diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml deleted file mode 100644 index 81246706c..000000000 --- a/.github/workflows/build.yml +++ /dev/null @@ -1,95 +0,0 @@ -name: Build - -on: - push: - branches: - - main - pull_request: - -concurrency: - group: ${{ github.workflow }}-$${{ github.head_ref || github.run_id }} - cancel-in-progress: true - -defaults: - run: - shell: nix develop --fallback --command bash -e {0} - -jobs: - build-nix: - runs-on: ubuntu-latest - permissions: write-all - steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 - with: - fetch-depth: 2 - - name: Get changed files - id: changed-files - uses: dorny/paths-filter@de90cc6fb38fc0963ad72b210f1f284cd68cea36 # v3.0.2 - with: - filters: | - files: - - '*.nix' - - 'go.*' - - '**/*.go' - - 'integration_test/' - - 'config-example.yaml' - - uses: NixOS/nix-installer-action@6b8548fe06acfb0155a50ab5d561accb215764cc # main - if: steps.changed-files.outputs.files == 'true' - - uses: Mic92/hestia/action@ff07bb902a9968ac0c3d0e51d90a606662a375d8 # main - if: steps.changed-files.outputs.files == 'true' - - - name: Check vendor hash - id: vendorhash - if: steps.changed-files.outputs.files == 'true' - run: | - go run ./cmd/vendorhash check | tee check-result - { - grep '^expected_sri=' check-result || true - grep '^actual_sri=' check-result || true - } >> "$GITHUB_OUTPUT" - - - name: Vendor hash diverging - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 - if: failure() && steps.vendorhash.outcome == 'failure' - with: - github-token: ${{secrets.GITHUB_TOKEN}} - script: | - github.rest.pulls.createReviewComment({ - pull_number: context.issue.number, - owner: context.repo.owner, - repo: context.repo.repo, - body: 'Vendor hash in `flakehashes.json` is stale (was `${{ steps.vendorhash.outputs.expected_sri }}`, should be `${{ steps.vendorhash.outputs.actual_sri }}`). Run `go run ./cmd/vendorhash update` and commit the result.' - }) - - - name: Run nix build - if: steps.changed-files.outputs.files == 'true' - run: nix build --fallback - - - uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0 - if: steps.changed-files.outputs.files == 'true' - with: - name: headscale-linux - path: result/bin/headscale - build-cross: - runs-on: ubuntu-latest - strategy: - matrix: - env: - - "GOARCH=arm64 GOOS=linux" - - "GOARCH=amd64 GOOS=linux" - - "GOARCH=arm64 GOOS=darwin" - - "GOARCH=amd64 GOOS=darwin" - steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 - - uses: NixOS/nix-installer-action@6b8548fe06acfb0155a50ab5d561accb215764cc # main - - uses: Mic92/hestia/action@ff07bb902a9968ac0c3d0e51d90a606662a375d8 # main - - - name: Run go cross compile - env: - CGO_ENABLED: 0 - run: env ${{ matrix.env }} go build -o "headscale" - ./cmd/headscale - - uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0 - with: - name: "headscale-${{ matrix.env }}" - path: "headscale" diff --git a/.github/workflows/nix-checks.yml b/.github/workflows/nix-checks.yml deleted file mode 100644 index 03c4b8e8b..000000000 --- a/.github/workflows/nix-checks.yml +++ /dev/null @@ -1,56 +0,0 @@ -name: Nix Flake Checks - -on: - push: - branches: - - main - pull_request: - branches: - - main - -concurrency: - group: ${{ github.workflow }}-$${{ github.head_ref || github.run_id }} - cancel-in-progress: true - -# Each job only runs `nix build .#checks..`; the check logic lives -# in flake.nix via the flake-checks library. The fileset-filtered checks hit the -# hestia cache when their inputs are unchanged, so no changed-files gating. -permissions: - contents: read - -jobs: - build: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 - - uses: NixOS/nix-installer-action@6b8548fe06acfb0155a50ab5d561accb215764cc # main - - uses: Mic92/hestia/action@ff07bb902a9968ac0c3d0e51d90a606662a375d8 # main - - name: build - run: nix build -L .#checks.x86_64-linux.build - - gotest: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 - - uses: NixOS/nix-installer-action@6b8548fe06acfb0155a50ab5d561accb215764cc # main - - uses: Mic92/hestia/action@ff07bb902a9968ac0c3d0e51d90a606662a375d8 # main - - name: gotest - run: nix build -L .#checks.x86_64-linux.gotest - - golangci-lint: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 - - uses: NixOS/nix-installer-action@6b8548fe06acfb0155a50ab5d561accb215764cc # main - - uses: Mic92/hestia/action@ff07bb902a9968ac0c3d0e51d90a606662a375d8 # main - - name: golangci-lint - run: nix build -L .#checks.x86_64-linux.golangci-lint - - formatting: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 - - uses: NixOS/nix-installer-action@6b8548fe06acfb0155a50ab5d561accb215764cc # main - - uses: Mic92/hestia/action@ff07bb902a9968ac0c3d0e51d90a606662a375d8 # main - - name: formatting - run: nix build -L .#checks.x86_64-linux.formatting diff --git a/.github/workflows/nix-module-test.yml b/.github/workflows/nix-module-test.yml deleted file mode 100644 index 1a7fbcc85..000000000 --- a/.github/workflows/nix-module-test.yml +++ /dev/null @@ -1,51 +0,0 @@ -name: NixOS Module Tests - -on: - push: - branches: - - main - pull_request: - branches: - - main - -concurrency: - group: ${{ github.workflow }}-$${{ github.head_ref || github.run_id }} - cancel-in-progress: true - -jobs: - nix-module-check: - runs-on: ubuntu-latest - permissions: - contents: read - - steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 - with: - fetch-depth: 2 - - - name: Get changed files - id: changed-files - uses: dorny/paths-filter@de90cc6fb38fc0963ad72b210f1f284cd68cea36 # v3.0.2 - with: - filters: | - nix: - - 'nix/**' - - 'flake.nix' - - 'flake.lock' - go: - - 'go.*' - - '**/*.go' - - 'cmd/**' - - 'hscontrol/**' - - - uses: NixOS/nix-installer-action@6b8548fe06acfb0155a50ab5d561accb215764cc # main - if: steps.changed-files.outputs.nix == 'true' || steps.changed-files.outputs.go == 'true' - - - uses: Mic92/hestia/action@ff07bb902a9968ac0c3d0e51d90a606662a375d8 # main - if: steps.changed-files.outputs.nix == 'true' || steps.changed-files.outputs.go == 'true' - - - name: Run NixOS module tests - if: steps.changed-files.outputs.nix == 'true' || steps.changed-files.outputs.go == 'true' - run: | - echo "Running NixOS module integration test..." - nix build .#checks.x86_64-linux.headscale -L --fallback diff --git a/.github/workflows/test-integration.yaml b/.github/workflows/test-integration.yaml deleted file mode 100644 index 3b8e858ce..000000000 --- a/.github/workflows/test-integration.yaml +++ /dev/null @@ -1,55 +0,0 @@ -name: integration - -on: - pull_request: - branches: - - main - -concurrency: - group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }} - cancel-in-progress: true - -permissions: - contents: read - -# Each test is a NixOS-VM flake check (full tailscale version matrix, sqlite -# plus a postgres variant) — one job per check, derived from the checks the -# flake exposes. The fileset-filtered, content-addressed checks hit the hestia -# cache when their inputs are unchanged. A prime job builds the shared images + -# test binary once so the matrix substitutes them instead of each rebuilding. -jobs: - list: - runs-on: ubuntu-latest - outputs: - checks: ${{ steps.list.outputs.checks }} - steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 - - uses: NixOS/nix-installer-action@6b8548fe06acfb0155a50ab5d561accb215764cc # main - - uses: Mic92/hestia/action@ff07bb902a9968ac0c3d0e51d90a606662a375d8 # main - - id: list - run: | - checks=$(nix eval --json .#checks.x86_64-linux --apply builtins.attrNames \ - | jq -c '[.[] | select(startswith("integration-"))]') - echo "checks=$checks" >> "$GITHUB_OUTPUT" - - prime: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 - - uses: NixOS/nix-installer-action@6b8548fe06acfb0155a50ab5d561accb215764cc # main - - uses: Mic92/hestia/action@ff07bb902a9968ac0c3d0e51d90a606662a375d8 # main - - run: nix build -L --fallback .#packages.x86_64-linux.integration-deps - - integration: - needs: [list, prime] - runs-on: ubuntu-latest - strategy: - fail-fast: false - matrix: - check: ${{ fromJson(needs.list.outputs.checks) }} - steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1 - - uses: NixOS/nix-installer-action@6b8548fe06acfb0155a50ab5d561accb215764cc # main - - uses: Mic92/hestia/action@ff07bb902a9968ac0c3d0e51d90a606662a375d8 # main - - name: ${{ matrix.check }} - run: nix build -L --fallback .#checks.x86_64-linux.${{ matrix.check }} diff --git a/integration/README.md b/integration/README.md index 5511a113f..ce180246d 100644 --- a/integration/README.md +++ b/integration/README.md @@ -21,16 +21,19 @@ go run ./cmd/hi doctor go run ./cmd/hi run "TestPingAllByIP" ``` -Alternatively, [`act`](https://github.com/nektos/act) runs the GitHub -Actions workflow locally: +In CI each test also runs as its own hermetic NixOS-VM flake check. Run +one locally exactly the way CI does: ```bash -act pull_request -W .github/workflows/test-integration.yaml +nix build .#checks.x86_64-linux.integration-TestPingAllByIP ``` -Each test runs as a separate workflow on GitHub Actions. To add a new -test, run `go generate` inside `../cmd/gh-action-integration-generator/` -and commit the generated workflow file. +The check matrix is generated: after adding or renaming a test, run `go +generate` in `.github/workflows/` to refresh `integration/tests.nix`, +`integration/postgres-tests.nix`, and `integration/excluded-tests.json`, +then commit the result. Tests that need the public internet (real DERP) +cannot run hermetically; they are listed in `excluded-tests.json` and +run via the `integration-legacy` workflow instead. ## Framework overview