Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c7965e787c | ||
|
|
96021e7795 | ||
|
|
74b3b9e869 |
+6
-28
@@ -2,38 +2,16 @@
|
|||||||
# node:24-alpine + python3/make/g++/postgresql-client + pnpm + a warm pnpm
|
# node:24-alpine + python3/make/g++/postgresql-client + pnpm + a warm pnpm
|
||||||
# store. The install step resolves from the baked store (--prefer-offline)
|
# store. The install step resolves from the baked store (--prefer-offline)
|
||||||
# instead of paying a ~731s cold fetch + native compile every run.
|
# instead of paying a ~731s cold fetch + native compile every run.
|
||||||
#
|
|
||||||
# PINNED to an immutable lock-tag (#1328, brain D27): ci-image.yml pushes
|
|
||||||
# lock-<sha256(pnpm-lock.yaml)[:12]> atomically with :latest, so the two are
|
|
||||||
# byte-identical at push time. A mutable :latest resolves per-pod at pull time
|
|
||||||
# on the k8s backend, which made CI verdicts non-reproducible (same tree, same
|
|
||||||
# config, different images across runs; see #1324 comment 23382/23386). The pin
|
|
||||||
# changes ONLY through reviewed commits; a wrong tag fails loudly at image pull.
|
|
||||||
#
|
|
||||||
# Bump procedure: when a recipe change (pnpm-lock.yaml / Dockerfile.ci) lands on
|
|
||||||
# main, ci-image.yml pushes lock-<new>; a follow-up PR updates this anchor.
|
|
||||||
# Until then pipelines keep the old pin: reproducible, with the documented
|
|
||||||
# network-fallback lag (frozen-lockfile resolves missing packages from network).
|
|
||||||
# Known limitation: lock- addresses the lockfile only, so a Dockerfile-only
|
|
||||||
# change re-pushes the same tag with new content (#1328 follow-up: recipe-hash).
|
|
||||||
variables:
|
variables:
|
||||||
- &node_image 'git.mosaicstack.dev/mosaicstack/stack/ci-base:lock-9cb7ffcd8828'
|
- &node_image 'git.mosaicstack.dev/mosaicstack/stack/ci-base:latest'
|
||||||
- &enable_pnpm 'corepack enable'
|
- &enable_pnpm 'corepack enable'
|
||||||
|
|
||||||
when:
|
when:
|
||||||
# PR + manual CI run on any branch: the pull_request pipeline is the merge
|
# PR + manual CI run on any branch — the pull_request pipeline is the merge gate.
|
||||||
# gate (next is protected and the default branch since 2026-08-19).
|
# push CI is restricted to protected branches (main) so a feature-branch push no
|
||||||
# Push CI runs on main only. next deliberately runs NO push ci: post-merge
|
# longer fires a redundant SECOND pipeline alongside its PR pipeline. This ~halves
|
||||||
# verification on next is carried by publish.yml's `verify` step
|
# CI load on the storage-constrained runner with zero loss of gating (branch
|
||||||
# (pnpm verify:release), which mirrors this pipeline's complete mandatory
|
# protection requires no push/ci status context; main still gets full push CI).
|
||||||
# set step-for-step, enforced by scripts/verify-release.test.mjs. PR CI
|
|
||||||
# tests the PR HEAD tree (refs/pull/N/head, measured 2026-08-19), not a
|
|
||||||
# merge ref, so if next advances before a merge the landed tree differs
|
|
||||||
# from the tested one; publish verify re-runs the full set on the landed
|
|
||||||
# tree (PGlite path). Measured 2026-08-19: the 21 most recent push events
|
|
||||||
# on next each ran exactly one pipeline (publish), zero ci.
|
|
||||||
# Keeping push ci off next also avoids a redundant second full-suite run
|
|
||||||
# per merge on the storage-constrained runner.
|
|
||||||
- event: [pull_request, manual]
|
- event: [pull_request, manual]
|
||||||
- event: push
|
- event: push
|
||||||
branch: main
|
branch: main
|
||||||
|
|||||||
@@ -18,12 +18,7 @@
|
|||||||
variables:
|
variables:
|
||||||
# Pre-baked CI base (see .woodpecker/ci-image.yml): node:24-alpine +
|
# Pre-baked CI base (see .woodpecker/ci-image.yml): node:24-alpine +
|
||||||
# toolchain + warm pnpm store. Kills the second cold install publish pays.
|
# toolchain + warm pnpm store. Kills the second cold install publish pays.
|
||||||
# PINNED to the immutable lock-tag, not :latest (#1328, brain D27): a mutable
|
- &node_image 'git.mosaicstack.dev/mosaicstack/stack/ci-base:latest'
|
||||||
# tag resolves per-pod at pull time on the k8s backend and made CI verdicts
|
|
||||||
# non-reproducible (#1324). Byte-identical to :latest at pin time (pushed
|
|
||||||
# atomically by the same kaniko run, main 712c770, 2026-07-26). Bump only via
|
|
||||||
# reviewed PR, per the procedure in .woodpecker/ci.yml's header comment.
|
|
||||||
- &node_image 'git.mosaicstack.dev/mosaicstack/stack/ci-base:lock-9cb7ffcd8828'
|
|
||||||
- &enable_pnpm 'corepack enable'
|
- &enable_pnpm 'corepack enable'
|
||||||
# Heavy kaniko image builds (~25 min) — gate them so a merge that only touches
|
# Heavy kaniko image builds (~25 min) — gate them so a merge that only touches
|
||||||
# the npm-only CLI (@mosaicstack/mosaic) or docs does NOT rebuild the platform
|
# the npm-only CLI (@mosaicstack/mosaic) or docs does NOT rebuild the platform
|
||||||
|
|||||||
@@ -11,8 +11,13 @@ Git operations via Mosaic wrapper scripts. Platform-aware (Gitea or GitHub).
|
|||||||
|
|
||||||
Scripts auto-detect platform from git remote. Run from inside the repo directory.
|
Scripts auto-detect platform from git remote. Run from inside the repo directory.
|
||||||
|
|
||||||
Credentials come from the framework credentials loader (never from a shared env
|
For force-merge (branch protection bypass):
|
||||||
file):
|
|
||||||
|
```bash
|
||||||
|
GITEA_TOKEN=$(cat ~/.config/mosaic/credentials/gitea.env | grep TOKEN | cut -d= -f2)
|
||||||
|
```
|
||||||
|
|
||||||
|
Or use the credentials loader:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
source ~/.config/mosaic/tools/_lib/credentials.sh
|
source ~/.config/mosaic/tools/_lib/credentials.sh
|
||||||
@@ -81,10 +86,14 @@ cd ~/src/<repo>
|
|||||||
~/.config/mosaic/tools/git/pr-merge.sh -n <pr#> -d
|
~/.config/mosaic/tools/git/pr-merge.sh -n <pr#> -d
|
||||||
```
|
```
|
||||||
|
|
||||||
Branch protection is a gate, not an obstacle: if it blocks a merge, fix the cause —
|
**Force-merge bypassing branch protection:**
|
||||||
a failing check, a moved head, or a missing review. Never bypass it with a raw
|
|
||||||
API call, a shared credential, or `force_merge`. Exceptional cases go to the
|
```bash
|
||||||
operator or the coordinating seat, still merged through the wrapper.
|
GITEA_TOKEN=$(cat ~/.config/mosaic/credentials/gitea.env | grep TOKEN | cut -d= -f2)
|
||||||
|
curl -X POST "https://git.mosaicstack.dev/api/v1/repos/<org>/<repo>/pulls/<PR>/merge" \
|
||||||
|
-H "Authorization: token $GITEA_TOKEN" -H "Content-Type: application/json" \
|
||||||
|
-d '{"Do":"squash","force_merge":true}'
|
||||||
|
```
|
||||||
|
|
||||||
## Notes
|
## Notes
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user