Install runner prerequisites in the pinned build container (closes #7)
All checks were successful
check / check (push) Successful in 10s
All checks were successful
check / check (push) Successful in 10s
Replacing klakegg/hugo:ext-alpine with the Dockerfile's pinned alpine digest satisfied the pinning requirement but dropped the runtime the Actions runner itself depends on, which would have broken the deploy: - act_runner executes JavaScript actions with `node` inside the job container and does not inject one. Stock alpine has no node, so actions/checkout - the job's first step - would fail with "node: not found", and script/bootstrap (which installs node) is step 2 and never runs. The build job fails, deploy is skipped for `needs: build`, and the site stops publishing. - Steps default to `bash`, which stock alpine does not ship either. Fixes, both scoped to keeping the mandated image replacement runnable: - A pre-checkout inline `run:` step (`apk add --no-cache nodejs git tar`) installs what the runner needs before the first `uses:` step. An inline run needs only a shell, so it works on the bare image. git is there for checkout's `submodules: recursive`; without it checkout degrades to a tarball download that cannot do submodules. - `defaults.run.shell: sh` on the build job, so the shell is stated rather than left to a bash-to-sh fallback. No pinned value is touched. The apk packages resolve at run time and are not hash-pinned; that gap is repo-wide (script/bootstrap has it too) and is tracked in #19. Also moves each version/date comment to sit directly above the pinned line rather than above the step's `- name:`, matching check.yml, and dates the actions/checkout pin 2026-02-28 as check.yml already does for the same SHA. Verified by running the build job's step sequence inside the pinned alpine digest: bare, `node` and `bash` are absent and the pinned checkout bundle dies with "node: not found"; after the new apk step, node 22.23.2, git 2.47.3 and GNU tar 1.35 are present, that same checkout bundle runs under node and gets as far as "GITHUB_WORKSPACE not defined", and script/bootstrap, script/test and the tar step all complete. make check and script/cibuild (with the build cache pruned, so nothing was CACHED) are green.
This commit is contained in:
8
TODO.md
8
TODO.md
@@ -31,9 +31,11 @@ Update `README.md` accordingly.
|
||||
(`upload`/`download-artifact` moved v3 to v4), and the wrangler install is
|
||||
pinned to an exact version. The abandoned `klakegg/hugo:ext-alpine` image is
|
||||
gone: the build job now runs on the same pinned `alpine` digest the
|
||||
`Dockerfile` uses, with `script/bootstrap` then `script/test`. Also dropped
|
||||
the dead `feat/initial-site` push trigger and reindented the file to 4-space
|
||||
YAML to match `check.yml`
|
||||
`Dockerfile` uses, with a pre-checkout `apk add nodejs git tar` step (the
|
||||
Actions runner needs `node` inside the job container to execute JavaScript
|
||||
actions), an explicit `shell: sh` default, then `script/bootstrap` and
|
||||
`script/test`. Also dropped the dead `feat/initial-site` push trigger and
|
||||
reindented the file to 4-space YAML to match `check.yml`
|
||||
- 2026-07-25: added the scripts-to-rule-them-all scaffold (closes #4): `script/`
|
||||
entrypoints, `Makefile` shims, a Hugo `Dockerfile` (sha256-pinned alpine) plus
|
||||
`.dockerignore` that runs `make check`, `.gitea/workflows/check.yml` running
|
||||
|
||||
Reference in New Issue
Block a user