krz/orgo

Lightning fast org-mode static site generator. fast go org-mode static-site-generator

Commit 96ed75bdbc

96ed75bdbc5df1d6de994046066467422c41e40d

parent: cca4404360

Verified · cmc ci/pages: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-11 01:11 UTC

ci: run jobs in localhost/orgo-ci and publish as orgo-ci

The image is built from .gitbay/Containerfile.ci on the runner host:
rust with clippy, the musl target and openssh-client. pages.sh and
release.sh source .gitbay/bot-ssh.sh, which writes the BOT_SSH_KEY
secret into the workspace and points ssh and git at it with -F; the
instance is GITBAY_SSH rather than the origin URL, which inside the
container is the container itself.

Closes #4

Layout: unified · split

.gitbay/Containerfile.ci added +23
@@ -0,0 +1,23 @@
1# The image orgo's CI jobs run in. gitbay's runner never pulls, so the
2# operator builds it on the runner host and .gitbay/ci.yml names it by tag.
3# The file is staged in the runner user's home first: a login shell under su
4# cannot read root's stdin, and root's session does not share /tmp with it.
5#
6# scp -P 2222 .gitbay/Containerfile.ci root@gitbay.org:/var/lib/gitbay-runner/orgo-ci.Containerfile
7# ssh -p 2222 root@gitbay.org 'chown ci-runner /var/lib/gitbay-runner/orgo-ci.Containerfile \
8# && su - ci-runner -s /bin/sh -c "podman build -t localhost/orgo-ci:1 -f orgo-ci.Containerfile ." \
9# && rm /var/lib/gitbay-runner/orgo-ci.Containerfile'
10#
11# Tagged, not :latest, so a change here is a deliberate bump in ci.yml.
12FROM docker.io/library/rust:1-trixie
13
14# The rust image installs the minimal profile: clippy for the test job, the
15# musl target and its linker for release.sh's second tarball, openssh-client
16# for the pushes. git and ca-certificates are already present.
17RUN rustup component add clippy \
18 && rustup target add x86_64-unknown-linux-musl \
19 && apt-get update \
20 && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
21 musl-tools \
22 openssh-client \
23 && rm -rf /var/lib/apt/lists/*
.gitbay/bot-ssh.sh added +16
@@ -0,0 +1,16 @@
1# Sourced by pages.sh and release.sh. The build runs in a container that
2# holds no key of its own; the orgo-ci account's private key (write on this
3# repository) arrives as the BOT_SSH_KEY secret and is written into the
4# workspace beside an ssh config every ssh and git call is pointed at with
5# -F. GITBAY_SSH, set by the runner, is the instance as this build reaches
6# it. Nothing is written outside the workspace.
7: "${BOT_SSH_KEY:?BOT_SSH_KEY secret is not set}"
8: "${GITBAY_SSH:?GITBAY_SSH is not set; the runner is too old}"
9(
10 umask 077
11 printf '%s\n' "$BOT_SSH_KEY" >"$PWD/.bot_key"
12 printf 'IdentityFile %s\nIdentitiesOnly yes\nStrictHostKeyChecking accept-new\nUserKnownHostsFile %s\n' \
13 "$PWD/.bot_key" "$PWD/.known_hosts" >"$PWD/.ssh_config"
14)
15SSH="ssh -F $PWD/.ssh_config"
16export GIT_SSH_COMMAND="$SSH"
.gitbay/ci.yml +7
@@ -2,12 +2,17 @@
22# repository at the pushed commit and runs every step with `sh -c`, stopping at
33# the first failure. Repository secrets arrive as environment variables.
44#
5# Jobs run in localhost/orgo-ci, built from .gitbay/Containerfile.ci on the
6# runner host. Publishing goes over SSH as the orgo-ci account; see
7# .gitbay/bot-ssh.sh.
8#
59# The runner is Linux, and `runner next` claims the oldest pending build with no
610# platform targeting, so a second runner could not be aimed at macOS jobs. The
711# darwin tarballs are therefore built on a Mac by .githooks/pre-push at tag time
812# and uploaded to the same release; see RELEASING.org.
913jobs:
1014 test:
15 image: localhost/orgo-ci:1
1116 steps:
1217 - cargo test --locked
1318 - cargo clippy --all-targets --locked -- -D warnings
@@ -17,11 +22,13 @@ jobs:
1722 # Publishes the documentation site by force-pushing the built output to the
1823 # `pages` branch, which gitbay serves at https://orgo.krz.sh. A no-op off main.
1924 pages:
25 image: localhost/orgo-ci:1
2026 steps:
2127 - sh .gitbay/pages.sh
2228
2329 # The tag push is the release: binaries, the gitbay release, and crates.io.
2430 release:
2531 tags: "v*"
32 image: localhost/orgo-ci:1
2633 steps:
2734 - sh .gitbay/release.sh
.gitbay/pages.sh +3 −1
@@ -13,6 +13,8 @@ if [ "${GITBAY_REF:-}" != "main" ]; then
1313 exit 0
1414fi
1515
16. .gitbay/bot-ssh.sh
17
1618tmp=$(mktemp -d)
1719trap 'rm -rf "$tmp"' EXIT
1820site="$tmp/site"
@@ -31,6 +33,6 @@ git -C "$work" -c user.name=gitbay-ci -c user.email=ci@orgo.krz.sh commit -q \
3133 -m "Publish the documentation site
3234
3335Built from ${GITBAY_SHA} by \`orgo build docs -o _site --strict\`."
34git -C "$work" push -q --force "$(git remote get-url origin)" HEAD:refs/heads/pages
36git -C "$work" push -q --force "ssh://$GITBAY_SSH/$GITBAY_REPO.git" HEAD:refs/heads/pages
3537
3638echo "published the site from ${GITBAY_SHA} to the pages branch"
.gitbay/release.sh +3 −5
@@ -26,9 +26,7 @@ if [ "$tag" != "v$version" ]; then
2626 exit 1
2727fi
2828
29# Reach the forge on whatever host the runner cloned from, rather than a name it
30# may not have in known_hosts.
31host=$(git remote get-url origin | sed 's#.*://[^@]*@##; s#[:/].*##')
29. .gitbay/bot-ssh.sh
3230
3331dist=dist
3432mkdir -p "$dist"
@@ -52,10 +50,10 @@ done
5250# Notes come from the annotated tag, so the person cutting the release writes
5351# them at the moment they decide to cut it (`git tag -a "$tag" -F notes.md`).
5452git tag -l --format='%(contents)' "$tag" |
55 ssh "git@$host" release create "$repo" "$tag" --title "${tag#v}" --file -
53 $SSH "$GITBAY_SSH" release create "$repo" "$tag" --title "${tag#v}" --file -
5654
5755for f in "$dist"/*; do
58 ssh "git@$host" release asset add "$repo" "$tag" "$(basename "$f")" <"$f"
56 $SSH "$GITBAY_SSH" release asset add "$repo" "$tag" "$(basename "$f")" <"$f"
5957 echo "attached $(basename "$f")"
6058done
6159