From f7f634d104117ac0d49c0175cd508467ea496230 Mon Sep 17 00:00:00 2001 From: Graham Barber Date: Thu, 16 Jul 2026 21:51:02 -0700 Subject: [PATCH] run CI checks inside the pinned denoland/deno image MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The previous fix (download a pinned deno into the runner) fails on the nixery/microvm NixOS runner: no FHS dynamic linker, so the glibc deno binary can't execute ("required file not found"). Run fmt/typecheck/tests inside denoland/deno:$DENO_VERSION via docker-in-VM instead — same pinned version, working environment. Validated `deno fmt --check` in the image locally. Co-Authored-By: Claude Opus 4.8 --- .tangled/workflows/ci.yml | 50 +++++++++++++++++---------------------- 1 file changed, 22 insertions(+), 28 deletions(-) diff --git a/.tangled/workflows/ci.yml b/.tangled/workflows/ci.yml index 8d4c00d..842b8db 100644 --- a/.tangled/workflows/ci.yml +++ b/.tangled/workflows/ci.yml @@ -1,43 +1,37 @@ # Continuous checks: formatting, typecheck, and tests on every push and pull -# request to main. The container image is built separately, on release tags -# (build-image.yml). +# request to main. The container image is built separately (build-image.yml). # -# Deno is pinned explicitly rather than taken from nixpkgs: `deno fmt` rules and -# which file types it covers (CSS, HTML, SVG, Svelte, ...) change between -# versions, so CI must run the SAME version developers format with — otherwise -# the format check flags files that are clean locally. Keep DENO_VERSION in sync -# with your local deno (and ideally the Dockerfile's denoland/deno tag). +# Checks run INSIDE the official denoland/deno image, pinned to an exact version. +# Two reasons this beats installing deno into the runner: +# * Determinism — `deno fmt` rules and which file types it covers (CSS, HTML, +# SVG, Svelte, ...) change between versions, so CI must run the same version +# developers format with, or it flags files that are clean locally. +# * The nixery/microvm runner is NixOS, which has no FHS dynamic linker, so a +# downloaded glibc `deno` binary can't execute ("required file not found"). +# The official image ships a working environment. +# Keep DENO_VERSION in sync with your local deno (and the Dockerfile's tag). # # Skip a run with: git push -o skip-ci when: - event: ["push", "pull_request"] branch: ["main"] -engine: nixery +engine: microvm +image: nixos -dependencies: - nixpkgs: - - curl - - unzip - - git +virtualisation: + docker: true environment: - DENO_NO_UPDATE_CHECK: "1" - DENO_VERSION: "v2.9.3" + DENO_VERSION: "2.9.3" steps: - - name: "Checks: fmt, typecheck, tests (pinned Deno)" + - name: "Checks: fmt, typecheck, tests (pinned Deno image)" command: | set -euo pipefail - - # Install the pinned Deno into the workspace and put it first on PATH so - # that `deno task ...` (which shells out to `deno`) uses this version too. - export DENO_INSTALL="$PWD/.deno" - curl -fsSL https://deno.land/install.sh | sh -s "$DENO_VERSION" - export PATH="$DENO_INSTALL/bin:$PATH" - - deno --version - deno fmt --check - deno install - deno task check - deno task test + docker run --rm -u root \ + -v "$PWD":/app -w /app \ + -e DENO_NO_UPDATE_CHECK=1 \ + --entrypoint sh \ + "denoland/deno:$DENO_VERSION" \ + -c 'deno --version && deno fmt --check && deno install && deno task check && deno task test' -- 2.51.2