ci: every push is tracked in GLPI
CI / test (push) Successful in 13s
CI / security (push) Successful in 5s
CI / Promote to main (push) Skipped
CI / Build and publish the lists (push) Successful in 3m34s

This commit is contained in:
hcornet committed 2026-10-08 15:56:01 +02:00
1 parent ffe6ae1a2c
commit 74c0fdf934
2 files changed
+182

No files matched your search

+61
View File
@@ -0,0 +1,61 @@
#!/usr/bin/env bash
# The tracking of this run in GLPI: a Change for every push, a release for
# every version (warda-docs, ci/README.md). This file is the same in every
# repository (its source: warda-dns/warda-ci, .gitea/scripts/glpi-track.sh).
# It fetches the tracker, branch main of <owner>/warda-ci, into a temporary
# directory outside the workspace, and runs it in the checkout of the job:
# glpi-track.sh start | failed <job> | passed
# It never fails and never waits long (a fetch is stopped after 20 seconds,
# then come the bounds of the tracker): what goes wrong is told in a line
# "::warning::GLPI tracking: ..." and the status is 0.
# Environment: GLPI_API_URL, GLPI_APP_TOKEN, GLPI_USER_TOKEN (organization
# settings; one missing: nothing is done); WARDA_CI_READ_TOKEN, a token that
# reads warda-ci (needed when that repository is private); WARDA_CI_URL and
# WARDA_CI_REF, to fetch the tracker elsewhere (its own tests, or a tag of
# warda-ci in place of its branch main).
set -u
if [ -z "${GLPI_API_URL:-}" ] || [ -z "${GLPI_APP_TOKEN:-}" ] || [ -z "${GLPI_USER_TOKEN:-}" ]; then
echo "::notice::GLPI tracking: skipped, organization settings missing (variable GLPI_API_URL, secrets GLPI_APP_TOKEN and GLPI_USER_TOKEN)"
exit 0
fi
owner="${GITHUB_REPOSITORY_OWNER:-}"
if [ -z "$owner" ]; then
case "${GITHUB_REPOSITORY:-}" in */*) owner="${GITHUB_REPOSITORY%%/*}" ;; esac
fi
url="${WARDA_CI_URL:-${GITHUB_SERVER_URL:-}/${owner:-warda-dns}/warda-ci.git}"
ref="${WARDA_CI_REF:-main}"
dir="$(mktemp -d)" || { echo "::warning::GLPI tracking: no temporary directory: nothing is written by this step"; exit 0; }
trap 'rm -rf "$dir"' EXIT
export GIT_TERMINAL_PROMPT=0
fetch=(git clone --quiet --depth=1 --branch "$ref" "$url" "$dir/warda-ci")
if command -v timeout >/dev/null 2>&1; then fetch=(timeout -k 5 20 "${fetch[@]}"); fi
status=1
auth=""
if [ -n "${WARDA_CI_READ_TOKEN:-}" ]; then
auth="$(printf 'ci:%s' "$WARDA_CI_READ_TOKEN" | base64 2>/dev/null | tr -d '\n')" || auth=""
fi
unset WARDA_CI_READ_TOKEN
if [ -n "$auth" ]; then
# Gitea takes the token as the password. The header is masked and goes
# through the environment of git, neither in the log nor on its command line.
echo "::add-mask::$auth"
status=0
GIT_CONFIG_COUNT=1 GIT_CONFIG_KEY_0=http.extraHeader GIT_CONFIG_VALUE_0="Authorization: Basic $auth" \
"${fetch[@]}" >/dev/null 2>&1 || status=$?
fi
if [ "$status" != 0 ] && [ "$status" != 124 ] && [ "$status" != 137 ]; then
# Without a token; or once more without it: a token that Gitea refuses
# (expired, unknown) is refused for a public repository too. Not after a
# fetch that was stopped for its time: Gitea does not answer.
rm -rf "$dir/warda-ci"
status=0
"${fetch[@]}" >/dev/null 2>&1 || status=$?
fi
if [ "$status" != 0 ]; then
echo "::warning::GLPI tracking: the tracker (branch $ref of ${url%.git}) could not be fetched (git clone: status $status): nothing is written by this step"
elif [ ! -f "$dir/warda-ci/glpi/glpi-track.sh" ]; then
echo "::warning::GLPI tracking: no glpi/glpi-track.sh in the branch $ref of ${url%.git}: nothing is written by this step"
else
GLPI_TRACK_STUB="${BASH_SOURCE[0]}" bash "$dir/warda-ci/glpi/glpi-track.sh" "$@" || true
fi
exit 0
+121
View File
@@ -28,6 +28,24 @@
#
# Promotion: every push of develop whose checks pass is pushed on main
# (fast-forward only) with the secret RELEASE_TOKEN.
#
# GLPI: every push is a Change of the support platform, closed when the
# CI of main passes (no numbered version: no release). Steps of the jobs
# below say it, each for its own job: the first step of the job test, that
# the push is received and the tests start; the last step of a job that
# failed, that it failed; the last step of the last job (promote on
# develop, build on main), that the run passed. They run
# .gitea/scripts/glpi-track.sh, which fetches the tracker shared by every
# repository (branch main of warda-dns/warda-ci; warda-docs, ci/README.md).
# The pushes only: neither the daily build, a run by hand nor a pull
# request. GLPI never fails nor blocks a run: these steps always end well
# (a warning at most, in a time of their own), no job waits for them, and
# without the organization settings below nothing is done. A run that is
# cancelled says nothing: the next push completes its Change.
# Organization settings: variable GLPI_API_URL (the REST API of GLPI),
# secrets GLPI_APP_TOKEN and GLPI_USER_TOKEN (the API client and the
# account of the CI in GLPI); secret WARDA_CI_READ_TOKEN, optional (a
# token that reads warda-ci: needed when that repository is private).
name: CI
on:
@@ -62,6 +80,10 @@ env:
# Raise it if the build is killed (exit code 137).
BUILD_MEMORY: 3g
LISTS_URL: https://gitea.tips-of-mine.com/warda-dns/warda-lists/raw/branch/dist
# The tracking of this repository in GLPI: no numbered version, and what
# its branch main delivers.
GLPI_TRACK_RELEASES: "false"
GLPI_TRACK_PUBLISHED: listes publiées
jobs:
test:
@@ -76,6 +98,24 @@ jobs:
with:
ref: ${{ (github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') && 'main' || '' }}
# GLPI: the Change of this push (a new one, or the open one of the
# repository), moved to "En test". Not on main: its Changes were
# written by the run of develop, and move when the run ends; never for
# the daily build nor a run by hand. Never fails the job; 9 seconds
# when GLPI does not answer, 25 at most when it answers slowly
# (measured: warda-docs, ci/README.md).
- name: "GLPI: the push is received, the tests start"
if: github.event_name == 'push' && github.ref != 'refs/heads/main'
continue-on-error: true
timeout-minutes: 3
env:
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
GLPI_TRACK_BEFORE: ${{ github.event.before }}
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
run: bash .gitea/scripts/glpi-track.sh start || true
# The tests of the builder: names read as Warda reads them, the three
# plain formats, a UT1-style archive, exceptions, allow.txt,
# protect.txt, the files of warda-analyst, the figures of the
@@ -125,6 +165,20 @@ jobs:
test -s /tmp/dist/licenses/GPL-3.0-only.txt
echo "offline build checked"'
# GLPI: the last step of each job says the job failed (the Change
# back to "En attente"); it never fails nor blocks anything itself.
- name: "GLPI: this job failed"
if: failure() && github.event_name == 'push'
continue-on-error: true
timeout-minutes: 5
env:
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
GLPI_TRACK_BEFORE: ${{ github.event.before }}
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
run: bash .gitea/scripts/glpi-track.sh failed test || true
# Security: secrets committed by mistake. A finding stops the promotion
# and the publication of the lists, as a failed test does.
security:
@@ -148,6 +202,18 @@ jobs:
--entrypoint sh "$GITLEAKS_IMAGE" \
-c 'mkdir /repo && tar -x -C /repo && gitleaks dir /repo --redact -v --no-banner'
- name: "GLPI: this job failed"
if: failure() && github.event_name == 'push'
continue-on-error: true
timeout-minutes: 5
env:
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
GLPI_TRACK_BEFORE: ${{ github.event.before }}
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
run: bash .gitea/scripts/glpi-track.sh failed security || true
build:
name: Build and publish the lists
needs: [test, security]
@@ -245,6 +311,36 @@ jobs:
git push --force --quiet "${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}.git" HEAD:refs/heads/dist
echo "published: $LISTS_URL/"
# The steps of GLPI run for a push of main only: the daily build and a
# run by hand write nothing. The commit of the run is the one of the
# event (GITHUB_SHA), not the head of main checked out above.
- name: "GLPI: this job failed"
if: failure() && github.event_name == 'push'
continue-on-error: true
timeout-minutes: 5
env:
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
GLPI_TRACK_BEFORE: ${{ github.event.before }}
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
run: bash .gitea/scripts/glpi-track.sh failed build || true
# GLPI: the last job of a run of main (the lists are published: its
# Changes "Appliqué", then closed). On develop the last word is the
# promotion's.
- name: "GLPI: the run passed"
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
continue-on-error: true
timeout-minutes: 5
env:
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
GLPI_TRACK_BEFORE: ${{ github.event.before }}
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
run: bash .gitea/scripts/glpi-track.sh passed || true
# Promotion: a commit of develop that passed the checks is pushed on main
# (fast-forward only, never forced); the CI of main runs on it and
# publishes the lists. If main holds a commit that develop does not have,
@@ -282,3 +378,28 @@ jobs:
GIT_CONFIG_KEY_0=http.extraHeader \
GIT_CONFIG_VALUE_0="Authorization: Basic $auth" \
git push origin "$GITHUB_SHA:refs/heads/main"
- name: "GLPI: this job failed"
if: failure() && github.event_name == 'push'
continue-on-error: true
timeout-minutes: 5
env:
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
GLPI_TRACK_BEFORE: ${{ github.event.before }}
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
run: bash .gitea/scripts/glpi-track.sh failed promote || true
# GLPI: the last job of a run of develop: tested, promoted
# ("Qualification"); the run of main says the rest.
- name: "GLPI: the tests passed, the commit is promoted"
continue-on-error: true
timeout-minutes: 5
env:
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
GLPI_TRACK_BEFORE: ${{ github.event.before }}
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
run: bash .gitea/scripts/glpi-track.sh passed || true