# Fast feedback: this finishes in seconds, so it is not held behind the
2
# Fast feedback: this finishes in seconds, so it is not held behind the
3
# suite.
3
# suite.
4
build:
4
build:
5
image:localhost/gitbay-ci:1
5
steps:
6
steps:
6
- go build ./...
7
- go build ./...
7
- go vet ./...
8
- go vet ./...
@@ -12,6 +13,7 @@ jobs:
12
# The 20m is under the runner's own 30m limit, so go times out first and
13
# The 20m is under the runner's own 30m limit, so go times out first and
13
# says which test hung instead of the runner killing it blind.
14
# says which test hung instead of the runner killing it blind.
14
test:
15
test:
16
image:localhost/gitbay-ci:1
15
steps:
17
steps:
16
- missing=""; for t in git git-lfs gpg; do command -v "$t" >/dev/null || missing="$missing $t"; done; test -x /usr/sbin/sshd || missing="$missing sshd"; test -z "$missing" || { echo "runner is missing:$missing"; exit 1; }
18
- missing=""; for t in git git-lfs gpg; do command -v "$t" >/dev/null || missing="$missing $t"; done; test -x /usr/sbin/sshd || missing="$missing sshd"; test -z "$missing" || { echo "runner is missing:$missing"; exit 1; }
17
- go test ./... -count=1 -timeout 20m
19
- go test ./... -count=1 -timeout 20m
@@ -31,6 +33,7 @@ jobs:
31
# `build trigger krz/gitbay vuln` runs it on demand before a release
33
# `build trigger krz/gitbay vuln` runs it on demand before a release
32
# (#177).
34
# (#177).
33
vuln:
35
vuln:
36
image:localhost/gitbay-ci:1
34
schedule:"0 3 * * *"
37
schedule:"0 3 * * *"
35
steps:
38
steps:
36
- go run golang.org/x/vuln/cmd/govulncheck@latest ./...
39
- go run golang.org/x/vuln/cmd/govulncheck@latest ./...
@@ -53,6 +56,7 @@ jobs:
53
# linux-x64 bundle carries its own JRE, which is why the host needs no
56
# linux-x64 bundle carries its own JRE, which is why the host needs no
54
# Java.
57
# Java.
55
sonar:
58
sonar:
59
image:localhost/gitbay-ci:1
56
schedule:"30 3 * * *"
60
schedule:"30 3 * * *"
57
steps:
61
steps:
58
- |
62
- |
.gitbay/wiki/Admin.org+16
@@ -416,6 +416,22 @@ where every repository is trusted. There is no automatic fallback: a
416
runner started with =-isolation podman= that cannot find a working
416
runner started with =-isolation podman= that cannot find a working
417
podman exits rather than running a build unsandboxed.
417
podman exits rather than running a build unsandboxed.
418
418
419
gitbay's own jobs name =localhost/gitbay-ci:1=, built from
420
=deploy/Containerfile.ci= on the runner host. A job's image must carry
421
what its steps need: the suite drives real git, git-lfs, gpg and sshd and
422
asserts they exist before running, so the stock runner default would fail