lint: fix pre-existing failures so the self-test pipeline passes
continuous-integration/drone/push Build is passing
continuous-integration/drone/push Build is passing
Push build #33 (this branch) failed at the lint gate on failures inherited from main, which block this PR from merging: - runner/harness/warm.py: ruff format (long regex line — no code change) - nix/modules/acme-dns.nix: statix W201 'avoid repeated keys' — fold the three service definitions (acme-dns, cc-ci-acme-storage-seed, cc-ci-acme-traefik-handoff) into one services = { ... } attrset. Pure restructure: systemd.services eval of all three units is byte-identical to main (nix eval --json diff, all three IDENTICAL). scripts/lint.sh now: PASS.
This commit is contained in:
@@ -111,7 +111,10 @@ in
|
||||
"f /var/lib/ci-certs/acme-production-enabled 0600 root root -"
|
||||
];
|
||||
|
||||
services.acme-dns = {
|
||||
# Three systemd units (W201 statix): one attrset, distinct unit names — avoids
|
||||
# `services = { ... }` attribute sets repeating the `services` key.
|
||||
services = {
|
||||
acme-dns = {
|
||||
description = "Restricted authoritative DNS for cc-ci ACME DNS-01";
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
after = [ "network-online.target" ];
|
||||
@@ -139,7 +142,7 @@ in
|
||||
|
||||
# Seed the new cert's acmedns storage before the ACME unit first runs (see
|
||||
# acmeStorageSeed above). Ordering via the generated acme unit name.
|
||||
services.cc-ci-acme-storage-seed = {
|
||||
cc-ci-acme-storage-seed = {
|
||||
description = "Seed ci.autonomic.zone acme-dns storage from the legacy account";
|
||||
after = [ "acme-dns.service" ];
|
||||
wantedBy = [ "acme-ci.autonomic.zone.service" ];
|
||||
@@ -154,7 +157,10 @@ in
|
||||
# Traefik consumes its wildcard as immutable Swarm secrets, so a renewed
|
||||
# host certificate must be copied and reconciled rather than merely reloaded.
|
||||
# This service is started only by the production-mode ACME postRun hook.
|
||||
services.cc-ci-acme-traefik-handoff = {
|
||||
# Traefik consumes its wildcard as immutable Swarm secrets, so a renewed
|
||||
# host certificate must be copied and reconciled rather than merely reloaded.
|
||||
# This service is started only by the production-mode ACME postRun hook.
|
||||
cc-ci-acme-traefik-handoff = {
|
||||
description = "Install renewed cc-ci wildcard into Traefik Swarm secrets";
|
||||
after = [ "docker.service" "deploy-proxy.service" ];
|
||||
requires = [ "docker.service" ];
|
||||
@@ -189,6 +195,7 @@ in
|
||||
'';
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
security.acme = {
|
||||
acceptTerms = true;
|
||||
|
||||
@@ -41,7 +41,9 @@ _CTX.check_hostname = False
|
||||
_CTX.verify_mode = ssl.CERT_NONE
|
||||
|
||||
# A cold per-run stack name looks like "<tag>-<6hex>_ci_commoninternet_net_<svc>"; extract the hex.
|
||||
_STACK_HEX_RE = re.compile(r"^[a-z0-9]{1,4}-([0-9a-f]{6})_ci_(?:autonomic_zone|commoninternet_net)_")
|
||||
_STACK_HEX_RE = re.compile(
|
||||
r"^[a-z0-9]{1,4}-([0-9a-f]{6})_ci_(?:autonomic_zone|commoninternet_net)_"
|
||||
)
|
||||
|
||||
|
||||
def stable_domain(recipe: str) -> str:
|
||||
|
||||
Reference in New Issue
Block a user