From b71e470511252b527b52eb77aeae4bd383f00585 Mon Sep 17 00:00:00 2001 From: OpenCode Cabillot Date: Thu, 8 Oct 2026 20:29:23 +0000 Subject: [PATCH 1/2] ci: align pipeline on web/mydl pattern Split the monolithic docker-build/release/test workflows into the shared _ci-common.yaml + trigger-specific files used on web/mydl: - pr.yaml -> PR checks (hadolint + build smoke test) - main.yaml -> CI + local build + git semver tag (PAT, triggers tag.yaml) - tag.yaml -> CI + build/push :vX.Y.Z and :vX.Y.Z-latest (sole Docker push) - cron.yaml -> nightly rebuild of :vX.Y.Z-latest - _ci-common.yaml -> hadolint + build-test with docker smoke and GHA cache Docker pushes to :latest on every merge are replaced by versioned, tested tags. The tag job uses SA_TOKEN_ACTION_PUSH_TAGS (a PAT) so the tag push actually triggers tag.yaml - GITHUB_TOKEN would not. --- .gitea/workflows/_ci-common.yaml | 34 ++++++++++++++ .gitea/workflows/cron.yaml | 46 +++++++++++++++++++ .gitea/workflows/main.yaml | 46 +++++++++++++++++++ .gitea/workflows/pr.yaml | 12 +++++ .gitea/workflows/release.yaml | 23 ---------- .../workflows/{docker-build.yaml => tag.yaml} | 30 ++++++------ .gitea/workflows/test.yaml | 23 ---------- 7 files changed, 151 insertions(+), 63 deletions(-) create mode 100644 .gitea/workflows/_ci-common.yaml create mode 100644 .gitea/workflows/cron.yaml create mode 100644 .gitea/workflows/main.yaml create mode 100644 .gitea/workflows/pr.yaml delete mode 100644 .gitea/workflows/release.yaml rename .gitea/workflows/{docker-build.yaml => tag.yaml} (74%) delete mode 100644 .gitea/workflows/test.yaml diff --git a/.gitea/workflows/_ci-common.yaml b/.gitea/workflows/_ci-common.yaml new file mode 100644 index 0000000..83031de --- /dev/null +++ b/.gitea/workflows/_ci-common.yaml @@ -0,0 +1,34 @@ +name: CI Shared Jobs + +on: + workflow_call: + +jobs: + hadolint: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - uses: hadolint/hadolint-action@06be81baf89a55ffd0e24b8f04a4185738dd3387 # v3.5.0 + with: + dockerfile: pkg/Dockerfile + failure-threshold: warning + + build-test: + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4 + - name: Build (cached) + uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 + with: + context: . + file: pkg/Dockerfile + push: false + load: true + tags: ci-image:${{ github.sha }} + cache-from: type=gha + cache-to: type=gha,mode=max + - name: Smoke test (container starts) + run: docker run --rm --name mcp-ics-smoke-$(hostname) ci-image:${{ github.sha }} python -c "import src.server" diff --git a/.gitea/workflows/cron.yaml b/.gitea/workflows/cron.yaml new file mode 100644 index 0000000..ad33eca --- /dev/null +++ b/.gitea/workflows/cron.yaml @@ -0,0 +1,46 @@ +name: Nightly Rebuild +on: + schedule: + - cron: '0 0 * * *' +jobs: + ci: + uses: ./.gitea/workflows/_ci-common.yaml + secrets: inherit + build-push: + needs: [ci] + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + fetch-depth: 0 + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4 + - name: Login to Docker Hub + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4 + with: + username: ${{ secrets.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_TOKEN }} + - id: get-latest-tag + name: Get latest tag + run: | + TAG=$(git describe --tags --abbrev=0 2>/dev/null || echo "") + echo "tag=$TAG" >> $GITHUB_OUTPUT + - id: meta + name: Docker metadata + uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6 + with: + images: jcabillot/mcp-ics + tags: | + type=raw,value=${{ steps.get-latest-tag.outputs.tag }}-latest,enable=${{ steps.get-latest-tag.outputs.tag != '' }} + - name: Build and push + uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 + with: + context: . + file: pkg/Dockerfile + push: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + pull: true + cache-from: type=gha + cache-to: type=gha,mode=max diff --git a/.gitea/workflows/main.yaml b/.gitea/workflows/main.yaml new file mode 100644 index 0000000..bae1b37 --- /dev/null +++ b/.gitea/workflows/main.yaml @@ -0,0 +1,46 @@ +name: Main Release +on: + workflow_dispatch: + push: + branches: [main] +jobs: + ci: + uses: ./.gitea/workflows/_ci-common.yaml + secrets: inherit + build: + needs: [ci] + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4 + - name: Build (cached) + uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 + with: + context: . + file: pkg/Dockerfile + push: false + load: true + tags: jcabillot/mcp-ics:${{ github.sha }} + cache-from: type=gha + cache-to: type=gha,mode=max + tag: + needs: [build] + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + fetch-depth: 0 + - name: Configure git auth + run: | + git remote set-url origin "https://x-access-token:${{ secrets.SA_TOKEN_ACTION_PUSH_TAGS }}@scm.cabillot.eu/perso/mcp-ics.git" + - name: Bump version and push tag + uses: anothrNick/github-tag-action@4ed44965e0db8dab2b466a16da04aec3cc312fd8 # v1.75.0 + env: + GITHUB_TOKEN: ${{ secrets.SA_TOKEN_ACTION_PUSH_TAGS }} + DEFAULT_BUMP: patch + RELEASE_BRANCHES: main + WITH_V: true + GIT_API_TAGGING: false diff --git a/.gitea/workflows/pr.yaml b/.gitea/workflows/pr.yaml new file mode 100644 index 0000000..6666e61 --- /dev/null +++ b/.gitea/workflows/pr.yaml @@ -0,0 +1,12 @@ +name: PR Checks +on: + workflow_dispatch: + pull_request: + branches: [main] +concurrency: + group: pr-${{ github.ref }} + cancel-in-progress: true +jobs: + ci: + uses: ./.gitea/workflows/_ci-common.yaml + secrets: inherit diff --git a/.gitea/workflows/release.yaml b/.gitea/workflows/release.yaml deleted file mode 100644 index c0b28ce..0000000 --- a/.gitea/workflows/release.yaml +++ /dev/null @@ -1,23 +0,0 @@ -name: Release - -on: - push: - branches: [main] - -jobs: - tag: - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - with: - fetch-depth: 0 - - - name: Bump version and push tag - uses: anothrNick/github-tag-action@4ed44965e0db8dab2b466a16da04aec3cc312fd8 # v1.75.0 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - DEFAULT_BUMP: patch - RELEASE_BRANCHES: main - WITH_V: true - GIT_API_TAGGING: false diff --git a/.gitea/workflows/docker-build.yaml b/.gitea/workflows/tag.yaml similarity index 74% rename from .gitea/workflows/docker-build.yaml rename to .gitea/workflows/tag.yaml index a61cad7..4b0e61e 100644 --- a/.gitea/workflows/docker-build.yaml +++ b/.gitea/workflows/tag.yaml @@ -1,38 +1,32 @@ -name: Docker Build and Push - +name: Tag Release on: push: - branches: [main] - schedule: - - cron: '0 0 * * *' - + tags: ['*'] jobs: - build: + ci: + uses: ./.gitea/workflows/_ci-common.yaml + secrets: inherit + build-push: + needs: [ci] runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - with: - fetch-depth: 0 - - name: Set up Docker Buildx uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4 - - name: Login to Docker Hub uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - - - name: Docker metadata - id: meta + - id: meta + name: Docker metadata uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6 with: images: jcabillot/mcp-ics tags: | - type=raw,value=latest,enable=${{ github.ref == 'refs/heads/main' }} - type=sha - + type=ref,event=tag + type=ref,event=tag,suffix=-latest - name: Build and push uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: @@ -42,3 +36,5 @@ jobs: tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} pull: true + cache-from: type=gha + cache-to: type=gha,mode=max diff --git a/.gitea/workflows/test.yaml b/.gitea/workflows/test.yaml deleted file mode 100644 index a3b68e3..0000000 --- a/.gitea/workflows/test.yaml +++ /dev/null @@ -1,23 +0,0 @@ -name: Test - -on: - pull_request: - branches: [main] - -jobs: - build: - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4 - - - name: Build - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 - with: - context: . - file: pkg/Dockerfile - push: false - pull: true From 155178c6651375a5a29d912be63a62d8bde6bd13 Mon Sep 17 00:00:00 2001 From: OpenCode Cabillot Date: Thu, 8 Oct 2026 20:40:10 +0000 Subject: [PATCH 2/2] ci: smoke test = compileall (server.py raises on import without CALDAV_DATA_PATH) --- .gitea/workflows/_ci-common.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.gitea/workflows/_ci-common.yaml b/.gitea/workflows/_ci-common.yaml index 83031de..044edcb 100644 --- a/.gitea/workflows/_ci-common.yaml +++ b/.gitea/workflows/_ci-common.yaml @@ -30,5 +30,5 @@ jobs: tags: ci-image:${{ github.sha }} cache-from: type=gha cache-to: type=gha,mode=max - - name: Smoke test (container starts) - run: docker run --rm --name mcp-ics-smoke-$(hostname) ci-image:${{ github.sha }} python -c "import src.server" + - name: Smoke test (compile sanity) + run: docker run --rm --name mcp-ics-smoke-$(hostname) ci-image:${{ github.sha }} python -m compileall -q src/