# Fast feedback: this finishes in seconds, so it is not held behind the
3
3
# suite.
4
4
build:
5
image:localhost/gitbay-ci:1
5
6
steps:
6
7
- go build ./...
7
8
- go vet ./...
@@ -12,6 +13,7 @@ jobs:
12
13
# The 20m is under the runner's own 30m limit, so go times out first and
13
14
# says which test hung instead of the runner killing it blind.
14
15
test:
16
image:localhost/gitbay-ci:1
15
17
steps:
16
18
- missing=""; for t in git git-lfs gpg; do command -v "$t" >/dev/null || missing="$missing $t"; done; test -x /usr/sbin/sshd || missing="$missing sshd"; test -z "$missing" || { echo "runner is missing:$missing"; exit 1; }
17
19
- go test ./... -count=1 -timeout 20m
@@ -31,6 +33,7 @@ jobs:
31
33
# `build trigger krz/gitbay vuln` runs it on demand before a release
32
34
# (#177).
33
35
vuln:
36
image:localhost/gitbay-ci:1
34
37
schedule:"0 3 * * *"
35
38
steps:
36
39
- go run golang.org/x/vuln/cmd/govulncheck@latest ./...
@@ -53,6 +56,7 @@ jobs:
53
56
# linux-x64 bundle carries its own JRE, which is why the host needs no
54
57
# Java.
55
58
sonar:
59
image:localhost/gitbay-ci:1
56
60
schedule:"30 3 * * *"
57
61
steps:
58
62
- |
.gitbay/wiki/Admin.org+16
@@ -416,6 +416,22 @@ where every repository is trusted. There is no automatic fallback: a
416
416
runner started with =-isolation podman= that cannot find a working
417
417
podman exits rather than running a build unsandboxed.
418
418
419
gitbay's own jobs name =localhost/gitbay-ci:1=, built from
420
=deploy/Containerfile.ci= on the runner host. A job's image must carry
421
what its steps need: the suite drives real git, git-lfs, gpg and sshd and
422
asserts they exist before running, so the stock runner default would fail