ci: no toolchain installs on the bare aarch64 (klokka) runner; builtin:checkout

The aarch64 release leg runs on the klokka host. Gate the sccache /
cargo-binstall / cargo-leptos installs to the ephemeral x86_64 container; on
the bare runner check-and-fail instead (the sccache tarball was x86_64-only
anyway, so it was both a host mutation and a wrong-arch binary). Switch
checkout to v4 builtin:checkout (native Go, no Node/download) in all jobs.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Bendik Aagaard Lynghaug
2026-09-28 12:37:04 +02:00
co-authored by Claude Opus 4.8
parent 9de5d7e2d9
commit c1c337c2a2
+25 -12
View File
@@ -23,7 +23,7 @@ jobs:
runs-on: ${{ matrix.runs-on }} runs-on: ${{ matrix.runs-on }}
steps: steps:
- uses: actions/checkout@v4 - uses: builtin:checkout
- name: Install Rust stable - name: Install Rust stable
uses: dtolnay/rust-toolchain@stable uses: dtolnay/rust-toolchain@stable
@@ -39,22 +39,35 @@ jobs:
echo "RUSTC_WRAPPER=sccache" >> "$GITHUB_ENV" echo "RUSTC_WRAPPER=sccache" >> "$GITHUB_ENV"
echo "SCCACHE_DIR=${{ matrix.sccache_dir }}" >> "$GITHUB_ENV" echo "SCCACHE_DIR=${{ matrix.sccache_dir }}" >> "$GITHUB_ENV"
mkdir -p "${{ matrix.sccache_dir }}" mkdir -p "${{ matrix.sccache_dir }}"
if ! command -v sccache >/dev/null 2>&1; then if command -v sccache >/dev/null 2>&1; then sccache --version; exit 0; fi
V=0.8.2 # Bare runners (aarch64 = klokka host) are pre-provisioned; CI must not
curl -sSL "https://github.com/mozilla/sccache/releases/download/v${V}/sccache-v${V}-x86_64-unknown-linux-musl.tar.gz" | tar -xz # install onto them (and this tarball is x86_64-only). Only the
sudo install -m0755 "sccache-v${V}-x86_64-unknown-linux-musl/sccache" /usr/local/bin/sccache # ephemeral x86_64 container installs; a bare host missing it fails loud.
if [ "${{ matrix.arch }}" != x86_64 ]; then
echo "::error::sccache missing on the bare ${{ matrix.arch }} runner — provision klokka; CI must not install on bare hosts"; exit 1
fi fi
V=0.8.2
curl -sSL "https://github.com/mozilla/sccache/releases/download/v${V}/sccache-v${V}-x86_64-unknown-linux-musl.tar.gz" | tar -xz
sudo install -m0755 "sccache-v${V}-x86_64-unknown-linux-musl/sccache" /usr/local/bin/sccache
sccache --version sccache --version
- name: Install cargo-binstall - name: Install cargo-binstall
run: | run: |
command -v cargo-binstall || \ if command -v cargo-binstall >/dev/null 2>&1; then exit 0; fi
curl -L --proto '=https' --tlsv1.2 -sSf \ if [ "${{ matrix.arch }}" != x86_64 ]; then
https://raw.githubusercontent.com/cargo-bins/cargo-binstall/main/install-from-binstall-release.sh \ echo "::error::cargo-binstall missing on the bare ${{ matrix.arch }} runner — provision klokka"; exit 1
| bash fi
curl -L --proto '=https' --tlsv1.2 -sSf \
https://raw.githubusercontent.com/cargo-bins/cargo-binstall/main/install-from-binstall-release.sh \
| bash
- name: Install cargo-leptos - name: Install cargo-leptos
run: command -v cargo-leptos || cargo binstall cargo-leptos --locked --no-confirm run: |
if command -v cargo-leptos >/dev/null 2>&1; then exit 0; fi
if [ "${{ matrix.arch }}" != x86_64 ]; then
echo "::error::cargo-leptos missing on the bare ${{ matrix.arch }} runner — provision klokka"; exit 1
fi
cargo binstall cargo-leptos --locked --no-confirm
- name: Build - name: Build
run: cargo leptos build --release run: cargo leptos build --release
@@ -111,7 +124,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: builtin:checkout
- name: Log in to Docker Hub - name: Log in to Docker Hub
run: echo "${{ secrets.DOCKERHUB_TOKEN }}" | docker login -u bendik --password-stdin run: echo "${{ secrets.DOCKERHUB_TOKEN }}" | docker login -u bendik --password-stdin
@@ -128,7 +141,7 @@ jobs:
runs-on: aarch64 runs-on: aarch64
steps: steps:
- uses: actions/checkout@v4 - uses: builtin:checkout
- name: Compute checksums and update PKGBUILD - name: Compute checksums and update PKGBUILD
run: | run: |