lint: fix pre-existing failures so the self-test pipeline passes
continuous-integration/drone/push Build is passing

Push build #33 (this branch) failed at the lint gate on failures inherited from
main, which block this PR from merging:
- runner/harness/warm.py: ruff format (long regex line — no code change)
- nix/modules/acme-dns.nix: statix W201 'avoid repeated keys' — fold the three
  service definitions (acme-dns, cc-ci-acme-storage-seed,
  cc-ci-acme-traefik-handoff) into one services = { ... } attrset. Pure
  restructure: systemd.services eval of all three units is byte-identical to
  main (nix eval --json diff, all three IDENTICAL).

scripts/lint.sh now: PASS.
This commit is contained in:
2026-10-05 16:59:33 +00:00
parent 2a7cdcdee4
commit e83cd46806
2 changed files with 81 additions and 72 deletions
+10 -3
View File
@@ -111,7 +111,10 @@ in
"f /var/lib/ci-certs/acme-production-enabled 0600 root root -" "f /var/lib/ci-certs/acme-production-enabled 0600 root root -"
]; ];
services.acme-dns = { # Three systemd units (W201 statix): one attrset, distinct unit names — avoids
# `services = { ... }` attribute sets repeating the `services` key.
services = {
acme-dns = {
description = "Restricted authoritative DNS for cc-ci ACME DNS-01"; description = "Restricted authoritative DNS for cc-ci ACME DNS-01";
wantedBy = [ "multi-user.target" ]; wantedBy = [ "multi-user.target" ];
after = [ "network-online.target" ]; after = [ "network-online.target" ];
@@ -139,7 +142,7 @@ in
# Seed the new cert's acmedns storage before the ACME unit first runs (see # Seed the new cert's acmedns storage before the ACME unit first runs (see
# acmeStorageSeed above). Ordering via the generated acme unit name. # acmeStorageSeed above). Ordering via the generated acme unit name.
services.cc-ci-acme-storage-seed = { cc-ci-acme-storage-seed = {
description = "Seed ci.autonomic.zone acme-dns storage from the legacy account"; description = "Seed ci.autonomic.zone acme-dns storage from the legacy account";
after = [ "acme-dns.service" ]; after = [ "acme-dns.service" ];
wantedBy = [ "acme-ci.autonomic.zone.service" ]; wantedBy = [ "acme-ci.autonomic.zone.service" ];
@@ -154,7 +157,10 @@ in
# Traefik consumes its wildcard as immutable Swarm secrets, so a renewed # Traefik consumes its wildcard as immutable Swarm secrets, so a renewed
# host certificate must be copied and reconciled rather than merely reloaded. # host certificate must be copied and reconciled rather than merely reloaded.
# This service is started only by the production-mode ACME postRun hook. # This service is started only by the production-mode ACME postRun hook.
services.cc-ci-acme-traefik-handoff = { # Traefik consumes its wildcard as immutable Swarm secrets, so a renewed
# host certificate must be copied and reconciled rather than merely reloaded.
# This service is started only by the production-mode ACME postRun hook.
cc-ci-acme-traefik-handoff = {
description = "Install renewed cc-ci wildcard into Traefik Swarm secrets"; description = "Install renewed cc-ci wildcard into Traefik Swarm secrets";
after = [ "docker.service" "deploy-proxy.service" ]; after = [ "docker.service" "deploy-proxy.service" ];
requires = [ "docker.service" ]; requires = [ "docker.service" ];
@@ -189,6 +195,7 @@ in
''; '';
}; };
}; };
};
security.acme = { security.acme = {
acceptTerms = true; acceptTerms = true;
+3 -1
View File
@@ -41,7 +41,9 @@ _CTX.check_hostname = False
_CTX.verify_mode = ssl.CERT_NONE _CTX.verify_mode = ssl.CERT_NONE
# A cold per-run stack name looks like "<tag>-<6hex>_ci_commoninternet_net_<svc>"; extract the hex. # A cold per-run stack name looks like "<tag>-<6hex>_ci_commoninternet_net_<svc>"; extract the hex.
_STACK_HEX_RE = re.compile(r"^[a-z0-9]{1,4}-([0-9a-f]{6})_ci_(?:autonomic_zone|commoninternet_net)_") _STACK_HEX_RE = re.compile(
r"^[a-z0-9]{1,4}-([0-9a-f]{6})_ci_(?:autonomic_zone|commoninternet_net)_"
)
def stable_domain(recipe: str) -> str: def stable_domain(recipe: str) -> str: