No description
  • JavaScript 84.8%
  • Shell 15.2%
Find a file
2026-09-19 20:08:49 +00:00
.forgejo/workflows fix(ci): pin node variant defaults in the contracts and drop the dead prerelease block 2026-09-19 21:11:45 +02:00
scripts fix(ci): pin node variant defaults in the contracts and drop the dead prerelease block 2026-09-19 21:11:45 +02:00
tests/fixtures ## [1.3.0] - 2026-07-25 2026-07-25 23:26:59 +02:00
.gitignore fix(ci): strict version sync and fail on existing tags for all callers 2026-09-18 16:46:41 +02:00
CHANGELOG.md Update version 2026-09-19 22:08:24 +02:00
README.md feat(ci): centralize node tag and publish workflows 2026-09-19 20:58:36 +02:00

central_ci

Reusable Forgejo Actions workflows shared across HomeIoT / BHK projects.

Repo: faicel/central_ci

Layout

Path Role
.forgejo/workflows/validate_flow.yml PR branch flow (*→dev, dev→staging, staging→main)
.forgejo/workflows/rust_crate_checks.yml fmt, clippy, machete, deny, version sync, tag check, tests
.forgejo/workflows/node_checks.yml npm ci, lint, type-check, tests, version sync, tag check, optional build
.forgejo/workflows/create_tag_on_dev.yml checks + create/push vX.Y.Z-rc
.forgejo/workflows/create_tag_on_main.yml checks + create/push vX.Y.Z + ensure release/X.Y
.forgejo/workflows/publish_on_tag.yml checks + reuse-safe Forgejo release + optional cargo publish, release_id output
scripts/create-release.mjs Release creation source of truth (inlined in publish_on_tag)
scripts/check-version-sync.sh Local / copy into crates
scripts/resolve-cargo-registry.sh Tag → forgejo / forgejorc (inlined in publish workflow)
scripts/release-branch-name.sh X.Y.Z → release/X.Y (inlined in create-tag-on-main)

Shell helpers used by CI are inlined in the reusable workflows so callers do not need read access to check out central_ci as a second repository (works across orgs with one PAT). The scripts/ copies remain the editable source of truth + unit tests.

Companion image

Rust jobs expect the shared toolchain image:

code.bhk-itsolutions.com/homeiot/ci-rust-embedded:rust-1.97.0

(needs node for actions/checkout, plus cargo-deny / cargo-machete).

Usage — full Rust crate publish flow (thin callers)

Each consumer keeps only triggers + params. Logic lives here.

# .forgejo/workflows/create-tag-on-dev.yml
name: Create tag on dev
on:
  push:
    branches: [dev]
jobs:
  tag:
    uses: faicel/central_ci/.forgejo/workflows/create_tag_on_dev.yml@main
    # repository is auto-detected from github.repository
    # with:
    #   enable_deny: false
    #   test_command: "cargo test --features std"
    secrets:
      RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
# .forgejo/workflows/create-tag-on-main.yml
name: Create tag on main
on:
  push:
    branches: [main]
jobs:
  tag:
    uses: faicel/central_ci/.forgejo/workflows/create_tag_on_main.yml@main
    secrets:
      RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
# .forgejo/workflows/publish-on-tag.yml
name: Publish release on tag
on:
  push:
    tags: ["v*"]
jobs:
  publish:
    uses: faicel/central_ci/.forgejo/workflows/publish_on_tag.yml@main
    secrets:
      RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
# .forgejo/workflows/check-on-feature-branch.yml
name: Run checks on feature branches
on:
  push:
    branches: ["*", "!dev", "!staging", "!main"]
jobs:
  checks:
    uses: faicel/central_ci/.forgejo/workflows/rust_crate_checks.yml@main
    secrets:
      RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
# .forgejo/workflows/validate-branch-flow.yml
name: Validate branch flow
on:
  pull_request_target:
    types: [opened, synchronize, reopened, edited]
jobs:
  validate:
    uses: faicel/central_ci/.forgejo/workflows/validate_flow.yml@main

Common inputs

Input Default Notes
repository github.repository (caller) Optional override owner/name
forgejo_host code.bhk-itsolutions.com
ci_image …/ci-rust-embedded:rust-1.97.0
working_directory . Monorepo subdir
enable_deny / enable_machete / enable_version_sync true Forwarded to checks
enable_tag_check true (tag workflows) / false (publish)
test_command cargo test e.g. cargo test --features sx1278

Usage — Node/npm projects (SPA)

There is no rust/node dispatcher anymore: a runner was shown to ignore if: guards on reusable (uses:) jobs, so runtime routing could run both routes. Selection happens by FILE NAME — each kind has its own workflows:

Workflow Node usage
node_checks.yml Standalone checker (also embedded by the _node tag/publish variants): install_command (npm ci), lint_command, typecheck_command, test_command, package.json ↔ CHANGELOG sync (a top [Unreleased] section is skipped), tag check, optional build_command
create_tag_on_dev_node.yml Node checks, then create/push vX.Y.Z-rc (an already existing tag always fails; version from version_command, default node -p "require('./package.json').version")
create_tag_on_main_node.yml Node checks, then create/push vX.Y.Z + ensure release/X.Y
publish_on_tag_node.yml Node checks, then reuse-safe release creation (strict vX.Y.Z(-rc) matching the package version, 404-only create, generic asset overwrite guard via asset_prefix), release_id output — NO npm publish; the caller uploads its artifacts
# .forgejo/workflows/check-on-feature-branch.yml (Node)
name: Run checks on feature branches
on:
  push:
    branches-ignore: [dev, staging, main]
jobs:
  checks:
    uses: faicel/central_ci/.forgejo/workflows/node_checks.yml@main
    secrets:
      RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
# .forgejo/workflows/publish-on-tag.yml (Node SPA, upload job)
jobs:
  publish:
    uses: faicel/central_ci/.forgejo/workflows/publish_on_tag_node.yml@main
    with:
      enable_tag_check: false
      release_name_prefix: front
      asset_prefix: front
    secrets:
      RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
  upload_dist:
    needs: publish
    runs-on: docker
    steps:
      - run: echo "release id = ${{ needs.publish.outputs.release_id }}"

Usage — checks only

jobs:
  checks:
    uses: faicel/central_ci/.forgejo/workflows/rust_crate_checks.yml@main
    secrets:
      RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}

Local tests

chmod +x scripts/*.sh
./scripts/test-check-version-sync.sh
./scripts/test-resolve-cargo-registry.sh
./scripts/test-release-branch-name.sh

Version sync convention

Consumer crates must keep these equal:

  1. Cargo.toml → version = "x.y.z"
  2. CHANGELOG.md → top heading ## [x.y.z] - YYYY-MM-DD

Security note

Prefer pinning @vX.Y.Z (or a commit SHA) instead of @main once you tag releases of central_ci. Protect .forgejo/**/*.yml on consumer main branches (Forgejo Protected file patterns).