forgejo-mcp/.forgejo/workflows/track-downloads.yml

75 lines
3.5 KiB
YAML

# Daily snapshot of release-asset download counts into docs/downloads/downloads.jsonl.
#
# NOTE: this is the ONLY Forgejo Actions workflow in the repo — CI/CD otherwise runs
# on Tekton (op1st cluster). It exists here because a tiny scheduled curl+commit is
# not worth a cluster CronJob. Requires:
# - Forgejo Actions enabled for the repo (Settings → Actions).
# - A repo/org secret DOWNLOAD_TRACKER_TOKEN: a token with write access used to
# push the daily commit back to the default branch.
#
# Runs on the ubuntu-latest runner. To stay portable we don't assume jq is present
# and avoid JS actions — the job installs any missing tool, then clones the repo
# manually with plain git (the token in the clone URL also authenticates the push).
name: track-downloads
on:
schedule:
- cron: "17 6 * * *" # 06:17 UTC daily (off the hour to dodge runner contention)
workflow_dispatch: {}
jobs:
snapshot:
runs-on: ubuntu-latest
steps:
- name: Snapshot + commit
# POSIX sh, not bash: the runner's pod image is not guaranteed to ship bash,
# and Forgejo's default `run:` shell (bash -e) fails to start if it's absent.
shell: sh
env:
TRACKER_TOKEN: ${{ secrets.DOWNLOAD_TRACKER_TOKEN }}
run: |
set -eu
# OpenShift runs the pod as an arbitrary UID with HOME=/ (read-only), so
# git's global config and tool caches have nowhere writable. Respect XDG:
# point HOME + XDG base dirs at a fresh writable directory.
XDG_BASE="$(mktemp -d)"
export HOME="$XDG_BASE"
export XDG_CONFIG_HOME="$XDG_BASE/.config"
export XDG_CACHE_HOME="$XDG_BASE/.cache"
mkdir -p "$XDG_CONFIG_HOME" "$XDG_CACHE_HOME"
# --- ensure curl, jq, git (distro-agnostic; pod image may be UBI/Debian/Alpine) ---
need=""
for t in curl jq git; do command -v "$t" >/dev/null 2>&1 || need="$need $t"; done
if [ -n "$need" ]; then
echo "Installing:$need"
if command -v microdnf >/dev/null 2>&1; then microdnf install -y $need
elif command -v dnf >/dev/null 2>&1; then dnf install -y $need
elif command -v yum >/dev/null 2>&1; then yum install -y $need
elif command -v apt-get >/dev/null 2>&1; then apt-get update -qq && apt-get install -y -qq --no-install-recommends $need ca-certificates
elif command -v apk >/dev/null 2>&1; then apk add --no-cache $need
else echo "No known package manager to install:$need" >&2; exit 1
fi
fi
# --- clone (shallow) using the token so the later push is authenticated ---
REPO_URL="https://${TRACKER_TOKEN}@codeberg.org/goern/forgejo-mcp.git"
git clone --depth 1 "$REPO_URL" work
cd work
# Local (repo) identity — clone and git run as the same UID, so no
# global safe.directory needed and nothing writes outside the workspace.
git config user.name "op1st-gitops"
git config user.email "op1st-gitops@noreply.codeberg.org"
# --- snapshot today's download counts ---
./hack/snapshot-downloads.sh
# --- commit + push only if the counts moved ---
if git diff --quiet -- docs/downloads/downloads.jsonl; then
echo "No change in download counts today — nothing to commit."
exit 0
fi
git add docs/downloads/downloads.jsonl
git commit -m "chore: 📊 snapshot release download counts"
git push origin HEAD:main