CI and the daily publish run #2

Manually merged
SkyfaR merged 1 commit from ci into night-2 2026-10-07 07:17:02 +02:00
Owner

Builds on #1 (base night-2; retarget to main once #1 is merged).

  • ci.yml: fmt, clippy -D warnings, workspace tests, a dry run of the pipeline on every PR and push.
  • publish.yml: daily and on dispatch on main: catalog → aggregator (raw data from ogc-db-raw when a read token exists, else curated only) → aggregator with names → site → gates (stops for approval when the anomaly gate trips) → minisign signature → commit public/ and cache/ with a bot token. Once a signed latest.json is on main, unsigned publishing is refused. report.md goes out encrypted to the owner as an artifact, never into the repo.
  • README: the secrets and variables to set (OGC_SALT_SECRET, OGC_DB_PUSH_TOKEN, MINISIGN_SECRET_KEY + MINISIGN_PASSWORD, OGC_DB_RAW_TOKEN; variables MINISIGN_PUBLIC_KEY, OGC_REPORT_RECIPIENTS).

Simulated locally in rust:1-trixie containers; not yet run on the real Forgejo (skip-ci handling, dispatch input, git over HTTP with a token header).

Builds on #1 (base night-2; retarget to main once #1 is merged). - `ci.yml`: fmt, clippy -D warnings, workspace tests, a dry run of the pipeline on every PR and push. - `publish.yml`: daily and on dispatch on main: catalog → aggregator (raw data from ogc-db-raw when a read token exists, else curated only) → aggregator with names → site → gates (stops for approval when the anomaly gate trips) → minisign signature → commit `public/` and `cache/` with a bot token. Once a signed `latest.json` is on main, unsigned publishing is refused. `report.md` goes out encrypted to the owner as an artifact, never into the repo. - README: the secrets and variables to set (OGC_SALT_SECRET, OGC_DB_PUSH_TOKEN, MINISIGN_SECRET_KEY + MINISIGN_PASSWORD, OGC_DB_RAW_TOKEN; variables MINISIGN_PUBLIC_KEY, OGC_REPORT_RECIPIENTS). Simulated locally in rust:1-trixie containers; not yet run on the real Forgejo (skip-ci handling, dispatch input, git over HTTP with a token header).
CI and the daily publish run
All checks were successful
CI / Format, lint, test and check the data (pull_request) Successful in 2m13s
1a8d9faf49
ci.yml formats, lints and tests the workspace on every pull request and
push. publish.yml runs daily on main: catalog, aggregator, site, gates,
minisign signature, and a commit of public/ and cache/; the private report
goes out encrypted as an artifact, never into the repository. README lists
the secrets and variables the run needs.
SkyfaR manually merged commit 7b484f38a5 into night-2 2026-10-07 07:17:02 +02:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
LevelXStudios/ogc-db!2
No description provided.