Files
artifactapi/.woodpecker/pre-commit.yaml
T
unkin-agent 10671884d2
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci: move Go steps to the estate-built gobuilder image
The packer-built almalinux9-gobuilder image is being retired. Switch
test and pre-commit steps to artifactapi docker-internal/gobuilder
0.1.2-alma9, which trusts the estate CA and ships go-cache-plugin
baked in on PATH.

- Point test/pre-commit steps at the new image
- Drop the curl/sha256sum bootstrap for go-cache-plugin; set
  GOCACHEPROG directly as a static env var since the binary is
  always present now
- Best-effort S3 cache behaviour is unchanged: verified go build/test
  still succeed with unreachable/invalid S3 credentials, since the
  plugin itself degrades to cache misses at runtime
2026-10-02 23:45:55 +10:00

35 lines
1.2 KiB
YAML

when:
- event: pull_request
steps:
- name: pre-commit
# gobuilder trusts the internal CA, which the S3 build cache endpoint needs.
# go-cache-plugin is baked into the image; S3 errors degrade to cache misses.
image: "artifactapi.k8s.syd1.au.unkin.net/docker-internal/gobuilder:0.1.2-alma9"
commands:
- uvx pre-commit run --all-files
environment:
# golib lives on Gitea; skip the public proxy/sum db.
GOPRIVATE: git.unkin.net
GOCACHEPROG: "go-cache-plugin --cache-dir=/tmp/gocache"
GOCACHE_S3_BUCKET: gocache
# Explicit region skips a GetBucketLocation probe RGW handles poorly.
GOCACHE_S3_REGION: us-east-1
GOCACHE_S3_ENDPOINT_URL: "https://s3.ceph.unkin.net"
GOCACHE_S3_PATH_STYLE: "true"
GOCACHE_KEY_PREFIX: ci-artifactapi
AWS_ACCESS_KEY_ID:
from_secret: GOCACHE_AWS_ACCESS_KEY_ID
AWS_SECRET_ACCESS_KEY:
from_secret: GOCACHE_AWS_SECRET_ACCESS_KEY
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 1
limits:
memory: 2Gi
cpu: 2