.gitbay/ci.yml

41 lines · 2449 bytes

 1# Weekly man-page catalog sync, ported from the GitHub workflow. The change
 2# lands as an MR for review, never straight on main. The script refuses to
 3# write a suspiciously short list, so an upstream markup change can't
 4# silently gut the catalog.
 5#
 6# The build runs in a container on the instance's runner, which holds no
 7# key of its own inside the container. The push and the merge request go
 8# over SSH as the hutch-ci account (write on this repository): its private
 9# key arrives as the BOT_SSH_KEY build secret and is written into the
10# workspace beside an ssh config every ssh and git call is pointed at
11# with -F. GITBAY_SSH, set by the runner, is the instance as this build
12# reaches it.
13jobs:
14  # Reads every view file for icon-only controls without accessibility
15  # labels — no build, no simulator. The xcodebuild test plan is not
16  # ported: it needs a macOS runner this instance does not have.
17  accessibility:
18    steps:
19      - python3 scripts/check_accessibility.py
20  sync-man-pages:
21    schedule: "0 6 * * 1"
22    steps:
23      - python3 scripts/sync_man_pages.py
24      - |
25        set -e
26        if git diff --quiet -- Hutch/Resources/man-pages.json; then
27          echo "catalog unchanged"
28          exit 0
29        fi
30        test -n "$BOT_SSH_KEY" || { echo "ERROR: BOT_SSH_KEY secret is not set"; exit 1; }
31        test -n "$GITBAY_SSH" || { echo "ERROR: GITBAY_SSH is not set; the runner is too old"; exit 1; }
32        umask 077
33        printf '%s\n' "$BOT_SSH_KEY" > "$PWD/.bot_key"
34        printf 'IdentityFile %s\nIdentitiesOnly yes\nStrictHostKeyChecking accept-new\nUserKnownHostsFile %s\n' "$PWD/.bot_key" "$PWD/.known_hosts" > "$PWD/.ssh_config"
35        export GIT_SSH_COMMAND="ssh -F $PWD/.ssh_config"
36        git -c user.name=ci -c user.email=ci@gitbay.org checkout -q -B automated/man-page-catalog
37        git -c user.name=ci -c user.email=ci@gitbay.org commit -qam "Sync bundled man page catalog with man.sr.ht"
38        git push -qf "ssh://$GITBAY_SSH/krz/hutch.git" automated/man-page-catalog
39        if ! ssh -F "$PWD/.ssh_config" "$GITBAY_SSH" mr list krz/hutch --json | grep -q "automated/man-page-catalog"; then
40          ssh -F "$PWD/.ssh_config" "$GITBAY_SSH" "mr create krz/hutch --source automated/man-page-catalog --target main --title 'Sync bundled man page catalog' --body 'Automated update from scripts/sync_man_pages.py. Review the diff to Hutch/Resources/man-pages.json before merging.'"
41        fi