diff --git a/.tangled/workflows/packages.yml b/.tangled/workflows/packages.yml index ca3553d..1ee4679 100644 --- a/.tangled/workflows/packages.yml +++ b/.tangled/workflows/packages.yml @@ -1,9 +1,13 @@ -# Substitute .#android + .#flatpak from binary cache only (hosted Spindle cannot compile). -# Warm cache locally: +# Build .#android + .#flatpak on Spindle itself — prefer the codegod100 +# Cachix cache when it has a hit, but (unlike the previous cache-only/ +# max-jobs=0 setup) fall back to actually compiling in-pipeline on a miss. +# Prior debugging concluded hosted Spindle "can't compile" but never +# confirmed that against the current image/resources — this build is the +# real test of that assumption. Warm the cache locally to skip compiling: # just android # just flatpak && cachix push codegod100 ./result-flatpak # -# On push/manual to main (not PRs), after a successful substitute: +# On push/manual to main (not PRs), after a successful build: # 1. Force-move annotated tag `dev` to this commit # 2. Push the tag (needs DEPLOY_KEY — write deploy key) # 3. Republish Tangled assets onto that tag (needs ATP_APP_PASSWORD) @@ -36,33 +40,25 @@ environment: DEV_TAG: "dev" steps: - - name: "Substitute APK from cache" + - name: "Build APK (cache first, else compile)" command: | set -euo pipefail - export NIX_CONFIG=$'experimental-features = nix-command flakes\naccept-flake-config = true\nmax-jobs = 0\nextra-substituters = https://codegod100.cachix.org\nextra-trusted-public-keys = codegod100.cachix.org-1:LZFL5VrR644WUjleS3bLbVeOdzlXqzKznQWvD5MVthA=' + export NIX_CONFIG=$'experimental-features = nix-command flakes\naccept-flake-config = true\nextra-substituters = https://codegod100.cachix.org\nextra-trusted-public-keys = codegod100.cachix.org-1:LZFL5VrR644WUjleS3bLbVeOdzlXqzKznQWvD5MVthA=' echo "kind=${TANGLED_PIPELINE_KIND:-?} sha=${TANGLED_SHA:-?}" nix --version - if ! nix build .#android --out-link result-android \ + nix build .#android --out-link result-android -L --print-build-logs \ --substituters 'https://codegod100.cachix.org https://cache.nixos.org' \ - --trusted-public-keys 'codegod100.cachix.org-1:LZFL5VrR644WUjleS3bLbVeOdzlXqzKznQWvD5MVthA= cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY='; then - echo "error: .#android not in cache. On a machine with Cachix write access:" >&2 - echo " just android" >&2 - exit 1 - fi + --trusted-public-keys 'codegod100.cachix.org-1:LZFL5VrR644WUjleS3bLbVeOdzlXqzKznQWvD5MVthA= cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=' test -s result-android/sleek.apk ls -lah result-android/ - - name: "Substitute Flatpak from cache" + - name: "Build Flatpak (cache first, else compile)" command: | set -euo pipefail - export NIX_CONFIG=$'experimental-features = nix-command flakes\naccept-flake-config = true\nmax-jobs = 0\nextra-substituters = https://codegod100.cachix.org\nextra-trusted-public-keys = codegod100.cachix.org-1:LZFL5VrR644WUjleS3bLbVeOdzlXqzKznQWvD5MVthA=' - if ! nix build .#flatpak --out-link result-flatpak \ + export NIX_CONFIG=$'experimental-features = nix-command flakes\naccept-flake-config = true\nextra-substituters = https://codegod100.cachix.org\nextra-trusted-public-keys = codegod100.cachix.org-1:LZFL5VrR644WUjleS3bLbVeOdzlXqzKznQWvD5MVthA=' + nix build .#flatpak --out-link result-flatpak -L --print-build-logs \ --substituters 'https://codegod100.cachix.org https://cache.nixos.org' \ - --trusted-public-keys 'codegod100.cachix.org-1:LZFL5VrR644WUjleS3bLbVeOdzlXqzKznQWvD5MVthA= cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY='; then - echo "error: .#flatpak not in cache. On a machine with Cachix write access:" >&2 - echo " just flatpak && cachix push codegod100 ./result-flatpak" >&2 - exit 1 - fi + --trusted-public-keys 'codegod100.cachix.org-1:LZFL5VrR644WUjleS3bLbVeOdzlXqzKznQWvD5MVthA= cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=' test -s result-flatpak/uk.nandi.sleek.flatpak ls -lah result-flatpak/ cat result-flatpak/build-info.json diff --git a/README.md b/README.md index aa36541..919d9ac 100644 --- a/README.md +++ b/README.md @@ -119,7 +119,7 @@ CI APKs are signed with the committed `android/ci.keystore` (password `android`, ### Spindle (Tangled CI) -[`.tangled/workflows/packages.yml`](.tangled/workflows/packages.yml) substitutes `.#android` and `.#flatpak` from the `codegod100` Cachix cache on pushes/PRs to `main` (and manual runs) — hosted Spindle can't compile these itself, so warm the cache first from a machine that can (`just android`, `just flatpak && cachix push codegod100 ./result-flatpak`). On `main` pushes it force-moves annotated tag `dev` and republishes Tangled assets (`sleek.apk`, `uk.nandi.sleek.flatpak`) onto that tag. +[`.tangled/workflows/packages.yml`](.tangled/workflows/packages.yml) builds `.#android` and `.#flatpak` on pushes/PRs to `main` (and manual runs), preferring a hit in the `codegod100` Cachix cache but compiling in-pipeline on a miss (`just android` / `just flatpak && cachix push codegod100 ./result-flatpak` locally still saves Spindle the work). On `main` pushes it force-moves annotated tag `dev` and republishes Tangled assets (`sleek.apk`, `uk.nandi.sleek.flatpak`) onto that tag. | Secret | Purpose | |--------|---------|