diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml
index 7fef642..ff4b560 100644
--- a/.gitea/workflows/ci.yml
+++ b/.gitea/workflows/ci.yml
@@ -30,24 +30,25 @@ jobs:
MARIADB_USER: j621
MARIADB_PASSWORD: j621
options: >-
- --health-cmd "healthcheck.sh --connect --innodb_initialized"
- --health-interval 5s
- --health-timeout 5s
- --health-retries 20
+ --health-cmd="healthcheck.sh --connect --innodb_initialized"
+ --health-interval=5s
+ --health-timeout=5s
+ --health-retries=12
redis:
image: redis:7-alpine
options: >-
- --health-cmd "redis-cli ping"
- --health-interval 5s
- --health-timeout 5s
- --health-retries 20
+ --health-cmd="redis-cli ping"
+ --health-interval=5s
+ --health-timeout=5s
+ --health-retries=12
env:
+ # Connect as root so Django can create the test database itself;
+ # everything else mirrors the development defaults.
DB_HOST: mariadb
DB_PORT: "3306"
DB_NAME: j621
- DB_USER: j621
- DB_PASSWORD: j621
- DB_ROOT_PASSWORD: root
+ DB_USER: root
+ DB_PASSWORD: root
REDIS_URL: redis://redis:6379/1
steps:
- uses: actions/checkout@v4
@@ -55,27 +56,10 @@ jobs:
- uses: actions/setup-python@v5
with:
python-version: "3.14"
- cache: pip
- cache-dependency-path: backend/requirements.txt
- name: Install backend dependencies
run: pip install -r backend/requirements.txt
- - name: Install a MariaDB client
- run: |
- sudo apt-get update
- sudo apt-get install -y --no-install-recommends default-mysql-client
-
- - name: Grant the test database rights
- run: |
- for i in $(seq 1 30); do
- mysql -h "$DB_HOST" -P "$DB_PORT" -u root -p"$DB_ROOT_PASSWORD" \
- -e "SELECT 1" >/dev/null 2>&1 && break
- sleep 2
- done
- mysql -h "$DB_HOST" -P "$DB_PORT" -u root -p"$DB_ROOT_PASSWORD" \
- -e "GRANT ALL ON \`test_j621\`.* TO 'j621'@'%'; FLUSH PRIVILEGES;"
-
- name: Django system checks
working-directory: backend
run: python manage.py check
@@ -98,8 +82,6 @@ jobs:
- uses: actions/setup-node@v4
with:
node-version: "22"
- cache: npm
- cache-dependency-path: frontend/package-lock.json
- name: Install frontend dependencies
working-directory: frontend
diff --git a/.gitea/workflows/publish.yml b/.gitea/workflows/publish.yml
index cefc74d..7b328f7 100644
--- a/.gitea/workflows/publish.yml
+++ b/.gitea/workflows/publish.yml
@@ -30,8 +30,10 @@ jobs:
name: Build & push images
runs-on: ubuntu-latest
env:
- REGISTRY_USER: ${{ github.actor }}
- REGISTRY_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ # Prefer dedicated registry secrets (as on other repos); fall back to
+ # the automatic Actions token.
+ REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }}
+ REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITHUB_TOKEN }}
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
steps:
- uses: actions/checkout@v4
diff --git a/AGENTS.md b/AGENTS.md
index 18c81ed..b22bd8e 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -49,6 +49,12 @@ Project constraints (do not regress):
- Periodic commands (follow syncs, similarity cleanup, guest blacklist
refresh) run in the composes' `scheduler` service — the backend image with
the j621-scheduler entrypoint, intervals via J621_*_EVERY. No host cron.
+- CI lives in .gitea/workflows: ci.yml runs on every push/PR (Django checks +
+ the full backend suite against MariaDB/Redis service containers, frontend
+ lint/type-check/build); publish.yml is manual and builds/pushes both images
+ multi-arch. Jobs run on the user-scoped msi-mortar-ci runner (labels
+ `desktop` + `ubuntu-latest`). Do not add actions/cache (`cache: pip`/`npm`)
+ to these workflows: Gitea's cache service hangs the job on restore/save.
- Security/permission tests live in backend/apps/core/tests and need a
one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%';
@@ -85,7 +91,12 @@ Security hardening (do not weaken):
SECRET_KEY (apps/accounts/crypto.py); rotating SECRET_KEY invalidates them
(and all signed media URLs), so users must re-enter the key.
- API throttles live in REST_FRAMEWORK (env-overridable): anon 120/min,
- user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour.
+ user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour. Signed
+ media URLs (raw/thumbnail/staged-file/similarity-file actions) are exempt
+ on purpose:
/