blob: f8e429e05a9abe718acf1765a80b69f27ad36073 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
|
name: CI
on:
pull_request:
workflow_call:
secrets:
CACHIX_AUTH_TOKEN:
description: "auth token for cachi"
workflow_dispatch:
jobs:
eval:
name: Evaluate flake
runs-on: ubuntu-latest
outputs:
matrix: ${{ steps.eval.outputs.matrix }}
steps:
- uses: actions/checkout@v4
- name: Install Nix
uses: DeterminateSystems/nix-installer-action@v9
- name: Setup Cachix
uses: cachix/cachix-action@v13
with:
name: getchoo
authToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Evaluate jobs
id: eval
run: |
echo "matrix=$(nix eval --show-trace --json .#workflowMatrix)" >> "$GITHUB_OUTPUT"
build:
needs: eval
strategy:
fail-fast: false
matrix: ${{ fromJSON(needs.eval.outputs.matrix) }}
name: Build (${{ matrix.attr }})
runs-on: ${{ matrix.os }}
env:
JOBS: "hydraJobs"
steps:
- uses: actions/checkout@v4
- name: Install Nix
uses: DeterminateSystems/nix-installer-action@v9
- name: Setup Cachix
uses: cachix/cachix-action@v13
with:
name: getchoo
authToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Run build
run: |
for url in "https://cache.nixos.org" "https://getchoo.cachix.org"; do
if nix eval --raw .#"$JOBS".${{ matrix.attr }} \
| cut -c12-43 \
| xargs -I {} curl -f "$url"/{}.narinfo &> /dev/null; then
echo ${{ matrix.attr }} is already cached in $url!
fi
done
nix build --print-build-logs --fallback \
.#"$JOBS".${{ matrix.attr }}
check:
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest]
name: Check flake (${{ matrix.os }})
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v4
- name: Install Nix
uses: DeterminateSystems/nix-installer-action@v9
- name: Setup Cachix
uses: cachix/cachix-action@v13
with:
name: getchoo
authToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Run check
run: |
nix flake check \
--print-build-logs \
--fallback \
--show-trace \
--option allow-import-from-derivation true
gate:
needs: [build, check]
name: CI Gate
runs-on: ubuntu-latest
if: always()
steps:
- name: Exit with result
run: |
build_result="${{ needs.build.result }}"
check_result="${{ needs.check.result }}"
results=("$build_result" "$check_result")
for result in "${results[@]}"; do [ "$result" != "success" ] && exit 1; done
exit 0
|