Files
ngit-grasp/.ngit/act/workflows/deployment_e2e.yaml
T
DanConwayDev 03d2b24bfe ci(deploy): exercise container replacement
The portable image and persistence test should run in CI rather than relying on an operator to have Docker installed locally.

Add a focused ngit-ci workflow that obtains only the Docker client, curl, and jq through Nix, then builds the image, replaces the relay container, and verifies that its NIP-11 identity survives on the mounted volume.

The workflow deliberately requires an explicitly mounted daemon socket and fails clearly when the operator has kept ngit-ci's secure default. This is intended for the disposable KVM guest daemon and does not weaken embedded-act hosts.

Validated the workflow as YAML and listed its jobs and triggers with act 0.2.86 or newer from the ngit-ci development shell; git diff --check passes. The actual container job requires the remote runner's opted-in guest socket.
2026-08-20 20:00:28 +00:00

39 lines
1.1 KiB
YAML

# ngit-ci currently evaluates push path filters but not pull-request path
# filters, so PRs run this workflow unconditionally.
on:
push:
paths:
- ".dockerignore"
- "Cargo.lock"
- "Cargo.toml"
- "Dockerfile"
- "build.rs"
- "compose*.yaml"
- "deploy/**"
- "scripts/test-container-deployment.sh"
- "src/**"
pull_request:
name: Container deployment e2e
jobs:
container-deployment:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v5
- uses: cachix/install-nix-action@v31
with:
nix_path: nixpkgs=channel:nixos-unstable
- name: Require the disposable guest container daemon
run: |
if [[ ! -S /var/run/docker.sock ]]; then
echo "container daemon socket is not available" >&2
echo "this workflow requires an ngit-ci operator opt-in" >&2
exit 1
fi
- name: Build, replace, and verify the container
run: |
nix shell nixpkgs#docker-client nixpkgs#curl nixpkgs#jq \
--command scripts/test-container-deployment.sh