Restore native Forgejo CI with isolated ephemeral runners #8
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
kaiba/kaiba-infra!8
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "codex/forgejo-repository-cutover"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Restore project validation on Forgejo using the existing pinned inputs and full native workflow gates. Jobs run in fresh repository-scoped ephemeral VMs; deployment and cache publishing credentials stay outside the guests. Owned source fetches retain the same revisions.
The ARM runner passed live private checkout, scoped Nix fetching, artifact upload with independent stored-content hashing, anonymous denial, and a dependent job in a second fresh VM. Native x86 and full project workflow results are required before changing the protected merge gate. Main tips and administrator push/merge blocks remain unchanged.
GitHub workflows remain as historical records. Go module identities and historical provenance links are preserved. Host fixture checks do not establish deployed-host acceptance; production physical provisioning remains separately gated.
Includes the isolated VM, HTTPS relay, one-job controller, digest-bound host installer and operational recovery procedure. Validation: 91 infrastructure policy tests, 46 provisioning CI tests, and actionlint for all ported workflows. The one-time host installer avoids per-job sudo or hardware operations. Restricted control tokens are stored through systemd LoadCredential and never shared with guests.
Stage Forgejo primary hosting and journaled migration toolingto Restore native Forgejo CI with isolated ephemeral runnersView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.