Files
actions/README.md
T
jcoffey-dev 1f0c7971d6 discourse-release: announce a given tag, for releases made by the job's own token
Gitea starts no workflow for events caused by the Actions bot, so a release
created with GITHUB_TOKEN never fires 'on: release'. With 'tag:' the action
fetches that release itself; drafts are skipped.
2026-09-26 19:26:53 -07:00

63 lines
2.2 KiB
Markdown

# actions
Shared Gitea Actions for Coffey Labs and INBUXA workflows. The instance sets
`DEFAULT_ACTIONS_URL = self`, so `uses: coffey-labs/actions/<name>@<sha>`
resolves here and nothing is fetched from GitHub implicitly.
Pin every use by full commit SHA.
## checkout
```yaml
- uses: coffey-labs/actions/checkout@<sha>
with:
fetch-depth: 0 # optional; default 1. 0 = all history and tags
tags: true # optional; tags with a shallow fetch
```
Works in any job image with a POSIX shell. Installs git with apk or apt-get
if the image has none, and clones from the runner's internal Gitea address
(`CI_SERVER_INTERNAL`) so CI traffic never crosses Cloudflare.
## discourse-release
Announces a published release on the community forum, in the repo's
Announcements category. Add to a project repo as `.gitea/workflows/announce.yml`:
```yaml
on:
release:
types: [published]
jobs:
announce:
runs-on: light
steps:
- uses: coffey-labs/actions/discourse-release@<sha>
with:
api-key: ${{ secrets.DISCOURSE_RELEASE_KEY }}
discord-webhook: ${{ secrets.DISCORD_RELEASE_WEBHOOK }} # optional
```
A workflow that creates its release with the job's own token (`secrets.GITHUB_TOKEN`)
must announce it itself, as a last step: Gitea starts no workflow for events
the Actions bot causes, so `on: release` never fires for such a release.
```yaml
- uses: coffey-labs/actions/discourse-release@<sha>
with:
api-key: ${{ secrets.DISCOURSE_RELEASE_KEY }}
tag: ${{ github.ref_name }}
```
Both at once is fine: a repo+tag is announced once, whichever runs first.
- The repo must be listed in `discourse-release/release-map.json`, the one
place that maps repos to forum categories.
- `DISCOURSE_RELEASE_KEY` is an org-level secret (coffey-labs and inbuxa)
holding release-bot's key, which can only create posts.
- Re-running is safe: each repo+tag gets one topic, enforced by the forum.
- Release notes are passed to the forum through `jq` only, so quotes,
backticks and multi-line Markdown arrive exactly as written.
- To turn it off for a repo, delete its `announce.yml`; for everyone, remove
the org secret.