Fix CI for the user-scoped runners
- ci.yml: connect to the test MariaDB as root so Django creates the test database itself (no client install/grant step), and drop actions/cache (cache: pip/npm): Gitea's cache service hangs the job on restore/save. - publish.yml: prefer the REGISTRY_USER/REGISTRY_TOKEN secrets (as on other repos) and fall back to the automatic Actions token. - AGENTS.md: note the CI layout, the runner labels and the cache caveat.
This commit is contained in:
+12
-30
@@ -30,24 +30,25 @@ jobs:
|
|||||||
MARIADB_USER: j621
|
MARIADB_USER: j621
|
||||||
MARIADB_PASSWORD: j621
|
MARIADB_PASSWORD: j621
|
||||||
options: >-
|
options: >-
|
||||||
--health-cmd "healthcheck.sh --connect --innodb_initialized"
|
--health-cmd="healthcheck.sh --connect --innodb_initialized"
|
||||||
--health-interval 5s
|
--health-interval=5s
|
||||||
--health-timeout 5s
|
--health-timeout=5s
|
||||||
--health-retries 20
|
--health-retries=12
|
||||||
redis:
|
redis:
|
||||||
image: redis:7-alpine
|
image: redis:7-alpine
|
||||||
options: >-
|
options: >-
|
||||||
--health-cmd "redis-cli ping"
|
--health-cmd="redis-cli ping"
|
||||||
--health-interval 5s
|
--health-interval=5s
|
||||||
--health-timeout 5s
|
--health-timeout=5s
|
||||||
--health-retries 20
|
--health-retries=12
|
||||||
env:
|
env:
|
||||||
|
# Connect as root so Django can create the test database itself;
|
||||||
|
# everything else mirrors the development defaults.
|
||||||
DB_HOST: mariadb
|
DB_HOST: mariadb
|
||||||
DB_PORT: "3306"
|
DB_PORT: "3306"
|
||||||
DB_NAME: j621
|
DB_NAME: j621
|
||||||
DB_USER: j621
|
DB_USER: root
|
||||||
DB_PASSWORD: j621
|
DB_PASSWORD: root
|
||||||
DB_ROOT_PASSWORD: root
|
|
||||||
REDIS_URL: redis://redis:6379/1
|
REDIS_URL: redis://redis:6379/1
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
@@ -55,27 +56,10 @@ jobs:
|
|||||||
- uses: actions/setup-python@v5
|
- uses: actions/setup-python@v5
|
||||||
with:
|
with:
|
||||||
python-version: "3.14"
|
python-version: "3.14"
|
||||||
cache: pip
|
|
||||||
cache-dependency-path: backend/requirements.txt
|
|
||||||
|
|
||||||
- name: Install backend dependencies
|
- name: Install backend dependencies
|
||||||
run: pip install -r backend/requirements.txt
|
run: pip install -r backend/requirements.txt
|
||||||
|
|
||||||
- name: Install a MariaDB client
|
|
||||||
run: |
|
|
||||||
sudo apt-get update
|
|
||||||
sudo apt-get install -y --no-install-recommends default-mysql-client
|
|
||||||
|
|
||||||
- name: Grant the test database rights
|
|
||||||
run: |
|
|
||||||
for i in $(seq 1 30); do
|
|
||||||
mysql -h "$DB_HOST" -P "$DB_PORT" -u root -p"$DB_ROOT_PASSWORD" \
|
|
||||||
-e "SELECT 1" >/dev/null 2>&1 && break
|
|
||||||
sleep 2
|
|
||||||
done
|
|
||||||
mysql -h "$DB_HOST" -P "$DB_PORT" -u root -p"$DB_ROOT_PASSWORD" \
|
|
||||||
-e "GRANT ALL ON \`test_j621\`.* TO 'j621'@'%'; FLUSH PRIVILEGES;"
|
|
||||||
|
|
||||||
- name: Django system checks
|
- name: Django system checks
|
||||||
working-directory: backend
|
working-directory: backend
|
||||||
run: python manage.py check
|
run: python manage.py check
|
||||||
@@ -98,8 +82,6 @@ jobs:
|
|||||||
- uses: actions/setup-node@v4
|
- uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: "22"
|
node-version: "22"
|
||||||
cache: npm
|
|
||||||
cache-dependency-path: frontend/package-lock.json
|
|
||||||
|
|
||||||
- name: Install frontend dependencies
|
- name: Install frontend dependencies
|
||||||
working-directory: frontend
|
working-directory: frontend
|
||||||
|
|||||||
@@ -30,8 +30,10 @@ jobs:
|
|||||||
name: Build & push images
|
name: Build & push images
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
env:
|
env:
|
||||||
REGISTRY_USER: ${{ github.actor }}
|
# Prefer dedicated registry secrets (as on other repos); fall back to
|
||||||
REGISTRY_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
# the automatic Actions token.
|
||||||
|
REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }}
|
||||||
|
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITHUB_TOKEN }}
|
||||||
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
|
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|||||||
@@ -49,6 +49,12 @@ Project constraints (do not regress):
|
|||||||
- Periodic commands (follow syncs, similarity cleanup, guest blacklist
|
- Periodic commands (follow syncs, similarity cleanup, guest blacklist
|
||||||
refresh) run in the composes' `scheduler` service — the backend image with
|
refresh) run in the composes' `scheduler` service — the backend image with
|
||||||
the j621-scheduler entrypoint, intervals via J621_*_EVERY. No host cron.
|
the j621-scheduler entrypoint, intervals via J621_*_EVERY. No host cron.
|
||||||
|
- CI lives in .gitea/workflows: ci.yml runs on every push/PR (Django checks +
|
||||||
|
the full backend suite against MariaDB/Redis service containers, frontend
|
||||||
|
lint/type-check/build); publish.yml is manual and builds/pushes both images
|
||||||
|
multi-arch. Jobs run on the user-scoped msi-mortar-ci runner (labels
|
||||||
|
`desktop` + `ubuntu-latest`). Do not add actions/cache (`cache: pip`/`npm`)
|
||||||
|
to these workflows: Gitea's cache service hangs the job on restore/save.
|
||||||
- Security/permission tests live in backend/apps/core/tests and need a
|
- Security/permission tests live in backend/apps/core/tests and need a
|
||||||
one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%';
|
one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%';
|
||||||
|
|
||||||
@@ -85,7 +91,12 @@ Security hardening (do not weaken):
|
|||||||
SECRET_KEY (apps/accounts/crypto.py); rotating SECRET_KEY invalidates them
|
SECRET_KEY (apps/accounts/crypto.py); rotating SECRET_KEY invalidates them
|
||||||
(and all signed media URLs), so users must re-enter the key.
|
(and all signed media URLs), so users must re-enter the key.
|
||||||
- API throttles live in REST_FRAMEWORK (env-overridable): anon 120/min,
|
- API throttles live in REST_FRAMEWORK (env-overridable): anon 120/min,
|
||||||
user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour.
|
user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour. Signed
|
||||||
|
media URLs (raw/thumbnail/staged-file/similarity-file actions) are exempt
|
||||||
|
on purpose: <img>/<video> tags fetch them without an Authorization header,
|
||||||
|
so a gallery would otherwise drain the anonymous bucket and get 429 JSON
|
||||||
|
instead of images. THROTTLE_ENABLED=false removes the anon+user limits for
|
||||||
|
private/tailnet deployments (the login/register/proxy guards stay).
|
||||||
- Only admins (superusers) may grant/revoke the staff role or delete
|
- Only admins (superusers) may grant/revoke the staff role or delete
|
||||||
staff/admin accounts; staff manage regular/uploader accounts only.
|
staff/admin accounts; staff manage regular/uploader accounts only.
|
||||||
- Storage, duplicates, delete, temp-clear, uploads and downloads require
|
- Storage, duplicates, delete, temp-clear, uploads and downloads require
|
||||||
|
|||||||
Reference in New Issue
Block a user