blob: 58d1966555c13f0b441e8e3ed4f893e2f9ee107d (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
|
name: CI
on:
pull_request:
workflow_call:
secrets:
CACHIX_AUTH_TOKEN:
description: "auth token for cachix"
workflow_dispatch:
jobs:
eval:
name: Evaluate flake
runs-on: ubuntu-latest
outputs:
matrix: ${{ steps.eval.outputs.matrix }}
steps:
- uses: actions/checkout@v4
- name: Install Nix
uses: DeterminateSystems/nix-installer-action@v9
- name: Setup Cachix
uses: cachix/cachix-action@v13
with:
name: getchoo
authToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Evaluate jobs
id: eval
run: |
nix shell --inputs-from . \
nixpkgs#{bash,coreutils,jq,nix-eval-jobs} \
--command bash ./.github/eval-flake.sh
build:
needs: eval
strategy:
fail-fast: false
matrix: ${{ fromJSON(needs.eval.outputs.matrix) }}
name: Build (${{ matrix.attr }})
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v4
- name: Install Nix
uses: DeterminateSystems/nix-installer-action@v9
- name: Setup Cachix
uses: cachix/cachix-action@v13
with:
name: getchoo
authToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Run build
if: ${{ !matrix.isCached }}
run: |
nix build \
--accept-flake-config \
--print-build-logs \
--fallback \
.#hydraJobs.${{ matrix.attr }}
check:
strategy:
matrix:
os: [ubuntu-latest, macos-latest]
name: Check flake (${{ matrix.os }})
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v4
- name: Install Nix
uses: DeterminateSystems/nix-installer-action@v9
- name: Setup Cachix
uses: cachix/cachix-action@v13
with:
name: getchoo
authToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Run check
run: |
nix flake check \
--print-build-logs \
--fallback \
--show-trace \
--option allow-import-from-derivation true
gate:
needs: [build, check]
name: CI Gate
runs-on: ubuntu-latest
if: always()
steps:
- name: Exit with result
run: |
build_result="${{ needs.build.result }}"
check_result="${{ needs.check.result }}"
results=("$build_result" "$check_result")
for result in "${results[@]}"; do [ "$result" != "success" ] && exit 1; done
exit 0
|