ci: use static matrices with change-based guards
Build containers / Compute changes (push) Successful in 3s
Build containers / fedora-cosmic (rawhide) (push) Failing after 1m10s
Build containers / fedora-remote (44) (push) Failing after 1m14s
Build containers / fedora-cosmic (44) (push) Successful in 13m5s
Build containers / Prune old releases and tags (push) Failing after 28s

Gitea does not expand a dynamic fromJson matrix (the job name stayed literal
and it queued with no matching runner). Instead, compute cosmic/remote booleans
in a changes job and gate static-matrix build jobs with job-level if.
This commit is contained in:
2026-09-27 23:14:13 +02:00
parent fdc1441c32
commit 8e85980468
3 changed files with 67 additions and 44 deletions
+43 -11
View File
@@ -13,17 +13,18 @@ on:
jobs: jobs:
# Work out which images actually changed, so a push only rebuilds those. # Work out which images actually changed, so a push only rebuilds those.
changes: changes:
name: Compute build matrix name: Compute changes
runs-on: job-v2 runs-on: job-v2
outputs: outputs:
matrix: ${{ steps.matrix.outputs.matrix }} cosmic: ${{ steps.changes.outputs.cosmic }}
remote: ${{ steps.changes.outputs.remote }}
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: actions/checkout@v4
with: with:
fetch-depth: 0 fetch-depth: 0
- name: Compute matrix - name: Detect changed images
id: matrix id: changes
shell: bash shell: bash
run: | run: |
set -euo pipefail set -euo pipefail
@@ -36,17 +37,28 @@ jobs:
else else
changed="" changed=""
fi fi
matrix="$(printf '%s\n' "${changed}" | ./ci-matrix.sh)" eval "$(printf '%s\n' "${changed}" | ./ci-changes.sh)"
echo "matrix=${matrix}" >> "$GITHUB_OUTPUT" echo "cosmic=${cosmic}" >> "$GITHUB_OUTPUT"
echo "remote=${remote}" >> "$GITHUB_OUTPUT"
build: build-cosmic:
name: ${{ matrix.image }} (${{ matrix.distro }}) name: ${{ matrix.image }} (${{ matrix.distro }})
needs: changes needs: changes
if: needs.changes.outputs.cosmic == 'true'
runs-on: ${{ matrix.runner }} runs-on: ${{ matrix.runner }}
strategy: strategy:
fail-fast: false fail-fast: false
matrix: ${{ fromJson(needs.changes.outputs.matrix) }} matrix:
include:
- image: fedora-cosmic
distro: "44"
arch: x86_64
runner: job-v2
- image: fedora-cosmic
distro: rawhide
arch: x86_64
runner: job-v2
container: container:
image: "quay.io/fedora-ostree-desktops/buildroot:${{ matrix.distro }}" image: "quay.io/fedora-ostree-desktops/buildroot:${{ matrix.distro }}"
@@ -60,7 +72,7 @@ jobs:
GITEA_URL: https://git.plabble.org GITEA_URL: https://git.plabble.org
GITEA_REPO: Misthios/bootc-images GITEA_REPO: Misthios/bootc-images
steps: steps: &build_steps
- name: Install build tools - name: Install build tools
run: | run: |
set -xeuo pipefail set -xeuo pipefail
@@ -138,11 +150,31 @@ jobs:
pkgs="build/${IMAGE}-${DISTRO}-${ARCH}/packages-current.txt" pkgs="build/${IMAGE}-${DISTRO}-${ARCH}/packages-current.txt"
./release.sh "${IMAGE}" "${DISTRO}" "${buildid}" "${pkgs}" ./release.sh "${IMAGE}" "${DISTRO}" "${buildid}" "${pkgs}"
build-remote:
name: fedora-remote (44)
needs: changes
if: needs.changes.outputs.remote == 'true'
runs-on: job-v2
container:
image: "quay.io/fedora-ostree-desktops/buildroot:44"
options: "--security-opt=label=disable --privileged --user 0:0 --device=/dev/fuse --volume /:/run/host:rw"
env:
IMAGE: fedora-remote
DISTRO: "44"
ARCH: x86_64
REGISTRY: git.plabble.org/misthios
GITEA_URL: https://git.plabble.org
GITEA_REPO: Misthios/bootc-images
steps: *build_steps
prune: prune:
name: Prune old releases and tags name: Prune old releases and tags
runs-on: job-v2 runs-on: job-v2
needs: [changes, build] needs: [changes, build-cosmic, build-remote]
# Run even if some matrix builds failed (e.g. rawhide churn). # Run even if some builds were skipped or failed.
if: ${{ always() && github.event_name != 'pull_request' }} if: ${{ always() && github.event_name != 'pull_request' }}
container: container:
image: "quay.io/fedora-ostree-desktops/buildroot:44" image: "quay.io/fedora-ostree-desktops/buildroot:44"
Executable
+24
View File
@@ -0,0 +1,24 @@
#!/usr/bin/env bash
# Given changed paths on stdin, print `cosmic=<bool>` and `remote=<bool>` so the
# workflow can skip images that didn't change. Shared files or build tooling
# changes rebuild everything; empty input (schedule/manual) rebuilds everything.
set -euo pipefail
changed="$(cat || true)"
all=0
[[ -z "${changed}" ]] && all=1
grep -qE '^(build\.sh|release\.sh|prune-releases\.sh|prune-registry\.sh|ci-changes\.sh|\.gitea/)' <<< "${changed}" && all=1
grep -qE '^images/shared/' <<< "${changed}" && all=1
cosmic=false
remote=false
if [[ "${all}" == 1 ]]; then
cosmic=true
remote=true
fi
grep -qE '^images/fedora-cosmic/' <<< "${changed}" && cosmic=true
grep -qE '^images/fedora-remote/' <<< "${changed}" && remote=true
echo "cosmic=${cosmic}"
echo "remote=${remote}"
-33
View File
@@ -1,33 +0,0 @@
#!/usr/bin/env bash
# Print the CI build matrix (JSON) for the images affected by the paths on
# stdin (one per line). Any change to shared files or the build tooling
# rebuilds every image. Empty input (e.g. schedule/manual runs) rebuilds all.
set -euo pipefail
changed="$(cat || true)"
all=0
[[ -z "${changed}" ]] && all=1
grep -qE '^(build\.sh|release\.sh|prune-releases\.sh|prune-registry\.sh|ci-matrix\.sh|\.gitea/)' <<< "${changed}" && all=1
grep -qE '^images/shared/' <<< "${changed}" && all=1
cosmic=0
remote=0
if [[ "${all}" == 1 ]]; then
cosmic=1
remote=1
fi
grep -qE '^images/fedora-cosmic/' <<< "${changed}" && cosmic=1
grep -qE '^images/fedora-remote/' <<< "${changed}" && remote=1
entries=()
if [[ "${cosmic}" == 1 ]]; then
entries+=('{"image":"fedora-cosmic","distro":"44","arch":"x86_64","runner":"job-v2"}')
entries+=('{"image":"fedora-cosmic","distro":"rawhide","arch":"x86_64","runner":"job-v2"}')
fi
if [[ "${remote}" == 1 ]]; then
entries+=('{"image":"fedora-remote","distro":"44","arch":"x86_64","runner":"job-v2"}')
fi
joined="$(IFS=,; printf '%s' "${entries[*]:-}")"
printf '{"include":[%s]}\n' "${joined}"