mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
ci: refactor CI to use mise for shared tool setup (#25727)
This commit is contained in:
@@ -0,0 +1,76 @@
|
||||
name: "Go cache"
|
||||
description: Restore and save Go build and module caches.
|
||||
inputs:
|
||||
cache-path:
|
||||
description: "Optional newline-delimited cache paths. Defaults to go env GOCACHE and GOMODCACHE."
|
||||
required: false
|
||||
default: ""
|
||||
key-prefix:
|
||||
description: "Prefix for the cache key."
|
||||
required: false
|
||||
default: "go"
|
||||
download-modules:
|
||||
description: "Whether to run go mod download after restoring cache."
|
||||
required: false
|
||||
default: "true"
|
||||
runs:
|
||||
using: "composite"
|
||||
steps:
|
||||
- name: Compute Go cache key
|
||||
id: go-cache
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
if [[ -n "${INPUT_CACHE_PATH}" ]]; then
|
||||
paths="${INPUT_CACHE_PATH}"
|
||||
else
|
||||
paths="$(printf '%s\n%s' "$(go env GOCACHE)" "$(go env GOMODCACHE)")"
|
||||
fi
|
||||
|
||||
go_version="$(go env GOVERSION)"
|
||||
paths_hash="$(printf '%s\n' "${paths}" | git hash-object --stdin)"
|
||||
hash="$(
|
||||
{
|
||||
printf '%s\n' "${go_version}"
|
||||
for file in go.mod go.sum; do
|
||||
if [[ -f "${file}" ]]; then
|
||||
git hash-object "${file}"
|
||||
fi
|
||||
done
|
||||
} | git hash-object --stdin
|
||||
)"
|
||||
|
||||
{
|
||||
echo "path<<EOF"
|
||||
echo "${paths}"
|
||||
echo "EOF"
|
||||
echo "key=${INPUT_KEY_PREFIX}-${RUNNER_OS}-${RUNNER_ARCH}-${paths_hash}-${hash}"
|
||||
echo "restore-key=${INPUT_KEY_PREFIX}-${RUNNER_OS}-${RUNNER_ARCH}-${paths_hash}-"
|
||||
} >> "$GITHUB_OUTPUT"
|
||||
env:
|
||||
INPUT_CACHE_PATH: ${{ inputs.cache-path }}
|
||||
INPUT_KEY_PREFIX: ${{ inputs.key-prefix }}
|
||||
|
||||
- name: Restore Go cache, save on main
|
||||
if: ${{ github.ref == 'refs/heads/main' }}
|
||||
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
|
||||
with:
|
||||
path: ${{ steps.go-cache.outputs.path }}
|
||||
key: ${{ steps.go-cache.outputs.key }}
|
||||
restore-keys: |
|
||||
${{ steps.go-cache.outputs.restore-key }}
|
||||
|
||||
- name: Restore Go cache read-only
|
||||
if: ${{ github.ref != 'refs/heads/main' }}
|
||||
uses: actions/cache/restore@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
|
||||
with:
|
||||
path: ${{ steps.go-cache.outputs.path }}
|
||||
key: ${{ steps.go-cache.outputs.key }}
|
||||
restore-keys: |
|
||||
${{ steps.go-cache.outputs.restore-key }}
|
||||
|
||||
- name: Download Go modules
|
||||
if: ${{ inputs.download-modules == 'true' }}
|
||||
shell: bash
|
||||
run: ./.github/scripts/retry.sh -- go mod download -x
|
||||
@@ -1,10 +0,0 @@
|
||||
name: "Install cosign"
|
||||
description: |
|
||||
Cosign Github Action.
|
||||
runs:
|
||||
using: "composite"
|
||||
steps:
|
||||
- name: Install cosign
|
||||
uses: sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
|
||||
with:
|
||||
cosign-release: "v2.4.3"
|
||||
@@ -1,10 +0,0 @@
|
||||
name: "Install syft"
|
||||
description: |
|
||||
Downloads Syft to the Action tool cache and provides a reference.
|
||||
runs:
|
||||
using: "composite"
|
||||
steps:
|
||||
- name: Install syft
|
||||
uses: anchore/sbom-action/download-syft@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
|
||||
with:
|
||||
syft-version: "v1.26.1"
|
||||
@@ -0,0 +1,59 @@
|
||||
name: "pnpm install"
|
||||
description: Restore pnpm store cache and install root plus workspace dependencies.
|
||||
inputs:
|
||||
directory:
|
||||
description: "Workspace directory to install after the repository root."
|
||||
required: false
|
||||
default: "site"
|
||||
runs:
|
||||
using: "composite"
|
||||
steps:
|
||||
- name: Compute pnpm cache key
|
||||
id: pnpm-cache
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
store_path="$(pnpm store path --silent)"
|
||||
hash="$(
|
||||
for file in pnpm-lock.yaml "${INPUT_DIRECTORY}/pnpm-lock.yaml"; do
|
||||
if [[ -f "${file}" ]]; then
|
||||
git hash-object "${file}"
|
||||
fi
|
||||
done | git hash-object --stdin
|
||||
)"
|
||||
|
||||
{
|
||||
echo "store-path=${store_path}"
|
||||
echo "key=pnpm-${RUNNER_OS}-${RUNNER_ARCH}-${INPUT_DIRECTORY}-${hash}"
|
||||
echo "restore-key=pnpm-${RUNNER_OS}-${RUNNER_ARCH}-${INPUT_DIRECTORY}-"
|
||||
} >> "$GITHUB_OUTPUT"
|
||||
env:
|
||||
INPUT_DIRECTORY: ${{ inputs.directory }}
|
||||
|
||||
- name: Restore and save pnpm cache
|
||||
if: ${{ github.ref == 'refs/heads/main' }}
|
||||
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
|
||||
with:
|
||||
path: ${{ steps.pnpm-cache.outputs.store-path }}
|
||||
key: ${{ steps.pnpm-cache.outputs.key }}
|
||||
restore-keys: |
|
||||
${{ steps.pnpm-cache.outputs.restore-key }}
|
||||
|
||||
- name: Restore pnpm cache
|
||||
if: ${{ github.ref != 'refs/heads/main' }}
|
||||
uses: actions/cache/restore@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
|
||||
with:
|
||||
path: ${{ steps.pnpm-cache.outputs.store-path }}
|
||||
key: ${{ steps.pnpm-cache.outputs.key }}
|
||||
restore-keys: |
|
||||
${{ steps.pnpm-cache.outputs.restore-key }}
|
||||
|
||||
- name: Install root node_modules
|
||||
shell: bash
|
||||
run: ./scripts/pnpm_install.sh
|
||||
|
||||
- name: Install node_modules
|
||||
shell: bash
|
||||
run: "${GITHUB_WORKSPACE}/scripts/pnpm_install.sh"
|
||||
working-directory: ${{ github.workspace }}/${{ inputs.directory }}
|
||||
@@ -1,12 +0,0 @@
|
||||
name: "Setup Go tools"
|
||||
description: |
|
||||
Set up tools for `make gen`, `offlinedocs` and Schmoder CI.
|
||||
runs:
|
||||
using: "composite"
|
||||
steps:
|
||||
- name: go install tools
|
||||
shell: bash
|
||||
run: |
|
||||
./.github/scripts/retry.sh -- go install tool
|
||||
# NOTE: protoc-gen-go cannot be installed with `go get`
|
||||
./.github/scripts/retry.sh -- go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.30
|
||||
@@ -1,32 +0,0 @@
|
||||
name: "Setup Go"
|
||||
description: |
|
||||
Sets up the Go environment for tests, builds, etc.
|
||||
inputs:
|
||||
version:
|
||||
description: "The Go version to use."
|
||||
default: "1.26.2"
|
||||
use-cache:
|
||||
description: "Whether to use the cache."
|
||||
default: "true"
|
||||
runs:
|
||||
using: "composite"
|
||||
steps:
|
||||
- name: Setup Go
|
||||
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
|
||||
with:
|
||||
go-version: ${{ inputs.version }}
|
||||
cache: ${{ inputs.use-cache }}
|
||||
|
||||
- name: Install gotestsum
|
||||
shell: bash
|
||||
run: ./.github/scripts/retry.sh -- go install gotest.tools/gotestsum@0d9599e513d70e5792bb9334869f82f6e8b53d4d # main as of 2025-05-15
|
||||
|
||||
- name: Install mtimehash
|
||||
shell: bash
|
||||
run: ./.github/scripts/retry.sh -- go install github.com/slsyy/mtimehash/cmd/mtimehash@a6b5da4ed2c4a40e7b805534b004e9fde7b53ce0 # v1.0.0
|
||||
|
||||
# It isn't necessary that we ever do this, but it helps
|
||||
# separate the "setup" from the "run" times.
|
||||
- name: go mod download
|
||||
shell: bash
|
||||
run: ./.github/scripts/retry.sh -- go mod download -x
|
||||
@@ -0,0 +1,168 @@
|
||||
name: Setup mise
|
||||
description: Install mise tools from SHA256-pinned binaries, with CI-layer caching.
|
||||
inputs:
|
||||
install-args:
|
||||
description: Tool names or extra arguments passed to mise install. --locked is added by default.
|
||||
required: false
|
||||
default: ""
|
||||
locked:
|
||||
description: Whether to pass --locked to mise install.
|
||||
required: false
|
||||
default: "true"
|
||||
cache-key-prefix:
|
||||
description: Prefix for mise tool cache keys.
|
||||
required: false
|
||||
default: mise-ci-v1
|
||||
mise-version:
|
||||
description: mise version to install.
|
||||
required: false
|
||||
default: "2026.5.12"
|
||||
mise-sha256:
|
||||
description: SHA256 checksum for the mise binary.
|
||||
required: false
|
||||
default: ""
|
||||
use-cache:
|
||||
description: Whether to restore and save mise tool caches.
|
||||
required: false
|
||||
default: "true"
|
||||
runs:
|
||||
using: composite
|
||||
steps:
|
||||
- name: Compute mise cache key
|
||||
id: cache-key
|
||||
shell: bash
|
||||
env:
|
||||
CACHE_KEY_PREFIX: ${{ inputs.cache-key-prefix }}
|
||||
INPUT_INSTALL_ARGS: ${{ inputs.install-args }}
|
||||
INPUT_LOCKED: ${{ inputs.locked }}
|
||||
MISE_VERSION: ${{ inputs.mise-version }}
|
||||
RUNNER_ARCH: ${{ runner.arch }}
|
||||
RUNNER_OS: ${{ runner.os }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
case "${INPUT_LOCKED}" in
|
||||
true)
|
||||
if [[ -n "${INPUT_INSTALL_ARGS}" ]]; then
|
||||
install_args="--locked ${INPUT_INSTALL_ARGS}"
|
||||
else
|
||||
install_args="--locked"
|
||||
fi
|
||||
;;
|
||||
false)
|
||||
install_args="${INPUT_INSTALL_ARGS}"
|
||||
;;
|
||||
*)
|
||||
echo "::error::locked must be true or false."
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
install_args_hash="$(printf '%s' "$install_args" | git hash-object --stdin)"
|
||||
files_hash="$(git hash-object mise.toml mise.lock | git hash-object --stdin)"
|
||||
key="${CACHE_KEY_PREFIX}-${RUNNER_OS}-${RUNNER_ARCH}-${MISE_VERSION}-${install_args_hash}-${files_hash}"
|
||||
restore_key="${CACHE_KEY_PREFIX}-${RUNNER_OS}-${RUNNER_ARCH}-${MISE_VERSION}-${install_args_hash}-"
|
||||
|
||||
{
|
||||
echo "install-args<<EOF"
|
||||
echo "${install_args}"
|
||||
echo "EOF"
|
||||
echo "key=$key"
|
||||
echo "restore-key=$restore_key"
|
||||
} >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Select mise checksum
|
||||
id: checksum
|
||||
shell: bash
|
||||
env:
|
||||
CHECKSUMS_FILE: ${{ github.action_path }}/checksums.toml
|
||||
INPUT_MISE_SHA256: ${{ inputs.mise-sha256 }}
|
||||
MISE_CHECKSUM_SCRIPT: ${{ github.workspace }}/scripts/mise_checksum.sh
|
||||
MISE_VERSION: ${{ inputs.mise-version }}
|
||||
RUNNER_ARCH: ${{ runner.arch }}
|
||||
RUNNER_OS: ${{ runner.os }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
checksum="${INPUT_MISE_SHA256}"
|
||||
if [[ -z "${checksum}" ]]; then
|
||||
case "${RUNNER_OS}-${RUNNER_ARCH}" in
|
||||
Linux-X64)
|
||||
target="linux-x64"
|
||||
;;
|
||||
Linux-ARM64)
|
||||
target="linux-arm64"
|
||||
;;
|
||||
macOS-X64)
|
||||
target="macos-x64"
|
||||
;;
|
||||
macOS-ARM64)
|
||||
target="macos-arm64"
|
||||
;;
|
||||
Windows-X64)
|
||||
target="windows-x64"
|
||||
;;
|
||||
*)
|
||||
echo "::error::No mise checksum is pinned for ${RUNNER_OS}-${RUNNER_ARCH}."
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
checksum="$("${MISE_CHECKSUM_SCRIPT}" "${CHECKSUMS_FILE}" "${MISE_VERSION}" "${target}")"
|
||||
if [[ -z "${checksum}" ]]; then
|
||||
echo "::error::No mise checksum is pinned for mise ${MISE_VERSION} on ${target}."
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
echo "sha256=${checksum}" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Configure mise data directory
|
||||
id: mise-data-dir
|
||||
shell: bash
|
||||
env:
|
||||
RUNNER_OS: ${{ runner.os }}
|
||||
run: | # zizmor: ignore[github-env] MISE_DATA_DIR uses only runner-provided paths.
|
||||
set -euo pipefail
|
||||
|
||||
if [[ "${RUNNER_OS}" == "Windows" ]]; then
|
||||
data_dir="${LOCALAPPDATA:-${USERPROFILE}\\AppData\\Local}\\mise"
|
||||
else
|
||||
data_dir="${RUNNER_TEMP}/mise-data"
|
||||
fi
|
||||
|
||||
{
|
||||
printf 'path=%s\n' "${data_dir}"
|
||||
} >> "$GITHUB_OUTPUT"
|
||||
printf 'MISE_DATA_DIR=%s\n' "${data_dir}" >> "$GITHUB_ENV"
|
||||
|
||||
- name: Cache mise tools
|
||||
if: ${{ inputs.use-cache == 'true' && github.ref == 'refs/heads/main' }}
|
||||
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
|
||||
with:
|
||||
path: |
|
||||
~/.cache/mise
|
||||
${{ steps.mise-data-dir.outputs.path }}
|
||||
key: ${{ steps.cache-key.outputs.key }}
|
||||
restore-keys: |
|
||||
${{ steps.cache-key.outputs.restore-key }}
|
||||
|
||||
- name: Restore mise tools
|
||||
if: ${{ inputs.use-cache == 'true' && github.ref != 'refs/heads/main' }}
|
||||
uses: actions/cache/restore@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
|
||||
with:
|
||||
path: |
|
||||
~/.cache/mise
|
||||
${{ steps.mise-data-dir.outputs.path }}
|
||||
key: ${{ steps.cache-key.outputs.key }}
|
||||
restore-keys: |
|
||||
${{ steps.cache-key.outputs.restore-key }}
|
||||
|
||||
- name: Install mise tools
|
||||
uses: jdx/mise-action@1648a7812b9aeae629881980618f079932869151 # v4.0.1
|
||||
with:
|
||||
version: ${{ inputs.mise-version }}
|
||||
sha256: ${{ steps.checksum.outputs.sha256 }}
|
||||
mise_dir: ${{ steps.mise-data-dir.outputs.path }}
|
||||
install_args: ${{ steps.cache-key.outputs.install-args }}
|
||||
cache: "false"
|
||||
@@ -0,0 +1,9 @@
|
||||
# SHA256 hashes of the extracted mise binary verified by jdx/mise-action.
|
||||
# Keys use the GitHub runner target for each release artifact.
|
||||
|
||||
["2026.5.12"]
|
||||
linux-x64 = "a238972a3162d710b85b28c324372e96ca4e4b486c81fe78695000d9fbc77c48"
|
||||
linux-arm64 = "fd2d5227a8ad0b1e359c70527a8345a9ada72077f8dcbb559371653c3d95464f"
|
||||
macos-x64 = "de57e8dc82bbd880a69c9bc8aee06b9dcc578184b3e5cf86fcef80635d6a90b4"
|
||||
macos-arm64 = "e777070540ffe22cf8b2b9f88aed88b461d0887d940c4f1c1a97359463cde6e1"
|
||||
windows-x64 = "adf1b4c9f51e7d15cff723056fcd8fd51f40ebacadcca97fd5758c44d469d5ea"
|
||||
@@ -1,44 +0,0 @@
|
||||
name: "Setup Node"
|
||||
description: |
|
||||
Sets up the node environment for tests, builds, etc.
|
||||
inputs:
|
||||
directory:
|
||||
description: |
|
||||
The directory to run the setup in.
|
||||
required: false
|
||||
default: "site"
|
||||
runs:
|
||||
using: "composite"
|
||||
steps:
|
||||
- name: Install pnpm
|
||||
uses: pnpm/action-setup@739bfe42ca9233c5e6aca07c1a25a9d34aca49b0 # v6.0.7
|
||||
|
||||
- name: Setup Node
|
||||
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
||||
with:
|
||||
node-version: 22.19.0
|
||||
# See https://github.com/actions/setup-node#caching-global-packages-data
|
||||
cache: "pnpm"
|
||||
cache-dependency-path: ${{ inputs.directory }}/pnpm-lock.yaml
|
||||
|
||||
- name: Verify Node
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
expected="v22.19.0"
|
||||
actual="$(node --version)"
|
||||
if [[ "$actual" != "$expected" ]]; then
|
||||
echo "::error::Expected Node.js $expected, but got $actual from $(command -v node)."
|
||||
exit 1
|
||||
fi
|
||||
echo "Node.js $actual is active at $(command -v node)."
|
||||
|
||||
- name: Install root node_modules
|
||||
shell: bash
|
||||
run: ./scripts/pnpm_install.sh
|
||||
|
||||
- name: Install node_modules
|
||||
shell: bash
|
||||
run: ../scripts/pnpm_install.sh
|
||||
working-directory: ${{ inputs.directory }}
|
||||
@@ -1,17 +0,0 @@
|
||||
name: Setup sqlc
|
||||
description: |
|
||||
Sets up the sqlc environment for tests, builds, etc.
|
||||
runs:
|
||||
using: "composite"
|
||||
steps:
|
||||
- name: Setup sqlc
|
||||
# uses: sqlc-dev/setup-sqlc@c0209b9199cd1cce6a14fc27cabcec491b651761 # v4.0.0
|
||||
# with:
|
||||
# sqlc-version: "1.30.0"
|
||||
|
||||
# Switched to coder/sqlc fork to fix ambiguous column bug, see:
|
||||
# - https://github.com/coder/sqlc/pull/1
|
||||
# - https://github.com/sqlc-dev/sqlc/pull/4159
|
||||
shell: bash
|
||||
run: |
|
||||
./.github/scripts/retry.sh -- env CGO_ENABLED=1 go install github.com/coder/sqlc/cmd/sqlc@337309bfb9524f38466a5090e310040fc7af0203
|
||||
@@ -1,11 +0,0 @@
|
||||
name: "Setup Terraform"
|
||||
description: |
|
||||
Sets up Terraform for tests, builds, etc.
|
||||
runs:
|
||||
using: "composite"
|
||||
steps:
|
||||
- name: Install Terraform
|
||||
uses: hashicorp/setup-terraform@b9cd54a3c349d3f38e8881555d616ced269862dd # v3.1.2
|
||||
with:
|
||||
terraform_version: 1.15.5
|
||||
terraform_wrapper: false
|
||||
Reference in New Issue
Block a user