Restore native Forgejo CI with isolated ephemeral runners #8

Open
adam wants to merge 11 commits from codex/forgejo-repository-cutover into main
Owner

Restore project validation on Forgejo using the existing pinned inputs and full native workflow gates. Jobs run in fresh repository-scoped ephemeral VMs; deployment and cache publishing credentials stay outside the guests. Owned source fetches retain the same revisions.

The ARM runner passed live private checkout, scoped Nix fetching, artifact upload with independent stored-content hashing, anonymous denial, and a dependent job in a second fresh VM. Native x86 and full project workflow results are required before changing the protected merge gate. Main tips and administrator push/merge blocks remain unchanged.

GitHub workflows remain as historical records. Go module identities and historical provenance links are preserved. Host fixture checks do not establish deployed-host acceptance; production physical provisioning remains separately gated.

Includes the isolated VM, HTTPS relay, one-job controller, digest-bound host installer and operational recovery procedure. Validation: 91 infrastructure policy tests, 46 provisioning CI tests, and actionlint for all ported workflows. The one-time host installer avoids per-job sudo or hardware operations. Restricted control tokens are stored through systemd LoadCredential and never shared with guests.

Restore project validation on Forgejo using the existing pinned inputs and full native workflow gates. Jobs run in fresh repository-scoped ephemeral VMs; deployment and cache publishing credentials stay outside the guests. Owned source fetches retain the same revisions. The ARM runner passed live private checkout, scoped Nix fetching, artifact upload with independent stored-content hashing, anonymous denial, and a dependent job in a second fresh VM. Native x86 and full project workflow results are required before changing the protected merge gate. Main tips and administrator push/merge blocks remain unchanged. GitHub workflows remain as historical records. Go module identities and historical provenance links are preserved. Host fixture checks do not establish deployed-host acceptance; production physical provisioning remains separately gated. Includes the isolated VM, HTTPS relay, one-job controller, digest-bound host installer and operational recovery procedure. Validation: 91 infrastructure policy tests, 46 provisioning CI tests, and actionlint for all ported workflows. The one-time host installer avoids per-job sudo or hardware operations. Restricted control tokens are stored through systemd LoadCredential and never shared with guests.
adam changed title from Stage Forgejo primary hosting and journaled migration tooling to Restore native Forgejo CI with isolated ephemeral runners 2026-10-04 02:23:28 -04:00
Keep Forgejo workflow changes in the full CI selection boundary
Some checks failed
Validate infrastructure / Infrastructure policy (pull_request) Has been cancelled
Validate infrastructure / forgejo (pull_request) Has been cancelled
e4191f0cfe
Accept protected systemd credentials and persist NixOS CI units
Some checks failed
Validate infrastructure / forgejo (pull_request) Failing after 1m23s
Validate infrastructure / Infrastructure policy (pull_request) Has been cancelled
2903032065
Provision isolated restore fixture token without password API login
Some checks failed
Validate infrastructure / forgejo (pull_request) Failing after 47s
Validate infrastructure / Infrastructure policy (pull_request) Has been cancelled
fd59c77baa
Remove obsolete fixture test-driver import
Some checks failed
Validate infrastructure / forgejo (pull_request) Failing after 1m21s
Validate infrastructure / Infrastructure policy (pull_request) Has been cancelled
162ad4dc56
Use guest disk for build store and size measured ARM assembly peak
All checks were successful
Validate infrastructure / forgejo (pull_request) Successful in 1m31s
Validate infrastructure / Infrastructure policy (pull_request) Successful in 8s
8d20c25a57
Some checks are pending
Validate infrastructure / forgejo (pull_request) Successful in 1m31s
Validate infrastructure / Infrastructure policy (pull_request) Successful in 8s
kaiba/ci-cutover-pending
Required
Some required checks are missing.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin codex/forgejo-repository-cutover:codex/forgejo-repository-cutover
git switch codex/forgejo-repository-cutover
Sign in to join this conversation.
No description provided.