diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7043af25..fcc53c17 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -37,7 +37,6 @@ jobs: nix profile install --inputs-from . attic#attic-client attic login rc https://cache.zx.dev ${{ secrets.ATTIC_TOKEN }} attic use rc:main - - run: nix flake check - name: Build system configuration run: | if [ "${{ matrix.system }}" = "aarch64-darwin" ]; then diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml new file mode 100644 index 00000000..6f12d88b --- /dev/null +++ b/.github/workflows/deploy.yml @@ -0,0 +1,68 @@ +name: Deploy + +on: + workflow_run: + workflows: ["CI"] + types: [completed] + branches: [main] + workflow_dispatch: + +jobs: + deploy: + if: >- + github.event_name == 'workflow_dispatch' || + github.event.workflow_run.conclusion == 'success' + strategy: + max-parallel: 1 + matrix: + include: + - host: glyph + system: x86_64-linux + runner: ubuntu-latest + - host: spore + system: x86_64-linux + runner: ubuntu-latest + - host: zeta + system: aarch64-linux + runner: ubuntu-24.04-arm + runs-on: ${{ matrix.runner }} + steps: + - uses: actions/checkout@v4 + + - uses: cachix/install-nix-action@v31 + with: + github_access_token: ${{ secrets.GITHUB_TOKEN }} + extra_nix_config: | + extra-substituters = https://cache.zx.dev/main + extra-trusted-public-keys = main:mu0jkxdJTGWC3djDSEQb3rvZgqlhA8WVMulcTo5IW6c= + + - name: Configure Attic cache + run: | + nix profile install --inputs-from . attic#attic-client + attic login rc https://cache.zx.dev ${{ secrets.ATTIC_TOKEN }} + attic use rc:main + + - name: Connect to Tailscale + uses: tailscale/github-action@v3 + with: + oauth-client-id: ${{ secrets.TS_OAUTH_CLIENT_ID }} + oauth-secret: ${{ secrets.TS_OAUTH_SECRET }} + tags: tag:ci + + - name: Configure SSH + run: | + mkdir -p ~/.ssh + echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key + chmod 600 ~/.ssh/deploy_key + cat >> ~/.ssh/config <