ci: drop the external actions so the runner never needs github.com

Runs 11 and 14 died on 'dial tcp 20.205.243.166:443: i/o timeout' while act_runner cloned actions/checkout from GitHub. The workflow now fetches its own ref with git and relies on the node already present in the runner image, so it only touches this instance.
This commit is contained in:
pyh
2026-09-30 11:33:51 +08:00
parent 3a806f84ab
commit a3fbe602ff
+24 -14
View File
@@ -4,18 +4,22 @@
# 1. 推送版本标签(推荐):git tag -a v1.0.1 -m "..." && git push origin v1.0.1 # 1. 推送版本标签(推荐):git tag -a v1.0.1 -m "..." && git push origin v1.0.1
# 2. 仓库 → Actions → 选择本工作流 → Run workflow(手动,发布当前 ref 的版本) # 2. 仓库 → Actions → 选择本工作流 → Run workflow(手动,发布当前 ref 的版本)
# #
# 本工作流刻意不使用任何 `uses:` 外部 action:runner 在中国大陆访问 github.com 往往超时
# (表现为所有步骤 cancelled,日志里是 dial tcp ...:443: i/o timeout),而 checkout 只是
# git fetch、Node 本来就在 runner 镜像里。这样工作流只依赖本实例的 git 与镜像自带的 node。
#
# 已发布的版本不会让工作流失败:注册表返回 409(version already exists)时这一步记为 # 已发布的版本不会让工作流失败:注册表返回 409(version already exists)时这一步记为
# “已存在,本次跳过”,所以手动重跑同一个版本是安全的。 # “已存在,本次跳过”,所以手动重跑同一个版本是安全的。
# #
# 需要的权限: # 需要的权限:
# 默认使用 Gitea 内置的任务令牌 ${{ secrets.GITEA_TOKEN }} 发布。 # 默认使用 Gitea 内置的任务令牌 ${{ secrets.GITEA_TOKEN }} 发布。
# 若实例/组织把 Actions 的令牌上限设为只读,或任务令牌对包命名空间没有写权限, # 若实例/组织把 Actions 的令牌上限设为只读,或任务令牌对包命名空间没有写权限,
# 就配置一个带 write:package 权限的个人访问令牌: # 就配置一个带 write:package 权限的个人访问令牌(组织或仓库级 secret NPM_TOKEN),
# 仓库(或组织)Settings → Actions → Secrets → NPM_TOKEN。工作流会自动优先使用它。 # 工作流会自动优先使用它。
# #
# 依赖前提: # 依赖前提:
# - 实例启用了 Actions 并注册了 act_runner;runs-on 的标签要与 runner 一致。 # - 实例启用了 Actions 并注册了 act_runner;runs-on 的标签要与 runner 一致。
# - runner 需要能拉取 actions/checkout 与 actions/setup-node(默认从 github.com 取)。 # - runner 镜像里要有 node 与 npm(Gitea 官方 runner-images 自带)。
# - 包名、`cordis.patch.yml` 的 name、客户端模块 id 三处必须一致,改名时别漏。 # - 包名、`cordis.patch.yml` 的 name、客户端模块 id 三处必须一致,改名时别漏。
name: publish name: publish
@@ -25,7 +29,7 @@ on:
- 'v*' - 'v*'
workflow_dispatch: workflow_dispatch:
# 读取代码用于 checkout,向本组织写包。 # 读取代码用于检出,向本组织写包。
permissions: permissions:
contents: read contents: read
packages: write packages: write
@@ -36,14 +40,22 @@ jobs:
env: env:
REGISTRY: https://gitea.iwake.top/api/packages/dsh-plugin/npm/ REGISTRY: https://gitea.iwake.top/api/packages/dsh-plugin/npm/
steps: steps:
- name: Checkout - name: Check out the pushed ref
uses: actions/checkout@v4 run: |
set -eu
url="${GITHUB_SERVER_URL:-https://gitea.iwake.top}/${GITHUB_REPOSITORY:-dsh-plugin/session-delete}.git"
echo "从 ${url} 检出 ${GITHUB_REF}"
git init -q .
git remote add origin "${url}"
git fetch -q --depth 1 origin "${GITHUB_REF}"
git checkout -q FETCH_HEAD
git log --oneline -1
- name: Set up Node.js - name: Show the toolchain
uses: actions/setup-node@v4 run: |
with: set -eu
node-version: '22' node -v
registry-url: https://gitea.iwake.top/api/packages/dsh-plugin/npm/ npm -v
- name: Read and check the version - name: Read and check the version
id: version id: version
@@ -85,8 +97,7 @@ jobs:
echo "registry = $(npm config get registry)" echo "registry = $(npm config get registry)"
# 已发布的版本由注册表自己判定:Gitea 对同版本返回 409(package version already # 已发布的版本由注册表自己判定:Gitea 对同版本返回 409(package version already
# exists)。把它当成"本次无需发布"而不是失败,手动重跑因此是安全的; # exists)。把它当成“本次无需发布”而不是失败;其他错误(E401/E403 等)照旧失败。
# 其他错误(E401/E403 等)照旧让这一步失败。
set +e set +e
output="$(npm publish --registry "${REGISTRY}" --access public 2>&1)" output="$(npm publish --registry "${REGISTRY}" --access public 2>&1)"
status=$? status=$?
@@ -99,4 +110,3 @@ jobs:
else else
exit "${status}" exit "${status}"
fi fi