Fix CI for the user-scoped runners

- ci.yml: connect to the test MariaDB as root so Django creates the test
  database itself (no client install/grant step), and drop actions/cache
  (cache: pip/npm): Gitea's cache service hangs the job on restore/save.
- publish.yml: prefer the REGISTRY_USER/REGISTRY_TOKEN secrets (as on other
  repos) and fall back to the automatic Actions token.
- AGENTS.md: note the CI layout, the runner labels and the cache caveat.
This commit is contained in:
2026-09-22 23:12:56 -05:00
parent d9c1e9e521
commit 72fc42217f
3 changed files with 28 additions and 33 deletions
+12 -30
View File
@@ -30,24 +30,25 @@ jobs:
MARIADB_USER: j621
MARIADB_PASSWORD: j621
options: >-
--health-cmd "healthcheck.sh --connect --innodb_initialized"
--health-interval 5s
--health-timeout 5s
--health-retries 20
--health-cmd="healthcheck.sh --connect --innodb_initialized"
--health-interval=5s
--health-timeout=5s
--health-retries=12
redis:
image: redis:7-alpine
options: >-
--health-cmd "redis-cli ping"
--health-interval 5s
--health-timeout 5s
--health-retries 20
--health-cmd="redis-cli ping"
--health-interval=5s
--health-timeout=5s
--health-retries=12
env:
# Connect as root so Django can create the test database itself;
# everything else mirrors the development defaults.
DB_HOST: mariadb
DB_PORT: "3306"
DB_NAME: j621
DB_USER: j621
DB_PASSWORD: j621
DB_ROOT_PASSWORD: root
DB_USER: root
DB_PASSWORD: root
REDIS_URL: redis://redis:6379/1
steps:
- uses: actions/checkout@v4
@@ -55,27 +56,10 @@ jobs:
- uses: actions/setup-python@v5
with:
python-version: "3.14"
cache: pip
cache-dependency-path: backend/requirements.txt
- name: Install backend dependencies
run: pip install -r backend/requirements.txt
- name: Install a MariaDB client
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends default-mysql-client
- name: Grant the test database rights
run: |
for i in $(seq 1 30); do
mysql -h "$DB_HOST" -P "$DB_PORT" -u root -p"$DB_ROOT_PASSWORD" \
-e "SELECT 1" >/dev/null 2>&1 && break
sleep 2
done
mysql -h "$DB_HOST" -P "$DB_PORT" -u root -p"$DB_ROOT_PASSWORD" \
-e "GRANT ALL ON \`test_j621\`.* TO 'j621'@'%'; FLUSH PRIVILEGES;"
- name: Django system checks
working-directory: backend
run: python manage.py check
@@ -98,8 +82,6 @@ jobs:
- uses: actions/setup-node@v4
with:
node-version: "22"
cache: npm
cache-dependency-path: frontend/package-lock.json
- name: Install frontend dependencies
working-directory: frontend
+4 -2
View File
@@ -30,8 +30,10 @@ jobs:
name: Build & push images
runs-on: ubuntu-latest
env:
REGISTRY_USER: ${{ github.actor }}
REGISTRY_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# Prefer dedicated registry secrets (as on other repos); fall back to
# the automatic Actions token.
REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }}
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITHUB_TOKEN }}
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
steps:
- uses: actions/checkout@v4
+12 -1
View File
@@ -49,6 +49,12 @@ Project constraints (do not regress):
- Periodic commands (follow syncs, similarity cleanup, guest blacklist
refresh) run in the composes' `scheduler` service — the backend image with
the j621-scheduler entrypoint, intervals via J621_*_EVERY. No host cron.
- CI lives in .gitea/workflows: ci.yml runs on every push/PR (Django checks +
the full backend suite against MariaDB/Redis service containers, frontend
lint/type-check/build); publish.yml is manual and builds/pushes both images
multi-arch. Jobs run on the user-scoped msi-mortar-ci runner (labels
`desktop` + `ubuntu-latest`). Do not add actions/cache (`cache: pip`/`npm`)
to these workflows: Gitea's cache service hangs the job on restore/save.
- Security/permission tests live in backend/apps/core/tests and need a
one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%';
@@ -85,7 +91,12 @@ Security hardening (do not weaken):
SECRET_KEY (apps/accounts/crypto.py); rotating SECRET_KEY invalidates them
(and all signed media URLs), so users must re-enter the key.
- API throttles live in REST_FRAMEWORK (env-overridable): anon 120/min,
user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour.
user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour. Signed
media URLs (raw/thumbnail/staged-file/similarity-file actions) are exempt
on purpose: <img>/<video> tags fetch them without an Authorization header,
so a gallery would otherwise drain the anonymous bucket and get 429 JSON
instead of images. THROTTLE_ENABLED=false removes the anon+user limits for
private/tailnet deployments (the login/register/proxy guards stay).
- Only admins (superusers) may grant/revoke the staff role or delete
staff/admin accounts; staff manage regular/uploader accounts only.
- Storage, duplicates, delete, temp-clear, uploads and downloads require