- JavaScript 84.8%
- Shell 15.2%
|
|
||
|---|---|---|
| .forgejo/workflows | ||
| scripts | ||
| tests/fixtures | ||
| .gitignore | ||
| CHANGELOG.md | ||
| README.md | ||
central_ci
Reusable Forgejo Actions workflows shared across HomeIoT / BHK projects.
Repo: faicel/central_ci
Layout
| Path | Role |
|---|---|
.forgejo/workflows/validate_flow.yml |
PR branch flow (*→dev, dev→staging, staging→main) |
.forgejo/workflows/rust_crate_checks.yml |
fmt, clippy, machete, deny, version sync, tag check, tests |
.forgejo/workflows/node_checks.yml |
npm ci, lint, type-check, tests, version sync, tag check, optional build |
.forgejo/workflows/create_tag_on_dev.yml |
checks + create/push vX.Y.Z-rc |
.forgejo/workflows/create_tag_on_main.yml |
checks + create/push vX.Y.Z + ensure release/X.Y |
.forgejo/workflows/publish_on_tag.yml |
checks + reuse-safe Forgejo release + optional cargo publish, release_id output |
scripts/create-release.mjs |
Release creation source of truth (inlined in publish_on_tag) |
scripts/check-version-sync.sh |
Local / copy into crates |
scripts/resolve-cargo-registry.sh |
Tag → forgejo / forgejorc (inlined in publish workflow) |
scripts/release-branch-name.sh |
X.Y.Z → release/X.Y (inlined in create-tag-on-main) |
Shell helpers used by CI are inlined in the reusable workflows so callers do not need
read access to check out central_ci as a second repository (works across orgs with one PAT).
The scripts/ copies remain the editable source of truth + unit tests.
Companion image
Rust jobs expect the shared toolchain image:
code.bhk-itsolutions.com/homeiot/ci-rust-embedded:rust-1.97.0
(needs node for actions/checkout, plus cargo-deny / cargo-machete).
Usage — full Rust crate publish flow (thin callers)
Each consumer keeps only triggers + params. Logic lives here.
# .forgejo/workflows/create-tag-on-dev.yml
name: Create tag on dev
on:
push:
branches: [dev]
jobs:
tag:
uses: faicel/central_ci/.forgejo/workflows/create_tag_on_dev.yml@main
# repository is auto-detected from github.repository
# with:
# enable_deny: false
# test_command: "cargo test --features std"
secrets:
RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
# .forgejo/workflows/create-tag-on-main.yml
name: Create tag on main
on:
push:
branches: [main]
jobs:
tag:
uses: faicel/central_ci/.forgejo/workflows/create_tag_on_main.yml@main
secrets:
RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
# .forgejo/workflows/publish-on-tag.yml
name: Publish release on tag
on:
push:
tags: ["v*"]
jobs:
publish:
uses: faicel/central_ci/.forgejo/workflows/publish_on_tag.yml@main
secrets:
RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
# .forgejo/workflows/check-on-feature-branch.yml
name: Run checks on feature branches
on:
push:
branches: ["*", "!dev", "!staging", "!main"]
jobs:
checks:
uses: faicel/central_ci/.forgejo/workflows/rust_crate_checks.yml@main
secrets:
RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
# .forgejo/workflows/validate-branch-flow.yml
name: Validate branch flow
on:
pull_request_target:
types: [opened, synchronize, reopened, edited]
jobs:
validate:
uses: faicel/central_ci/.forgejo/workflows/validate_flow.yml@main
Common inputs
| Input | Default | Notes |
|---|---|---|
repository |
github.repository (caller) |
Optional override owner/name |
forgejo_host |
code.bhk-itsolutions.com |
|
ci_image |
…/ci-rust-embedded:rust-1.97.0 |
|
working_directory |
. |
Monorepo subdir |
enable_deny / enable_machete / enable_version_sync |
true |
Forwarded to checks |
enable_tag_check |
true (tag workflows) / false (publish) |
|
test_command |
cargo test |
e.g. cargo test --features sx1278 |
Usage — Node/npm projects (SPA)
There is no rust/node dispatcher anymore: a runner was shown to ignore
if: guards on reusable (uses:) jobs, so runtime routing could run both
routes. Selection happens by FILE NAME — each kind has its own workflows:
| Workflow | Node usage |
|---|---|
node_checks.yml |
Standalone checker (also embedded by the _node tag/publish variants): install_command (npm ci), lint_command, typecheck_command, test_command, package.json ↔ CHANGELOG sync (a top [Unreleased] section is skipped), tag check, optional build_command |
create_tag_on_dev_node.yml |
Node checks, then create/push vX.Y.Z-rc (an already existing tag always fails; version from version_command, default node -p "require('./package.json').version") |
create_tag_on_main_node.yml |
Node checks, then create/push vX.Y.Z + ensure release/X.Y |
publish_on_tag_node.yml |
Node checks, then reuse-safe release creation (strict vX.Y.Z(-rc) matching the package version, 404-only create, generic asset overwrite guard via asset_prefix), release_id output — NO npm publish; the caller uploads its artifacts |
# .forgejo/workflows/check-on-feature-branch.yml (Node)
name: Run checks on feature branches
on:
push:
branches-ignore: [dev, staging, main]
jobs:
checks:
uses: faicel/central_ci/.forgejo/workflows/node_checks.yml@main
secrets:
RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
# .forgejo/workflows/publish-on-tag.yml (Node SPA, upload job)
jobs:
publish:
uses: faicel/central_ci/.forgejo/workflows/publish_on_tag_node.yml@main
with:
enable_tag_check: false
release_name_prefix: front
asset_prefix: front
secrets:
RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
upload_dist:
needs: publish
runs-on: docker
steps:
- run: echo "release id = ${{ needs.publish.outputs.release_id }}"
Usage — checks only
jobs:
checks:
uses: faicel/central_ci/.forgejo/workflows/rust_crate_checks.yml@main
secrets:
RUNNER_TOKEN: ${{ secrets.RUNNER_TOKEN }}
Local tests
chmod +x scripts/*.sh
./scripts/test-check-version-sync.sh
./scripts/test-resolve-cargo-registry.sh
./scripts/test-release-branch-name.sh
Version sync convention
Consumer crates must keep these equal:
Cargo.toml→version = "x.y.z"CHANGELOG.md→ top heading## [x.y.z] - YYYY-MM-DD
Security note
Prefer pinning @vX.Y.Z (or a commit SHA) instead of @main once you tag releases of central_ci.
Protect .forgejo/**/*.yml on consumer main branches (Forgejo Protected file patterns).