feat(ci): reusable ecosystem workflows + selftest (999_testing)
All checks were successful
CI / preflight (push) Successful in 7s
CI / typecheck (push) Successful in 17s
ecosystem-selftest / semantic-release-bumptest (push) Successful in 12s
pulumi-preview / preview (push) Successful in 20s
ecosystem-selftest / eslint-gate (push) Successful in 5s
ecosystem-selftest / yamllint-gate (push) Successful in 4s

The ecosystem-CI architecture: reusable Forgejo workflows (on: workflow_call)
that downstream repos reference as
`uses: olsitec/foundation/.forgejo/workflows/<x>.yml@master`.

- reusable-node-build.yml: install + build for npm/bun/none — covers the npm
  package (olsicrypto), bun package (document-engine), and no-artifact versioned
  (olsitrack/api) shapes.
- reusable-docker-build.yml: docker build via the host socket (R5: trusted repos
  only until the runner is fenced) — the seaspots-homepage / token-service shape.
- reusable-lint.yml: eslint + yamllint gate (either error → job non-zero).
- reusable-semantic-release.yml: conventionalcommits-preset version probe (dry-run),
  faithful to the GitLab template; outputs the computed next version. Real Forgejo
  publishing deferred (no @semantic-release/forgejo analogue yet).

- ecosystem-selftest.yml + ci/semantic-release-bumptest.sh: self-contained proof
  on the runner of the 999_testing acceptance criteria that need no external repo —
  the semantic-release bump sequence (1.0.0→1.1.0→1.1.1→2.0.0→3.0.0) and the
  eslint/yamllint non-zero-exit gates. Validated in a foundation-ci container.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Andreas Niemann 2026-07-01 01:03:56 +02:00
parent f5f9d1f8a5
commit f9aecf1b18
6 changed files with 450 additions and 0 deletions

View file

@ -0,0 +1,81 @@
# reusable-semantic-release — compute the next semver from conventional commits
# (999_testing "semantic-release testing"). Mirrors the canonical GitLab template
# (olsitec/gitlab ci_templates/release-automation/semantic-release.yaml): the
# conventionalcommits preset + Olsitec's releaseRules, run as a `--dry-run --no-ci
# --tag-format '${version}'` version probe. Exposes the computed version as an output.
#
# jobs:
# version:
# uses: olsitec/foundation/.forgejo/workflows/reusable-semantic-release.yml@master
# build:
# needs: version
# runs-on: docker
# steps: [ run: echo "releasing ${{ needs.version.outputs.version }}" ]
#
# NOTE: dry-run only — it computes/prints the next version (the part exercised by
# 999_testing and the GitLab `generate-release-version` job). Actually PUBLISHING a
# release to Forgejo (tag + release + changelog) needs a Forgejo-side publish step
# and a token; that is deferred until the package/release flow is wired (the GitLab
# template publishes via @semantic-release/gitlab, which has no Forgejo analogue yet).
name: reusable-semantic-release
on:
workflow_call:
inputs:
branch:
type: string
default: master
outputs:
version:
description: "next release version (empty if the commits warrant no release)"
value: ${{ jobs.version.outputs.version }}
jobs:
version:
runs-on: docker
container:
image: foundation-ci:latest
outputs:
version: ${{ steps.compute.outputs.version }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # semantic-release needs full history + tags
- name: Write .releaserc.yaml (Olsitec conventionalcommits ruleset)
run: |
cat > .releaserc.yaml <<'EOF'
branches:
- name: ${{ inputs.branch }}
tagFormat: "${version}"
plugins:
- - "@semantic-release/commit-analyzer"
- preset: conventionalcommits
releaseRules:
- { breaking: true, release: major }
- { type: breaking, release: major }
- { type: feature, release: minor }
- { type: feat, release: minor }
- { type: fix, release: patch }
- { type: build, release: patch }
- { type: chore, release: patch }
- { type: ci, release: patch }
- { type: docs, release: patch }
- { type: perf, release: patch }
- { type: refactor, release: patch }
- { type: style, release: patch }
- { type: test, release: patch }
parserOpts:
noteKeywords: [ "BREAKING CHANGE", "BREAKING CHANGES" ]
- "@semantic-release/release-notes-generator"
EOF
- name: Compute next version (dry-run)
id: compute
run: |
out=$(semantic-release --dry-run --no-ci --tag-format '${version}' --branches "${{ inputs.branch }}" 2>&1 || true)
printf '%s\n' "$out"
ver=$(printf '%s\n' "$out" \
| grep -oiE 'next release version is [0-9]+\.[0-9]+\.[0-9]+' \
| grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | tail -1)
echo "computed next version: ${ver:-<none>}"
echo "version=$ver" >> "$GITHUB_OUTPUT"