sudo apk add).
      REPODEST=$HOME/packages abuild -d
      find "$HOME/packages" -name '*.apk'
  - cache_save: |
      # Seed the caches only when this go.sum has no entry yet — on a hit the
      # tarballs are already up there and re-uploading identical bytes is waste.
      cacher exists "$KEY_MOD" || cacher dir upload "$KEY_MOD" ~/go/pkg/mod
      cacher exists "$KEY_GOC" || cacher dir upload "$KEY_GOC" ~/.cache/go-build
  - publish: |
      set +x   # never echo the S3 credentials into the build log
      . ~/.apk-ci.env
      export RCLONE_CONFIG_GARAGE_TYPE=s3
      export RCLONE_CONFIG_GARAGE_PROVIDER=Other
      export RCLONE_CONFIG_GARAGE_ENDPOINT="$S3_ENDPOINT"
      export RCLONE_CONFIG_GARAGE_REGION=garage
      export RCLONE_CONFIG_GARAGE_FORCE_PATH_STYLE=true
      export RCLONE_CONFIG_GARAGE_ACCESS_KEY_ID="$APK_CI_S3_ACCESS_KEY"
      export RCLONE_CONFIG_GARAGE_SECRET_ACCESS_KEY="$APK_CI_S3_SECRET_KEY"
      set -x
      # Upload only; never delete. Old versions stay so a pinned deployment can
      # always be rebuilt — the same reason the upstream mirror is append-only.
      # abuild nests output under $REPODEST/<repo>/<arch>/, so flatten by
      # uploading each file to a fixed prefix rather than mirroring the tree.
      find "$HOME/packages" -name '*.apk' -print | while read -r f; do
        rclone copyto "$f" "garage:$S3_BUCKET/$APK_REPO/$(basename "$f")"
        echo "uploaded $(basename "$f")"
      done
      echo "published; apk-mirror on phoebe re-indexes within 15 minutes"