iris: the lint over a portal site, as its own repo
Test / test (push) Failing after 12s
Publish release / publish (push) Failing after 4s

question_lint becomes `iris check`, needs_replay becomes `iris
replay`, and the needs module and local-checkout loaders come with
them. Portal is a library dependency pinned to the release iris
matches (v0.3.36), so every type iris reads is the site's own and the
two never disagree about what a page is. `iris --path questions`
still works, so a content repo's one-line CI needs only a new path.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L4jrCgLiKKHAEFuZUJjckH
This commit is contained in:
Bendik Aagaard Lynghaug
2026-09-22 17:25:52 +02:00
co-authored by Claude Fable 5.1
commit 73906cdf35
12 changed files with 6927 additions and 0 deletions
+44
View File
@@ -0,0 +1,44 @@
name: Publish release
# A `v*` tag builds the binary and attaches it to the Gitea release as
# `iris`, with the tag's CHANGELOG.md section as the notes. Content
# repos pin IRIS_RELEASE to one of these tags in their lint workflow.
on:
push:
tags: ["v*"]
jobs:
publish:
runs-on: bare
env:
CARGO_HOME: /var/local/cargo
RUSTUP_HOME: /var/local/rustup
PATH: /var/local/cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/bin
SCCACHE_DIR: /var/local/sccache
SCCACHE_SERVER_PORT: "4228"
CARGO_TARGET_DIR: /var/local/cargo-target
steps:
- uses: actions/checkout@v4
- name: Build
run: cargo build --release
- name: Publish release
run: |
set -euo pipefail
tag="${{ github.ref_name }}"
api="${{ github.server_url }}/api/v1/repos/${{ github.repository }}"
auth="Authorization: token ${{ secrets.GITHUB_TOKEN }}"
notes=$(awk -v v="${tag#v}" '/^## /{p = ($2 == v)} p' CHANGELOG.md | tail -n +2)
body=$(jq -n --arg tag "$tag" --arg notes "$notes" '{tag_name: $tag, name: $tag, body: $notes}')
id=$(curl -sf -X POST -H "$auth" -H 'Content-Type: application/json' \
-d "$body" "$api/releases" | jq .id) \
|| id=$(curl -sf -H "$auth" "$api/releases/tags/$tag" | jq .id)
for aid in $(curl -sf -H "$auth" "$api/releases/$id/assets" | jq '.[].id'); do
curl -sf -X DELETE -H "$auth" "$api/releases/$id/assets/$aid"
done
curl -sf -X POST -H "$auth" \
-F "attachment=@/var/local/cargo-target/release/iris" \
"$api/releases/$id/assets?name=iris" > /dev/null
echo "published $tag"
+32
View File
@@ -0,0 +1,32 @@
name: Test
on:
push:
branches: [main]
pull_request:
jobs:
test:
runs-on: bare
env:
# Same shared toolchain and cache as uhhm/portal's workflows.
CARGO_HOME: /var/local/cargo
RUSTUP_HOME: /var/local/rustup
PATH: /var/local/cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/bin
SCCACHE_DIR: /var/local/sccache
SCCACHE_SERVER_PORT: "4228"
CARGO_TARGET_DIR: /var/local/cargo-target
steps:
- uses: actions/checkout@v4
- name: Test
run: cargo test
# The one thing a lint must never do is reject the content it
# is meant to serve: every live content repo has to pass.
- name: Check the live content repos
run: |
cargo build --release
for repo in uhhm/questions redoal/questions; do
/var/local/cargo-target/release/iris check --repo "${{ github.server_url }}/$repo"
done