name: Preflight # Manual, one-shot verification that the runner can actually do everything # the release workflows assume: build a container image, emulate a foreign # architecture, push to this Gitea instance's registry, push a Helm chart via # OCI, and reach the Issues API. None of the four existing Gitea Actions # workflows in this org build a container image before this repo — so none # of that is proven, only assumed. Run this BEFORE relying on release-image.yaml # or rebuild.yaml, and again after any Gitea/runner upgrade. # # See docs/operations.md for the escalation ladder if any job here fails. on: workflow_dispatch: {} jobs: docker-build: runs-on: ubuntu-22.04 steps: - uses: actions/checkout@v4 - uses: docker/setup-buildx-action@v3 - name: Build aptly-server for the native arch only (no push) uses: docker/build-push-action@v6 with: context: . file: images/aptly-server/Dockerfile push: false tags: preflight/aptly-server:local qemu-multiarch: runs-on: ubuntu-22.04 needs: docker-build steps: - uses: actions/checkout@v4 - uses: docker/setup-qemu-action@v3 - uses: docker/setup-buildx-action@v3 - name: Build for linux/amd64,linux/arm64 (no push) uses: docker/build-push-action@v6 with: context: . file: images/aptly-server/Dockerfile platforms: linux/amd64,linux/arm64 push: false registry-push: runs-on: ubuntu-22.04 needs: qemu-multiarch steps: - uses: actions/checkout@v4 - name: Verify registry secrets are set run: | test -n "${{ secrets.REGISTRY_USER }}" || { echo "::error::REGISTRY_USER is not set"; exit 1; } test -n "${{ secrets.REGISTRY_TOKEN }}" || { echo "::error::REGISTRY_TOKEN (a Personal Access Token with write:package) is not set. GITEA_TOKEN cannot authorize package pushes on Gitea — see docs/operations.md."; exit 1; } - uses: docker/login-action@v3 with: registry: git.morlana.online username: ${{ secrets.REGISTRY_USER }} password: ${{ secrets.REGISTRY_TOKEN }} - uses: docker/setup-qemu-action@v3 - uses: docker/setup-buildx-action@v3 - name: Push a throwaway multi-arch tag uses: docker/build-push-action@v6 with: context: . file: images/aptly-server/Dockerfile platforms: linux/amd64,linux/arm64 push: true tags: git.morlana.online/f.weber/aptly:preflight-${{ gitea.sha }} - name: Verify the manifest list has both platforms run: | docker buildx imagetools inspect git.morlana.online/f.weber/aptly:preflight-${{ gitea.sha }} helm-oci-push: runs-on: ubuntu-22.04 steps: - uses: actions/checkout@v4 - uses: azure/setup-helm@v4.3.0 with: version: ${{ vars.HELM_VERSION || '3.16.4' }} - name: helm registry login run: | echo "${{ secrets.REGISTRY_TOKEN }}" | helm registry login git.morlana.online \ --username "${{ secrets.REGISTRY_USER }}" --password-stdin - name: Package and push a throwaway chart version run: | helm package charts/aptly --version 0.0.0-preflight --app-version preflight helm push aptly-0.0.0-preflight.tgz oci://git.morlana.online/f.weber/charts - name: Verify it is pullable run: | helm show chart oci://git.morlana.online/f.weber/charts/aptly --version 0.0.0-preflight issues-api: runs-on: ubuntu-22.04 steps: - name: Open and close a test issue (proves rebuild.yaml's failure alert path) env: GITEA_API: https://git.morlana.online/api/v1 TOKEN: ${{ secrets.REGISTRY_TOKEN }} run: | issue_number=$(curl -fsS -X POST "${GITEA_API}/repos/${{ gitea.repository }}/issues" \ -H "Authorization: token ${TOKEN}" -H "Content-Type: application/json" \ -d '{"title":"[preflight] issues API check","body":"Created by preflight.yaml — safe to close/delete."}' \ | jq -r '.number') curl -fsS -X PATCH "${GITEA_API}/repos/${{ gitea.repository }}/issues/${issue_number}" \ -H "Authorization: token ${TOKEN}" -H "Content-Type: application/json" \ -d '{"state":"closed"}' >/dev/null echo "opened and closed issue #${issue_number}"