mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
ci(deploy): exercise container replacement
The portable image and persistence test should run in CI rather than relying on an operator to have Docker installed locally. Add a focused ngit-ci workflow that obtains only the Docker client, curl, and jq through Nix, then builds the image, replaces the relay container, and verifies that its NIP-11 identity survives on the mounted volume. The workflow deliberately requires an explicitly mounted daemon socket and fails clearly when the operator has kept ngit-ci's secure default. This is intended for the disposable KVM guest daemon and does not weaken embedded-act hosts. Validated the workflow as YAML and listed its jobs and triggers with act 0.2.86 or newer from the ngit-ci development shell; git diff --check passes. The actual container job requires the remote runner's opted-in guest socket.
This commit is contained in:
@@ -0,0 +1,38 @@
|
||||
# ngit-ci currently evaluates push path filters but not pull-request path
|
||||
# filters, so PRs run this workflow unconditionally.
|
||||
on:
|
||||
push:
|
||||
paths:
|
||||
- ".dockerignore"
|
||||
- "Cargo.lock"
|
||||
- "Cargo.toml"
|
||||
- "Dockerfile"
|
||||
- "build.rs"
|
||||
- "compose*.yaml"
|
||||
- "deploy/**"
|
||||
- "scripts/test-container-deployment.sh"
|
||||
- "src/**"
|
||||
pull_request:
|
||||
|
||||
name: Container deployment e2e
|
||||
|
||||
jobs:
|
||||
container-deployment:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 30
|
||||
steps:
|
||||
- uses: actions/checkout@v5
|
||||
- uses: cachix/install-nix-action@v31
|
||||
with:
|
||||
nix_path: nixpkgs=channel:nixos-unstable
|
||||
- name: Require the disposable guest container daemon
|
||||
run: |
|
||||
if [[ ! -S /var/run/docker.sock ]]; then
|
||||
echo "container daemon socket is not available" >&2
|
||||
echo "this workflow requires an ngit-ci operator opt-in" >&2
|
||||
exit 1
|
||||
fi
|
||||
- name: Build, replace, and verify the container
|
||||
run: |
|
||||
nix shell nixpkgs#docker-client nixpkgs#curl nixpkgs#jq \
|
||||
--command scripts/test-container-deployment.sh
|
||||
Reference in New Issue
Block a user