ci: GitLab pipeline (web build, rohana image push, desktop linux)
First CI for the lab GitLab (git.lab): web job builds the webapp with the lessons from the Gitea attempts baked in (frozen-lockfile instead of layered.sh, 6GB node heap), docker_web pushes the canonical apps/web/Dockerfile image to the rohana registry that Flux pulls from, and two manual jobs cover the desktop path - a dockerbuild build-image and the Electron Linux build replicating the manually verified flow. Also tracks the production client config (apps/desktop/axion1337/) that previously only existed inside the one-off manual desktop build. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
8d46fb33d2
commit
e21e101004
+101
@@ -0,0 +1,101 @@
|
||||
# GitLab-CI fuer den ThreadNet-Web-Fork (Lab-GitLab: git.lab).
|
||||
# Ersetzt die frueheren GitHub/Gitea-Actions-Workflows - Hintergrund: docs/axion1337-fork.md.
|
||||
#
|
||||
# Erkenntnisse aus den Gitea-CI-Versuchen (2026-07-30), hier eingeflossen:
|
||||
# - kein scripts/layered.sh: wuerde den gepinnten matrix-js-sdk-Stand aus pnpm-lock.yaml
|
||||
# mit Upstream-develop ueberschreiben (und braucht jq) -> frozen-lockfile-Install
|
||||
# - webpack braucht ~4 GB Heap -> NODE_OPTIONS
|
||||
# - Desktop-Build laeuft im dockerbuild-Image (rust:bullseye + node, glibc-2.31-Ziel)
|
||||
|
||||
stages:
|
||||
- build
|
||||
- package
|
||||
|
||||
web:
|
||||
stage: build
|
||||
image: node:24-bullseye
|
||||
variables:
|
||||
NODE_OPTIONS: "--max-old-space-size=6144"
|
||||
CI_PACKAGE: "true"
|
||||
before_script:
|
||||
- corepack enable
|
||||
script:
|
||||
- pnpm install --frozen-lockfile
|
||||
- cp apps/web/element.io/develop/config.json apps/web/config.json
|
||||
- VERSION=$(scripts/get-version-from-git.sh) pnpm --dir apps/web build
|
||||
artifacts:
|
||||
paths:
|
||||
- apps/web/webapp
|
||||
expire_in: 1 day
|
||||
|
||||
# Baut das kanonische Web-Image (apps/web/Dockerfile, Kontext = Monorepo-Root) und pusht
|
||||
# es in die rohana-Registry, aus der Flux/k8s zieht. Deploy bleibt ein manueller Tag-Bump
|
||||
# im gitops-Repo. Bewusster Doppel-Build (webpack laeuft im web-Job UND im Dockerfile) -
|
||||
# kanonisch/reproduzierbar vor schnell; Optimierung als Folgearbeit in Issue #2.
|
||||
docker_web:
|
||||
stage: package
|
||||
image: docker:27-cli
|
||||
needs:
|
||||
- job: web
|
||||
artifacts: false
|
||||
rules:
|
||||
- if: $CI_COMMIT_BRANCH == "main"
|
||||
variables:
|
||||
IMAGE: rohana.axion1337.de/sorb/threadnet-web
|
||||
DOCKER_BUILDKIT: "1"
|
||||
script:
|
||||
- echo "$REGISTRY_PASSWORD" | docker login rohana.axion1337.de -u "$REGISTRY_USER" --password-stdin
|
||||
- docker build -f apps/web/Dockerfile -t "$IMAGE:sha-$CI_COMMIT_SHORT_SHA" -t "$IMAGE:latest-ci" .
|
||||
- docker push "$IMAGE:sha-$CI_COMMIT_SHORT_SHA"
|
||||
- docker push "$IMAGE:latest-ci"
|
||||
|
||||
# Einmalig/selten: Build-Image fuer den Desktop-Build (rust:bullseye + node + tcl/sqlcipher,
|
||||
# aus apps/desktop/dockerbuild). Manuell ausloesen, wenn sich .node-version oder das
|
||||
# Dockerfile aendert.
|
||||
desktop_image:
|
||||
stage: package
|
||||
image: docker:27-cli
|
||||
rules:
|
||||
- if: $CI_COMMIT_BRANCH == "main"
|
||||
when: manual
|
||||
allow_failure: true
|
||||
variables:
|
||||
IMAGE: rohana.axion1337.de/sorb/element-desktop-build
|
||||
script:
|
||||
- echo "$REGISTRY_PASSWORD" | docker login rohana.axion1337.de -u "$REGISTRY_USER" --password-stdin
|
||||
- docker build -f apps/desktop/dockerbuild/Dockerfile -t "$IMAGE:bullseye" apps/desktop
|
||||
- docker push "$IMAGE:bullseye"
|
||||
|
||||
# Electron-Linux-Build (amd64, static sqlcipher) - repliziert den am 2026-07-29 manuell
|
||||
# verifizierten Build-Weg. Erst manuell, bis der Ablauf einmal gruen war.
|
||||
desktop_linux:
|
||||
stage: package
|
||||
image: rohana.axion1337.de/sorb/element-desktop-build:bullseye
|
||||
needs:
|
||||
- job: web
|
||||
artifacts: true
|
||||
rules:
|
||||
- if: $CI_COMMIT_BRANCH == "main"
|
||||
when: manual
|
||||
allow_failure: true
|
||||
variables:
|
||||
MAX_GLIBC: "2.31"
|
||||
USE_HARD_LINKS: "false"
|
||||
SQLCIPHER_BUNDLED: "1"
|
||||
script:
|
||||
- pnpm install --frozen-lockfile --filter element-desktop
|
||||
- cp -r apps/web/webapp apps/desktop/webapp
|
||||
# Produktions-Client-Config (getrackt seit diesem Commit, vorher nur im manuellen Build)
|
||||
- cp apps/desktop/axion1337/config.json apps/desktop/webapp/config.json
|
||||
- cd apps/desktop
|
||||
- pnpm run asar-webapp
|
||||
- pnpm run build:native
|
||||
# pnpm/npm setzen beim Install kein Executable-Bit auf 7za - bekannter Fix,
|
||||
# gleicher Schritt wie in der Upstream-CI ("Fix permissions")
|
||||
- chmod +x ../../node_modules/7zip-bin/linux/*/7za || true
|
||||
- pnpm run build --publish never -l tar.gz -l deb
|
||||
artifacts:
|
||||
paths:
|
||||
- apps/desktop/dist/*.deb
|
||||
- apps/desktop/dist/*.tar.gz
|
||||
expire_in: 1 week
|
||||
Reference in New Issue
Block a user