Compare commits
16
Commits
0.1.0
..
048a8870e6
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
048a8870e6 | ||
|
|
f0b28c81c0 | ||
|
|
1dfb979ebb | ||
|
|
f04ad3d5bc | ||
|
|
93cbfcf6b1 | ||
|
|
3e33b51d1b | ||
|
|
abbdf4410e | ||
|
|
245dfaf198 | ||
|
|
b9fe21175f | ||
|
|
5292455dbc | ||
|
|
d1ef039688 | ||
|
|
c65f86e5d5 | ||
|
|
b5bfe83140 | ||
|
|
60bf1bb3a9 | ||
|
|
24bd0270c0 | ||
|
|
475136c1e5 |
No files matched your search
+39
-4
@@ -49,15 +49,38 @@ jobs:
|
|||||||
needs: release-gate
|
needs: release-gate
|
||||||
if: needs.release-gate.outputs.skip != 'true'
|
if: needs.release-gate.outputs.skip != 'true'
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
# Bind-mount the shared pages tree so the coverage step below can write
|
# `image` extends the runner's default job image (catthehacker/act)
|
||||||
# into it. The runner whitelists this path via `container.valid_volumes`
|
# with Node 26 pre-planted in the tool cache layout, so setup-node's
|
||||||
# (docker-space `setup/gitea.sh`); `image` is omitted on purpose so the
|
# version probe hits and never downloads (see docker/Dockerfile). The
|
||||||
# runner keeps using its default job image.
|
# tag MUST equal the exact version pinned in `.node-version`; the bump
|
||||||
|
# ritual is documented in CONTRIBUTING.md § CI runner image. The volume
|
||||||
|
# bind-mounts the shared pages tree so the
|
||||||
|
# coverage step below can write into it; the runner whitelists this
|
||||||
|
# path via `container.valid_volumes` (docker-space `setup/gitea.sh`).
|
||||||
container:
|
container:
|
||||||
|
image: gitea.e1nsnull.de/tmu/act-ci:26.8.2
|
||||||
volumes:
|
volumes:
|
||||||
- /data/gitea-pages:/data/gitea-pages
|
- /data/gitea-pages:/data/gitea-pages
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
# TEMPORARY (remove once understood): the image provably carries
|
||||||
|
# the tool-cache entry (verified with `docker run --rm <image> ls
|
||||||
|
# /opt/hostedtoolcache/node/26.8.2/x64/bin`), yet setup-node still
|
||||||
|
# downloads. Print what the job container actually sees at
|
||||||
|
# runtime, mounts first — a mount over /opt/hostedtoolcache would
|
||||||
|
# hide the baked directory from the probe.
|
||||||
|
- name: Tool cache diagnostics
|
||||||
|
run: |
|
||||||
|
id
|
||||||
|
grep -E 'hostedtoolcache|workspace|overlay' /proc/mounts || true
|
||||||
|
ls -la /opt/hostedtoolcache || true
|
||||||
|
ls -la /opt/hostedtoolcache/node || true
|
||||||
|
ls -la "/opt/hostedtoolcache/node/$(tr -d '[:space:]' < .node-version)/" || true
|
||||||
|
test -f "/opt/hostedtoolcache/node/$(tr -d '[:space:]' < .node-version)/x64.complete" && echo MARKER-PRESENT || echo MARKER-MISSING
|
||||||
|
ls -la "/opt/hostedtoolcache/node/$(tr -d '[:space:]' < .node-version)/x64/bin" || true
|
||||||
|
"/opt/hostedtoolcache/node/$(tr -d '[:space:]' < .node-version)/x64/bin/node" -v || true
|
||||||
|
env | grep -iE 'RUNNER|TOOL|CACHE' || true
|
||||||
|
head -2 /etc/os-release
|
||||||
- uses: actions/setup-node@v4
|
- uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version-file: .node-version
|
node-version-file: .node-version
|
||||||
@@ -108,6 +131,10 @@ jobs:
|
|||||||
if: needs.release-gate.outputs.skip != 'true'
|
if: needs.release-gate.outputs.skip != 'true'
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
continue-on-error: true
|
continue-on-error: true
|
||||||
|
# Same baked image as `build` — without it this job re-downloads Node
|
||||||
|
# per run (see docker/Dockerfile).
|
||||||
|
container:
|
||||||
|
image: gitea.e1nsnull.de/tmu/act-ci:26.8.2
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
- uses: actions/setup-node@v4
|
- uses: actions/setup-node@v4
|
||||||
@@ -121,6 +148,10 @@ jobs:
|
|||||||
if: startsWith(gitea.ref, 'refs/tags/')
|
if: startsWith(gitea.ref, 'refs/tags/')
|
||||||
needs: build
|
needs: build
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
# Same baked image as `build` — setup-node still owns the registry-url
|
||||||
|
# `.npmrc` rewrite here; only the Node download is skipped.
|
||||||
|
container:
|
||||||
|
image: gitea.e1nsnull.de/tmu/act-ci:26.8.2
|
||||||
# The release page is created with the run's automatic Gitea token
|
# The release page is created with the run's automatic Gitea token
|
||||||
# (`github.token`), not `NPM_TOKEN`, so it needs `contents: write`.
|
# (`github.token`), not `NPM_TOKEN`, so it needs `contents: write`.
|
||||||
permissions:
|
permissions:
|
||||||
@@ -139,6 +170,10 @@ jobs:
|
|||||||
- uses: actions/setup-node@v4
|
- uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version-file: .node-version
|
node-version-file: .node-version
|
||||||
|
# Same lockfile/key as `build`, and tag runs can read caches
|
||||||
|
# saved on `main` — without this, every release pays a cold
|
||||||
|
# `npm ci` despite the warm shared npm cache.
|
||||||
|
cache: "npm"
|
||||||
registry-url: "https://registry.npmjs.org/"
|
registry-url: "https://registry.npmjs.org/"
|
||||||
- run: npm ci
|
- run: npm ci
|
||||||
# Consume the dist/ that `build` produced and gated, instead of
|
# Consume the dist/ that `build` produced and gated, instead of
|
||||||
|
|||||||
+1
-1
@@ -1 +1 @@
|
|||||||
26
|
26.8.2
|
||||||
+16
-1
@@ -7,9 +7,24 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
|||||||
|
|
||||||
## [Unreleased]
|
## [Unreleased]
|
||||||
|
|
||||||
|
## [0.1.3] - 2026-09-14
|
||||||
|
|
||||||
|
- change to custom image for CI
|
||||||
|
|
||||||
|
## [0.1.2] - 2026-09-14
|
||||||
|
|
||||||
|
- upgrade dependencies
|
||||||
|
|
||||||
|
## [0.1.1] - 2026-09-14
|
||||||
|
|
||||||
|
- upgrade dependencies
|
||||||
|
|
||||||
## [0.1.0] - 2026-09-14
|
## [0.1.0] - 2026-09-14
|
||||||
|
|
||||||
- basic setup
|
- basic setup
|
||||||
|
|
||||||
[Unreleased]: https://gitea.e1nsnull.de/tmu/tiny-pattern-ts/compare/0.1.0...main
|
[Unreleased]: https://gitea.e1nsnull.de/tmu/tiny-pattern-ts/compare/0.1.3...main
|
||||||
|
[0.1.3]: https://gitea.e1nsnull.de/tmu/tiny-pattern-ts/compare/0.1.2...0.1.3
|
||||||
|
[0.1.2]: https://gitea.e1nsnull.de/tmu/tiny-pattern-ts/compare/0.1.1...0.1.2
|
||||||
|
[0.1.1]: https://gitea.e1nsnull.de/tmu/tiny-pattern-ts/compare/0.1.0...0.1.1
|
||||||
[0.1.0]: https://gitea.e1nsnull.de/tmu/tiny-pattern-ts/compare/20308c5a6d8cccfb09b02ac2ebebd8055e91cd11...0.1.0
|
[0.1.0]: https://gitea.e1nsnull.de/tmu/tiny-pattern-ts/compare/20308c5a6d8cccfb09b02ac2ebebd8055e91cd11...0.1.0
|
||||||
@@ -90,6 +90,23 @@ This is why every test in the suite pairs an `expectTypeOf(...)` with an `assert
|
|||||||
- CI runs `npm run check` + `npm run test:ci` on every push to `main` — this is the authoritative gate. The one exception: a push headed by a release commit (`:rocket: Release x.y.z`) skips the full `build`/`maintain` jobs, because `create:release` pushes the tag for that exact commit right after and the tag run is the authoritative one (see `release-gate` in [.gitea/workflows/ci.yml](./.gitea/workflows/ci.yml)).
|
- CI runs `npm run check` + `npm run test:ci` on every push to `main` — this is the authoritative gate. The one exception: a push headed by a release commit (`:rocket: Release x.y.z`) skips the full `build`/`maintain` jobs, because `create:release` pushes the tag for that exact commit right after and the tag run is the authoritative one (see `release-gate` in [.gitea/workflows/ci.yml](./.gitea/workflows/ci.yml)).
|
||||||
- **Releases are NOT triggered by pushes.** Only the maintainer triggers a release (see [Publishing workflow](#publishing-workflow)).
|
- **Releases are NOT triggered by pushes.** Only the maintainer triggers a release (see [Publishing workflow](#publishing-workflow)).
|
||||||
|
|
||||||
|
## CI runner image
|
||||||
|
|
||||||
|
The `build` / `maintain` / `publish` jobs run in `gitea.e1nsnull.de/tmu/act-ci:<version>` ([docker/Dockerfile](./docker/Dockerfile)) — the runner's default act image with the Node distribution overlaid at the exact `/opt/hostedtoolcache` layout `actions/setup-node` probes before downloading, so no job pays the ~50 MB fetch. The image tag MUST equal the exact version pinned in `.node-version`; `release-gate` uses no Node and stays on the default image. The script is deliberately NOT an `npm run` script: building requires a docker daemon and registry credentials, so it belongs to no feedback tier — per [Script prefix convention](#script-prefix-convention), no existing prefix fits and that is the signal.
|
||||||
|
|
||||||
|
Bumping Node is one coordinated change, committed as a unit:
|
||||||
|
|
||||||
|
1. Edit `.node-version` to the new exact `x.y.z` — floats like `26` resolve to the latest patch at runtime and silently bust the baked entry; `scripts/runner-image.sh` refuses them.
|
||||||
|
2. `docker login gitea.e1nsnull.de` (user + package/access token), then `./scripts/runner-image.sh --push` — it reads the version from `.node-version` and builds/pushes `<IMAGE_REPO>:<version>`.
|
||||||
|
3. Repoint the three `container.image` tags in [.gitea/workflows/ci.yml](./.gitea/workflows/ci.yml) to the same version.
|
||||||
|
|
||||||
|
Skipping step 2 fails CI at image pull; skipping step 3 silently reverts to the per-job download.
|
||||||
|
|
||||||
|
Two invariants the image must satisfy for the probe to hit, both easy to break:
|
||||||
|
|
||||||
|
- **The `x64.complete` marker.** `actions/tool-cache` accepts a cached tool only when `<version>/<arch>.complete` exists next to the directory (`tc.find()` checks it); a plausible-looking `node/<version>/x64/` alone is ignored and the download happens anyway. See the comment in [docker/Dockerfile](./docker/Dockerfile).
|
||||||
|
- **Tag freshness.** The tag encodes only the Node version, so a Dockerfile change (like the marker above) produces _new content under an unchanged tag_. `act_runner` skips the pull when a tag of that name already exists locally (`forcePull=false` in the job log), so the runner must either force-pull (`force_pull` under `container:` in its `config.yaml`, if the installed version has it) or have the tag removed on the runner host (`docker rmi gitea.e1nsnull.de/tmu/act-ci:<version>`) after any image change. Symptom of getting this wrong: CI keeps running the previous image while the registry shows the new digest.
|
||||||
|
|
||||||
## Publishing workflow
|
## Publishing workflow
|
||||||
|
|
||||||
Publishing is CI-only by policy. Local `npm publish` is not supported. The maintainer triggers releases from `main`:
|
Publishing is CI-only by policy. Local `npm publish` is not supported. The maintainer triggers releases from `main`:
|
||||||
|
|||||||
+5
-1
@@ -35,7 +35,7 @@ Maintenance:
|
|||||||
✔ Add a minimal dir-listing webserver to the gitea docker setup (e.g. caddy `file_server browse` reusing the existing reverse proxy, or any single-binary static server, lipanski/docker-static-website) @done (9/13/2026, 9:02:37 PM)
|
✔ Add a minimal dir-listing webserver to the gitea docker setup (e.g. caddy `file_server browse` reusing the existing reverse proxy, or any single-binary static server, lipanski/docker-static-website) @done (9/13/2026, 9:02:37 PM)
|
||||||
✔ drop the `actions/upload-artifact` coverage step in favour of the shared-dir layout @done (9/13/2026, 10:37:22 PM)
|
✔ drop the `actions/upload-artifact` coverage step in favour of the shared-dir layout @done (9/13/2026, 10:37:22 PM)
|
||||||
☐ Explore serving coverage for non-tag pushes (e.g. `main/coverage`, PR previews) @low
|
☐ Explore serving coverage for non-tag pushes (e.g. `main/coverage`, PR previews) @low
|
||||||
☐ Manually verify the coverage was created on a real tag push (needs main) @low
|
✔ Manually verify the coverage was created on a real tag push (needs main) @low @done (9/14/2026, 1:55:03 PM)
|
||||||
→ design: no deploy step in CI; the webserver just exposes the shared directory (decided over Gitea Pages / Codecov — neither confirmed available/ wanted)
|
→ design: no deploy step in CI; the webserver just exposes the shared directory (decided over Gitea Pages / Codecov — neither confirmed available/ wanted)
|
||||||
☐ serve docs over self hosted server @low
|
☐ serve docs over self hosted server @low
|
||||||
☐ Add a minimal dir-listing webserver to the gitea docker setup for serving docs (reuse existing reverse proxy)
|
☐ Add a minimal dir-listing webserver to the gitea docker setup for serving docs (reuse existing reverse proxy)
|
||||||
@@ -45,3 +45,7 @@ Maintenance:
|
|||||||
☐ Add a minimal dir-listing webserver to the gitea docker setup for serving landing page (reuse existing reverse proxy)
|
☐ Add a minimal dir-listing webserver to the gitea docker setup for serving landing page (reuse existing reverse proxy)
|
||||||
☐ CI writes landing page to a shared volume keyed by project + tag (e.g. `/landing/tiny-pattern-ts/<tag>/`)
|
☐ CI writes landing page to a shared volume keyed by project + tag (e.g. `/landing/tiny-pattern-ts/<tag>/`)
|
||||||
☐ Browse to `…/tiny-pattern-ts/index.html` in the browser
|
☐ Browse to `…/tiny-pattern-ts/index.html` in the browser
|
||||||
|
☐ Stop Gitea CI re-downloading Node on every job (branch chore/fix-ci)
|
||||||
|
✔ Share the warm npm cache with the publish job @done
|
||||||
|
✔ Bake Node into the CI job image (docker/Dockerfile, container.image in ci.yml) @done
|
||||||
|
☐ Build/push gitea.e1nsnull.de/tmu/act-ci:26.8.2 and confirm setup-node skips the download (first run on the branch = acceptance test) @high
|
||||||
@@ -27,6 +27,14 @@
|
|||||||
"knope",
|
"knope",
|
||||||
"runwisp",
|
"runwisp",
|
||||||
"glab",
|
"glab",
|
||||||
|
"hostedtoolcache",
|
||||||
|
"nodebase",
|
||||||
|
"frontends",
|
||||||
|
"catthehacker",
|
||||||
|
"nsnull",
|
||||||
|
"dedup",
|
||||||
|
"dedupe",
|
||||||
|
"repoint",
|
||||||
"postversion",
|
"postversion",
|
||||||
"prebuild",
|
"prebuild",
|
||||||
"Zilla",
|
"Zilla",
|
||||||
|
|||||||
@@ -0,0 +1,51 @@
|
|||||||
|
# CI job image for the Gitea act_runner: the runner's default job image with
|
||||||
|
# Node pre-planted where actions/setup-node looks first.
|
||||||
|
#
|
||||||
|
# Why this layout: setup-node ignores `node` on PATH; its only fast path is a
|
||||||
|
# probe of /opt/hostedtoolcache/node/<version>/<arch>. Without an entry there
|
||||||
|
# it downloads the ~50 MB distribution on EVERY job (the runner's job
|
||||||
|
# containers are ephemeral, so its tool cache never survives a job). The
|
||||||
|
# official node images keep exactly the layout setup-node expects under
|
||||||
|
# /usr/local, so this layer is a pure file overlay — no scripts, no env.
|
||||||
|
#
|
||||||
|
# Why not a host bind of /opt/hostedtoolcache: binds never self-prune. Docker
|
||||||
|
# images are content-addressed: the base layers dedupe against the act image
|
||||||
|
# the host already has, and `docker image prune` / re-pulls are the cleanup
|
||||||
|
# story.
|
||||||
|
#
|
||||||
|
# NODE_VERSION must match `.node-version` exactly. setup-node resolves a float
|
||||||
|
# like `26` to the latest known patch at runtime, so a bump silently busts the
|
||||||
|
# baked entry; `.node-version` is pinned to x.y.z and scripts/runner-image.sh
|
||||||
|
# guards the coupling. Rebuild + repoint `container.image` in
|
||||||
|
# .gitea/workflows/ci.yml on every bump.
|
||||||
|
#
|
||||||
|
# The extra `nodebase` stage is load-bearing: `COPY --from=` resolves its value
|
||||||
|
# as a *stage name* at parse time, before build args exist, so
|
||||||
|
# `COPY --from=node:${NODE_VERSION}` collapses to the invalid `node:` on
|
||||||
|
# frontends that do not expand args there. ARGs declared before the first FROM
|
||||||
|
# *are* expanded in FROM, so routing through a named stage works everywhere.
|
||||||
|
|
||||||
|
# Global scope: only visible to FROM lines, but that is exactly where we need it.
|
||||||
|
ARG NODE_VERSION=26.8.2
|
||||||
|
FROM node:${NODE_VERSION} AS nodebase
|
||||||
|
|
||||||
|
FROM catthehacker/ubuntu:act-latest
|
||||||
|
|
||||||
|
# ARGs do not cross stage boundaries; redeclare (with the same default, so a
|
||||||
|
# bare `docker build -f docker/Dockerfile .` still works) for the paths below.
|
||||||
|
# Keep this default in sync with the global one above.
|
||||||
|
ARG NODE_VERSION=26.8.2
|
||||||
|
|
||||||
|
# node image: bin/ + lib/ under /usr/local → tool cache: bin/ + lib/ under <ver>/x64.
|
||||||
|
COPY --from=nodebase /usr/local /opt/hostedtoolcache/node/${NODE_VERSION}/x64
|
||||||
|
|
||||||
|
# actions/tool-cache only accepts a cached tool when the sibling marker file
|
||||||
|
# "<version>/<arch>.complete" exists — tc.find() checks it and falls back to
|
||||||
|
# downloading otherwise, however complete the directory is. The marker is what
|
||||||
|
# tc.cacheDir() writes after *it* installs a tool, so a pre-baked entry has to
|
||||||
|
# reproduce it explicitly.
|
||||||
|
RUN touch "/opt/hostedtoolcache/node/${NODE_VERSION}/x64.complete"
|
||||||
|
|
||||||
|
# Fail the build (not CI) if the overlay or the version arg were wrong.
|
||||||
|
# Shell form on purpose: exec form (`RUN [...]`) does not expand ARG values.
|
||||||
|
RUN "/opt/hostedtoolcache/node/${NODE_VERSION}/x64/bin/node" --version
|
||||||
Generated
+406
-406
File diff suppressed because it is too large.
Load diff
+3
-3
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "tiny-pattern-ts",
|
"name": "tiny-pattern-ts",
|
||||||
"version": "0.1.0",
|
"version": "0.1.3",
|
||||||
"description": "Pattern matching for TypeScript/ESM environments (F#-style, not regex)",
|
"description": "Pattern matching for TypeScript/ESM environments (F#-style, not regex)",
|
||||||
"keywords": [
|
"keywords": [
|
||||||
"adt",
|
"adt",
|
||||||
@@ -77,7 +77,7 @@
|
|||||||
"expect-type": "1.4.0",
|
"expect-type": "1.4.0",
|
||||||
"knip": "^6.34.0",
|
"knip": "^6.34.0",
|
||||||
"lefthook": "^2.1.12",
|
"lefthook": "^2.1.12",
|
||||||
"oxfmt": "^0.66.0",
|
"oxfmt": "^0.67.0",
|
||||||
"oxlint": "^1.81.0",
|
"oxlint": "^1.81.0",
|
||||||
"oxlint-tsgolint": "^7.0.2001",
|
"oxlint-tsgolint": "^7.0.2001",
|
||||||
"publint": "^0.3.24",
|
"publint": "^0.3.24",
|
||||||
@@ -87,6 +87,6 @@
|
|||||||
"node": ">=26"
|
"node": ">=26"
|
||||||
},
|
},
|
||||||
"allowScripts": {
|
"allowScripts": {
|
||||||
"lefthook@2.1.12": true
|
"lefthook@2.1.14": true
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Executable
+33
@@ -0,0 +1,33 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
# Build (and optionally push) the CI job image from docker/Dockerfile.
|
||||||
|
# Run wherever docker + registry credentials live (the runner host, or any
|
||||||
|
# machine that can reach the registry). The registry/repo below MUST match
|
||||||
|
# the `container.image` references in .gitea/workflows/ci.yml — the runner
|
||||||
|
# pulls the image by name.
|
||||||
|
#
|
||||||
|
# Usage: scripts/runner-image.sh [--push]
|
||||||
|
|
||||||
|
IMAGE_REPO="gitea.e1nsnull.de/tmu/act-ci"
|
||||||
|
|
||||||
|
NODE_VERSION="$(tr -d '[:space:]' < .node-version)"
|
||||||
|
if [[ ! "${NODE_VERSION}" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||||
|
echo "error: .node-version must be pinned to an exact x.y.z, got '${NODE_VERSION}'." >&2
|
||||||
|
echo " setup-node resolves floats like '26' to the latest patch at runtime," >&2
|
||||||
|
echo " which silently busts the tool-cache entry baked into the image." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
IMAGE="${IMAGE_REPO}:${NODE_VERSION}"
|
||||||
|
|
||||||
|
# --pull: refresh the act base layer so the derivative does not float on an
|
||||||
|
# aging default image forever (layer dedup keeps this cheap).
|
||||||
|
docker build --pull --build-arg "NODE_VERSION=${NODE_VERSION}" -t "${IMAGE}" -f docker/Dockerfile .
|
||||||
|
|
||||||
|
if [[ "${1:-}" == "--push" ]]; then
|
||||||
|
docker push "${IMAGE}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "built ${IMAGE}"
|
||||||
|
echo "reminder: bump container.image in .gitea/workflows/ci.yml to this tag"
|
||||||
Reference in new issue
Block a user