Files
chemenu/.gitea/workflows/nightly.yml
T
torben e4b2b6d9b1
CI / verify (push) Successful in 2m18s
Release / release (push) Successful in 36s
feat: preflight - prerequisites checked and tool paths recorded before wikitool runs; launcher refuses without it (#151, POSIX half)
Files changed:
- .claude/settings.json
- .gitea/workflows/ci.yml
- .gitea/workflows/nightly.yml
- .gitea/workflows/release.yml
- .gitea/workflows/tracker-live.yml
- .github/hooks/wiki-trace.json
- .gitignore
- .vibe/hooks.toml
- AGENTS.md
- CHANGES.md
- EVALS.md
- INSTALL.md
- README.md
- VERSION
- instructions/bootstrap.md
- instructions/preflight.md
- instructions/setup-instance.md
- instructions/upgrade-instance.md
- tools/CONTRACT.md
- tools/README.md
- tools/chemenu/cli.py
- tools/chemenu/commands/dist_cmd.py
- tools/chemenu/commands/docs_verify.py
- tools/chemenu/commands/doctor.py
- tools/chemenu/commands/git_publish.py
- tools/chemenu/commands/migrate_cmd.py
- tools/chemenu/config.py
- tools/chemenu/corpus_cache.py
- tools/chemenu/prerequisites.py
- tools/chemenu/search/ripgrep.py
- tools/chemenu/tests/conftest.py
- tools/chemenu/tests/test_dist_upgrade.py
- tools/chemenu/tests/test_doctor.py
- tools/chemenu/tests/test_preflight.py
- tools/chemenu/toolpaths.py
- tools/preflight.sh
- tools/prerequisites.txt
- tools/run_wikitool.py
- tools/trace-hook
- tools/wikitool
2026-10-01 05:52:55 +02:00

103 lines
4.3 KiB
YAML

# Nightly drift check.
#
# CI (`ci.yml`) runs on push and deliberately ignores content paths, because
# `publish` touches kb/, raw/ and work/ on every ingest and running the suite
# for that is noise. That exclusion is observed to work (Gitea #11), which is
# exactly why this file exists: since it landed, `lint --fail-on-error` no
# longer runs when the *corpus* changes. A wiki that drifts into inconsistency
# over a run of publishes would be seen by nobody.
#
# There is also drift that happens with no commit at all. `sources coverage`
# starts reporting the moment a file appears under `raw/` without a source page
# claiming it, and `migrate status` only answers when something asks.
#
# So: the same checks CI runs against the tree, on a clock instead of a push.
# `lint --fail-on-error` is the reason; the rest costs seconds.
#
# Deliberately absent: `migrate verify --from <rev>`. It needs a comparison
# revision that means something, and "yesterday" is not one - the invariant
# diff answers "did *this migration* lose anything", not "did anything change
# since yesterday". In normal operation a changed page is the desired outcome,
# not a finding.
#
# Runner shape: identical to ci.yml, and for the same reason - `nodejs` is what
# act_runner needs to execute the JavaScript `checkout` action *inside* the job
# container, so it is installed before the checkout or the job dies with exit
# 127. Do not re-derive this; see the header of ci.yml.
#
# Failure is meant to be visible without opening the Actions page. That is
# Gitea's own run notification, not something this workflow builds: a job that
# files its own issue needs an Actions token with issue-write and a dedup rule,
# which is more machinery than a red run already carries.
name: Nightly
on:
schedule:
# 03:17 UTC. Gitea evaluates cron in UTC and only for workflows on the
# default branch, so this file has to live on `main` to fire at all - a
# test branch proves nothing about it.
- cron: '17 3 * * *'
workflow_dispatch:
jobs:
drift:
runs-on: linux-docker
container:
image: debian:trixie-slim
env:
# Scope the Iteration Budget Gate to this run instead of letting it fall
# back to the parent PID, and keep the trace out of the checkout so the
# working tree stays clean.
WIKITOOL_SESSION_ID: nightly-${{ github.run_id }}
WIKI_TRACE_DIR: /tmp/wikitool-trace
steps:
- name: System dependencies
run: |
set -eu
apt-get update -qq
apt-get install -y --no-install-recommends \
python3 python3-venv git nodejs ripgrep ca-certificates
rm -rf /var/lib/apt/lists/*
- uses: actions/checkout@v7
- name: Tool environment
# More than `ci.yml`'s equivalent, because this job runs `doctor` and
# `ci.yml` does not. `doctor` asks whether a *working instance* is
# correctly configured, and a bare checkout is not one yet - it is the
# fresh clone instructions/bootstrap.md describes. Two of its checks
# answered for the container instead of for the repository on the first
# run (#9): `git-identity` found no `user.name`, and `skills` found
# nothing published, because `.agents/skills/` and `.claude/skills/`
# are generated and deliberately not committed. So the bootstrap runs
# first, and `doctor` then reports on an instance rather than on a
# tarball. `instructions verify` needs the same, for the same reason.
run: |
set -eu
git config --global --add safe.directory "$GITHUB_WORKSPACE"
git config --global user.name "Nightly"
git config --global user.email "nightly@example.invalid"
tools/preflight.sh
tools/wikitool instructions sync
- name: The instance is still correctly configured
run: tools/wikitool doctor
- name: The stack still describes itself
run: |
set -eu
tools/wikitool docs verify
tools/wikitool instructions verify
- name: The corpus is still structurally sound
# The one check push-driven CI no longer performs on a content commit.
run: tools/wikitool lint --fail-on-error
- name: Every raw file is still claimed, and the content shape declared
run: |
set -eu
tools/wikitool sources coverage
tools/wikitool migrate status