From f38a2a689c63dda4ed30df7e683b3743ba6b87e6 Mon Sep 17 00:00:00 2001 From: Ivan Godwin Date: Sat, 18 Jul 2026 09:49:36 -0700 Subject: [PATCH] ci: drop Node-based actions; run natively on the self-hosted runner actions/checkout and actions/setup-go are JavaScript actions and fail on the runner's node-less job containers (Cannot find: node in PATH). All jobs now run plain shell steps in a golang:1.25-alpine container: fetch by sha, apk deps, pinned protoc plugins, then lint/test/govulncheck. The generate-proto composite action is inlined and removed. Co-Authored-By: Claude Fable 5 --- .gitea/actions/generate-proto/action.yml | 37 ------- .gitea/workflows/ci.yml | 124 +++++++++++------------ 2 files changed, 59 insertions(+), 102 deletions(-) delete mode 100644 .gitea/actions/generate-proto/action.yml diff --git a/.gitea/actions/generate-proto/action.yml b/.gitea/actions/generate-proto/action.yml deleted file mode 100644 index 3b69111..0000000 --- a/.gitea/actions/generate-proto/action.yml +++ /dev/null @@ -1,37 +0,0 @@ -name: Generate protobuf code -description: > - Installs protoc and the pinned protoc-gen-go / protoc-gen-go-grpc plugins, - then runs `make proto-gen`. api/grpc/pb/ is gitignored (see .gitignore) and - regenerated at build time (mirrors what the Dockerfile does for image - builds), so any job that compiles Go code needs this step first or - `github.com/igodwin/notifier/api/grpc/pb` won't resolve. -# -# Local composite action, referenced from ci.yml via: -# uses: ./.gitea/actions/generate-proto -# Gitea Actions supports local composite actions the same way GitHub Actions -# does. Must run after a Go toolchain is on PATH (i.e. after actions/setup-go). - -runs: - using: composite - steps: - - name: Install protoc - shell: bash - run: | - sudo apt-get update - sudo apt-get install -y --no-install-recommends protobuf-compiler - protoc --version - - # Pinned exactly to the versions this module already depends on - # (google.golang.org/protobuf in go.mod, and the matching - # protoc-gen-go-grpc release) - deliberately not @latest, so CI can't - # drift out from under the checked-in go.mod without review. - - name: Install protoc-gen-go / protoc-gen-go-grpc (pinned) - shell: bash - run: | - go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.10 - go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@v1.5.1 - echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH" - - - name: Generate protobuf code (make proto-gen) - shell: bash - run: make proto-gen diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 925625b..a6e219d 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -1,10 +1,9 @@ name: CI -# Gitea Actions reads workflows from .gitea/workflows/ and executes them with -# a GitHub-Actions-compatible engine (act_runner). Standard actions/* steps -# work as long as the runner can resolve github.com (either directly or via a -# configured actions mirror on the Gitea instance) - see notes at the bottom -# of this file for offline/mirrored setups. +# Runner-native workflow: the self-hosted act_runner's job containers have no +# Node.js, so JavaScript actions (actions/checkout, actions/setup-go, ...) +# fail with "Cannot find: node in PATH". Every step here is a plain shell +# run-step inside a golang container instead. on: push: @@ -13,8 +12,6 @@ on: pull_request: # Cancel superseded runs for the same ref to save runner capacity. -# Gitea Actions accepts both the `gitea.*` and `github.*` context aliases; -# `github.*` is used here since it's the more portable spelling. concurrency: group: ci-${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true @@ -22,98 +19,95 @@ concurrency: jobs: lint: name: Lint - runs-on: ubuntu-latest + runs-on: docker + container: + image: golang:1.25-alpine # Advisory while the pre-existing lint backlog (~95 findings) is worked # off; flip to blocking by removing continue-on-error once clean. continue-on-error: true steps: - name: Checkout - uses: actions/checkout@v4 + run: | + apk add -q --no-cache git make protobuf protobuf-dev curl + git init -q . + git remote add origin https://gitea.ivangodwin.com/${{ gitea.repository }}.git + git fetch -q --depth 1 origin ${{ gitea.sha }} + git checkout -q FETCH_HEAD - - name: Set up Go - uses: actions/setup-go@v5 - with: - go-version-file: go.mod - cache: true - - # api/grpc/pb/ is gitignored and generated at build time (see - # .gitignore and the Dockerfile), so anything that compiles this - # module - including the linter, which type-checks packages - needs - # the generated code in place first. + # api/grpc/pb/ is gitignored and generated at build time, so anything + # that compiles this module - including the linter, which type-checks + # packages - needs the generated code in place first. - name: Generate protobuf code - uses: ./.gitea/actions/generate-proto + run: | + go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.10 + go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@v1.5.1 + export PATH="$PATH:$(go env GOPATH)/bin" + make proto-gen - # Installing the pinned binary via the official install script is more - # portable across Gitea Actions runner images than golangci-lint-action, - # which assumes a GitHub-hosted runner environment (it works, but the - # install script approach has fewer surprises on self-hosted runners - # and lets us pin an exact version without depending on the action's - # own release cadence). - - name: Install golangci-lint + - name: Run golangci-lint run: | curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | \ sh -s -- -b "$(go env GOPATH)/bin" v2.12.2 - echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH" - - - name: Run golangci-lint - run: golangci-lint run ./... + "$(go env GOPATH)/bin/golangci-lint" run ./... test: name: Test - runs-on: ubuntu-latest + runs-on: docker + container: + image: golang:1.25-alpine steps: - name: Checkout - uses: actions/checkout@v4 + run: | + apk add -q --no-cache git make protobuf protobuf-dev gcc musl-dev + git init -q . + git remote add origin https://gitea.ivangodwin.com/${{ gitea.repository }}.git + git fetch -q --depth 1 origin ${{ gitea.sha }} + git checkout -q FETCH_HEAD - - name: Set up Go - uses: actions/setup-go@v5 - with: - go-version-file: go.mod - cache: true - - # api/grpc/pb/ is gitignored and generated at build time; without this - # the module won't compile (pkg/client, internal/service, etc. import - # the generated package). - name: Generate protobuf code - uses: ./.gitea/actions/generate-proto + run: | + go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.10 + go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@v1.5.1 + export PATH="$PATH:$(go env GOPATH)/bin" + make proto-gen - # tests/e2e uses testcontainers-go and requires a Docker daemon that - # isn't guaranteed to be available/usable on Gitea Actions runners, so - # it is excluded from CI here via `go list ... | grep -v`. Run it - # locally (or on a runner with Docker-in-Docker configured) with: - # go test -race ./tests/e2e/... + # -race needs cgo, hence gcc/musl-dev above. tests/e2e uses + # testcontainers-go (needs a Docker daemon) and is excluded; run it + # locally with: go test -race ./tests/e2e/... + # coverage.out is left in the workspace; artifact upload is omitted + # until the instance's artifact storage is confirmed working. - name: Run tests (excluding e2e) run: | go test -race -covermode=atomic -coverprofile=coverage.out \ $(go list ./... | grep -v '/tests/e2e') - # coverage.out is left in the workspace for inspection; artifact - # upload is intentionally omitted since actions/upload-artifact - # support varies by Gitea version/configuration - add it back once - # your instance's artifact storage is confirmed working. vuln: name: Vulnerability scan + runs-on: docker + container: + image: golang:1.25-alpine # Advisory: govulncheck also reports Go-stdlib findings that are only # fixable by toolchain updates; flip to blocking once triaged. continue-on-error: true - runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v4 - - - name: Set up Go - uses: actions/setup-go@v5 - with: - go-version-file: go.mod - cache: true + run: | + apk add -q --no-cache git make protobuf protobuf-dev + git init -q . + git remote add origin https://gitea.ivangodwin.com/${{ gitea.repository }}.git + git fetch -q --depth 1 origin ${{ gitea.sha }} + git checkout -q FETCH_HEAD # govulncheck also loads and type-checks the module's packages, so the # generated protobuf code has to exist first. - name: Generate protobuf code - uses: ./.gitea/actions/generate-proto - - - name: Install govulncheck - run: go install golang.org/x/vuln/cmd/govulncheck@latest + run: | + go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.10 + go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@v1.5.1 + export PATH="$PATH:$(go env GOPATH)/bin" + make proto-gen - name: Run govulncheck - run: govulncheck ./... + run: | + go install golang.org/x/vuln/cmd/govulncheck@latest + "$(go env GOPATH)/bin/govulncheck" ./...