diff --git a/.tangled/workflows/deploy-microvm.yml b/.tangled/workflows/deploy-microvm.yml index 4e7c960..559daa9 100644 --- a/.tangled/workflows/deploy-microvm.yml +++ b/.tangled/workflows/deploy-microvm.yml @@ -45,13 +45,17 @@ steps: nproc test -e /dev/kvm && echo "kvm: present" || echo "kvm: absent" - # Finished runs keep no logs, so a silent toolchain drift is expensive to - # diagnose after the fact; fail loudly and early instead. + # A moved pin surfaces as an unexplained formatting diff three steps later; + # name the real cause here instead. - name: assert toolchain matches the pin command: | gleam --version test "$(gleam --version)" = "gleam 1.18.0" || { echo "gleam is not 1.18.0: the nixpkgs pin moved, so formatting may disagree; repin or reformat" >&2; exit 1; } + - name: warm hex deps (retried) + command: | + ./scripts/ci-warm-deps.sh + # Tests gate the push below: if any of these fail, the pipeline stops # here and no image is ever built or pushed, so a red build can never # reach ghcr.io/latest and the droplet never rolls onto it. diff --git a/.tangled/workflows/test-postgres.yml b/.tangled/workflows/test-postgres.yml index fd23987..d4acaf6 100644 --- a/.tangled/workflows/test-postgres.yml +++ b/.tangled/workflows/test-postgres.yml @@ -64,6 +64,10 @@ services: host all at_record_test 127.0.0.1/32 trust steps: + - name: warm hex deps (retried) + command: | + ./scripts/ci-warm-deps.sh + - name: postgres-gated tests command: | make test diff --git a/.tangled/workflows/test.yml b/.tangled/workflows/test.yml index 63a2f96..51340fc 100644 --- a/.tangled/workflows/test.yml +++ b/.tangled/workflows/test.yml @@ -26,13 +26,17 @@ dependencies: - git steps: - # Finished runs keep no logs, so a silent toolchain drift is expensive to - # diagnose after the fact; fail loudly and early instead. + # A moved pin surfaces as an unexplained formatting diff three steps later; + # name the real cause here instead. - name: assert toolchain matches the pin command: | gleam --version test "$(gleam --version)" = "gleam 1.18.0" || { echo "gleam is not 1.18.0: the nixpkgs pin moved, so formatting may disagree; repin or reformat" >&2; exit 1; } + - name: warm hex deps (retried) + command: | + ./scripts/ci-warm-deps.sh + - name: generate codecs + check formatting command: | make gen diff --git a/scripts/ci-warm-deps.sh b/scripts/ci-warm-deps.sh new file mode 100755 index 0000000..c4acb9d --- /dev/null +++ b/scripts/ci-warm-deps.sh @@ -0,0 +1,33 @@ +#!/usr/bin/env bash +# A cold checkout resolves shared, server, and web against hex.pm in one CI +# run from a shared runner IP; one transient hex request should not kill a +# run that is otherwise green, so retry each project's download before the +# real build/test steps ever touch it. +set -euo pipefail +cd "$(dirname "${BASH_SOURCE[0]}")/.." + +log() { printf '\033[36m[ci-warm-deps]\033[0m %s\n' "$*"; } + +DELAYS=(5 15) + +warm() { + local dir="$1" attempt=1 + while true; do + if (cd "$dir" && gleam deps download); then + return 0 + fi + if [ "$attempt" -gt "${#DELAYS[@]}" ]; then + echo "ci-warm-deps: $dir failed to resolve deps after $((attempt)) attempts" >&2 + return 1 + fi + local delay="${DELAYS[$((attempt - 1))]}" + log "$dir: attempt $attempt failed, retrying in ${delay}s" + sleep "$delay" + attempt=$((attempt + 1)) + done +} + +for dir in shared server web; do + log "warming $dir" + warm "$dir" +done