fix(ci): pr-iphone-deploy — cache, secrets, LGTM regex, concurrency, watch build, scope (#12)
All checks were successful
Admin Web Docker / Docker Build Validation (push) Has been skipped
Admin Web Docker / Admin Web Tests (push) Successful in 33s
CI / Detect Changes (push) Successful in 3s
Admin Web Docker / Semantic Release (push) Successful in 11s
CI / YouTube Worker (push) Has been skipped
Admin Web Docker / Build & Push Docker Image (push) Successful in 22s
CI / Deploy (push) Has been skipped

This commit was merged in pull request #12.
This commit is contained in:
2026-07-19 20:59:33 +02:00
parent 32ccbccf5b
commit 6937a36ccd
3 changed files with 114 additions and 54 deletions

View File

@@ -1,24 +1,35 @@
# =============================================================================
# TabataGo — PR → Build → WiFi/USB Direct Deploy → Wait LGTM → Merge
# TabataGo — PR → Build → devicectl Deploy → Wait LGTM → Merge
# =============================================================================
name: PR → Build → WiFi/USB Deploy → LGTM
name: PR → Build → devicectl Deploy → LGTM
on:
pull_request:
branches: [main]
types: [opened, synchronize, reopened]
# Only run the iOS build+deploy when the PR actually touches the Swift app
# or this workflow itself. Docs-only / backend-only / admin-web-only PRs
# skip the runner entirely (no point rebuilding an unchanged .app).
paths:
- 'tabatago-swift/**'
- '.github/workflows/pr-iphone-deploy.yml'
permissions:
contents: write
pull-requests: write
# Every mutation (comments, merge) goes through the Gitea API with PR_API_TOKEN,
# never the runner's native GITHUB_TOKEN — so a `permissions:` block would be
# a no-op here. Intentionally omitted.
concurrency:
# Per-PR grouping: superseded pushes cancel the previous pipeline, different
# PRs still run in parallel. Prevents double-merges and wasted runner time.
group: pr-iphone-deploy-${{ github.event.pull_request.number }}
cancel-in-progress: true
jobs:
build-deploy:
name: Build & Deploy to iPhone (WiFi/USB)
name: Build & Deploy to iPhone (devicectl)
runs-on: macos
timeout-minutes: 20
timeout-minutes: 30
steps:
- name: Checkout
@@ -42,9 +53,11 @@ jobs:
# Act runner caches
rm -rf ~/.cache/act/*/hostexecutor/tabatago-swift/build 2>/dev/null || true
# SPM caches are KEPT between runs — RevenueCat is 1.10 GiB and takes
# SPM cache is KEPT between runs — RevenueCat is ~1.10 GiB and takes
# 5+ minutes to clone; re-cloning on every CI run would waste time
# and cause random failures on the act_runner sandbox.
# and cause random failures on the act_runner sandbox. It lives at
# build/spm-cache (see -clonedSourcePackagesDirPath in the Build step)
# so NEVER `rm -rf build/` — only delete build/derived.
# Xcode DerivedData — suppression COMPLÈTE (le bundle ID a changé,
# l'ancien dossier TabataGo-* peut être ignoré par le nouveau build)
@@ -52,10 +65,12 @@ jobs:
# Module cache Xcode — des .pcm stale peuvent segfault le linker
rm -rf ~/Library/Developer/Xcode/DerivedData/ModuleCache.noindex 2>/dev/null || true
rm -rf ~/Library/Caches/com.apple.dt.Xcode
# NOTE: do NOT `rm -rf ~/Library/Caches/com.apple.dt.Xcode` — that is the
# shared global cache; wiping it slows every subsequent build.
# Build artifacts locaux (utilisés par le step "Build app")
rm -rf build/
# Build artifacts locaux — sparing build/spm-cache (see above).
rm -rf build/derived
rm -rf build/*.log 2>/dev/null || true
rm -rf .build
rm -rf tabatago-swift/.build
rm -rf tabatago-swift/TabataGo.xcodeproj
@@ -65,11 +80,45 @@ jobs:
find . -name "Package.resolved" -delete 2>/dev/null || true
find . -name ".package.resolved" -delete 2>/dev/null || true
echo "✅ Caches nettoyés"
echo "✅ Caches nettoyés (SPM cache préservé)"
- name: Install tools (xcodegen, node, ios-deploy)
- name: Install tools (xcodegen)
run: |
brew install xcodegen node ios-deploy || true
# The act_runner shell can land under Rosetta 2 on Apple Silicon;
# Homebrew lives in /opt/homebrew (ARM prefix), so run brew natively.
# (Brew refuses to install/upgrade under Rosetta in the ARM prefix.)
# Only xcodegen is needed — node is NOT used by any step in this
# workflow, and installing it triggers brew's "installed dependents
# check" which tries to rebuild unrelated formulae (e.g. gemini-cli)
# and fails the build.
arch -arm64 brew install xcodegen
- name: Write Secrets.xcconfig from Gitea secrets
env:
SUPABASE_URL: ${{ secrets.SUPABASE_URL }}
SUPABASE_ANON_KEY: ${{ secrets.SUPABASE_ANON_KEY }}
REVENUECAT_API_KEY: ${{ secrets.REVENUECAT_API_KEY }}
POSTHOG_API_KEY: ${{ secrets.POSTHOG_API_KEY }}
run: |
# Preflight: fail loudly if a secret is missing, rather than producing
# an .app that silently can't reach Supabase/RevenueCat at runtime.
for v in SUPABASE_URL SUPABASE_ANON_KEY REVENUECAT_API_KEY; do
val="$(printenv "$v")"
if [ -z "$val" ]; then
echo "❌ Secret missing: $v. Add it to Gitea repo secrets."
exit 1
fi
done
# POSTHOG_API_KEY may legitimately be empty (PostHog not yet wired).
# NOTE: heredoc body MUST start at column 0 — xcconfig keys are
# whitespace-sensitive, leading spaces would break the build setting.
cat > tabatago-swift/Config/Secrets.xcconfig <<EOF
SUPABASE_URL = ${SUPABASE_URL}
SUPABASE_ANON_KEY = ${SUPABASE_ANON_KEY}
REVENUECAT_API_KEY = ${REVENUECAT_API_KEY}
POSTHOG_API_KEY = ${POSTHOG_API_KEY}
EOF
echo "✅ Secrets.xcconfig written (values redacted)"
- name: Generate Xcode project
run: |
@@ -99,27 +148,20 @@ jobs:
CODE_SIGN_STYLE=Automatic \
DEVELOPMENT_TEAM=2MJF39L8VY
- name: Install to iPhone (WiFi → USB fallback)
- name: Install to iPhone (devicectl)
run: |
UDID="00008120-000925CE3672201E"
APP=$(find build/derived -name 'TabataGo.app' -type d | head -1)
# 1. Try WiFi first (Xcode 15+ devicectl network discovery)
echo "📱 Trying WiFi install via devicectl..."
if xcrun devicectl device install app --device "$UDID" "$APP" > /tmp/devicectl.log 2>&1; then
echo "✅ Installed via WiFi"
exit 0
fi
tail -10 /tmp/devicectl.log
# 2. Fallback to USB via ios-deploy
echo "🔌 WiFi failed, trying USB..."
if ios-deploy --bundle "$APP" --id "$UDID" --justlaunch; then
echo "✅ Installed via USB"
# devicectl handles both WiFi (network) and wired (USB-C/Thunderbolt)
# discovery natively — no separate USB-fallback tool needed.
echo "📱 Installing via devicectl..."
if xcrun devicectl device install app --device "$UDID" "$APP"; then
echo "✅ Installed via devicectl"
exit 0
fi
echo "❌ Install failed (both WiFi and USB)"
echo "❌ devicectl install failed"
exit 1
@@ -133,7 +175,7 @@ jobs:
curl -s -X POST \
-H "Authorization: token ${GT_TOKEN}" \
-H "Content-Type: application/json" \
-d "{\"body\":\"## 📱 Prêt à tester !\\n\\nL'app est déployée sur l'iPhone (USB/WiFi).\\n\\n- Teste les changements\\n- Reply **LGTM** pour merger\\n- Reply **KO** pour bloquer\"}" \
-d "{\"body\":\"## 📱 Prêt à tester !\\n\\nL'app est déployée sur l'iPhone (devicectl).\\n\\n- Teste les changements\\n- Reply **LGTM** pour merger\\n- Reply **KO** pour bloquer\"}" \
"${GITEA_URL}/api/v1/repos/${REPO}/issues/${PR}/comments"
wait-approval:
@@ -157,29 +199,31 @@ jobs:
echo "⏳ Attente LGTM sur PR #${PR}..."
LAST_ID=$(curl -s -H "Authorization: token ${GT_TOKEN}" \
"${API}/issues/${PR}/comments" | \
python3 -c "import json,sys; cs=json.load(sys.stdin); print(cs[-1]['id'] if cs else 0)" 2>/dev/null || echo 0)
# Re-fetch ALL comments each cycle (not since_id) so we also catch
# edits — e.g. a reviewer changing "KO" → "LGTM". Negligible cost for
# PRs with <50 comments.
while [ $TRIES -lt $MAX ]; do
sleep 30
TRIES=$((TRIES + 1))
COMMENTS=$(curl -s -H "Authorization: token ${GT_TOKEN}" \
"${API}/issues/${PR}/comments?since_id=${LAST_ID}")
"${API}/issues/${PR}/comments?limit=50&page=1")
if echo "$COMMENTS" | grep -qi '"body": *"LGTM"'; then
echo "✅ LGTM reçu ! Merge..."
# Match LGTM/KO anywhere in the body (with a word boundary so "KOM"
# or "LGTMX" don't trigger). Case-insensitive.
if echo "$COMMENTS" | grep -qiE '"body":[[:space:]]*"[^"]*\bLGTM\b'; then
echo "✅ LGTM reçu ! Squash-merge..."
curl -s -X POST \
-H "Authorization: token ${GT_TOKEN}" \
-H "Content-Type: application/json" \
-d "{\"Do\":\"merge\"}" \
-d "{\"Do\":\"squash\"}" \
"${API}/pulls/${PR}/merge"
echo "✅ Mergée."
echo "✅ Mergée (squash)."
exit 0
fi
if echo "$COMMENTS" | grep -qi '"body": *"KO"'; then
if echo "$COMMENTS" | grep -qiE '"body":[[:space:]]*"[^"]*\bKO\b'; then
echo "❌ KO reçu. Bloquée."
exit 1
fi