fix(ci): pr-iphone-deploy — cache, secrets, LGTM regex, concurrency, watch build, scope #12

Merged
millianlmx merged 6 commits from fix/ci-pr-iphone-deploy into main 2026-07-19 20:59:33 +02:00

6 Commits

Author SHA1 Message Date
Millian Lamiaux
bebe381100 fix(ci): drop node from brew install — unused, triggers gemini-cli rebuild
All checks were successful
CI / YouTube Worker (pull_request) Has been skipped
CI / Deploy (pull_request) Has been skipped
CI / Detect Changes (pull_request) Successful in 4s
PR → Build → devicectl Deploy → LGTM / Build & Deploy to iPhone (devicectl) (pull_request) Successful in 1m39s
PR → Build → devicectl Deploy → LGTM / Wait for LGTM comment (pull_request) Successful in 33s
Run failed at 'brew install xcodegen node' AFTER both formulae upgraded
successfully under ARM: brew's 'installed dependents check' then tried to
rebuild gemini-cli (0.40.1 -> 0.46.0, an unrelated dev tool on the runner
that depends on node) and exited 1.

Verified node is NOT used by any step in pr-iphone-deploy.yml — only
xcodegen is. The only node references in the repo are in
scripts/prepare-release.cjs and scripts/verify-admin-web-docker.sh,
neither of which runs in this workflow. Node was a historical leftover.

Drop node from the brew install. No node upgrade = no dependents check =
no gemini-cli rebuild. Also sync AGENTS.md §5 step 4.
2026-07-19 20:54:17 +02:00
Millian Lamiaux
437ec130fe fix(ci): run brew under ARM + drop ios-deploy, use devicectl only
Some checks failed
CI / Detect Changes (pull_request) Successful in 4s
CI / YouTube Worker (pull_request) Has been skipped
CI / Deploy (pull_request) Has been skipped
PR → Build → devicectl Deploy → LGTM / Build & Deploy to iPhone (devicectl) (pull_request) Failing after 30s
PR → Build → devicectl Deploy → LGTM / Wait for LGTM comment (pull_request) Has been skipped
Two related fixes to the Install tools / Deploy steps:

1. Rosetta/ARM-prefix conflict (unblocks run #142 failure)
   Run #142 failed at 'brew install':
     Cannot install under Rosetta 2 in ARM default prefix (/opt/homebrew)!
   The act_runner shell runs under Rosetta 2 on Apple Silicon, but Homebrew
   is installed natively in /opt/homebrew (ARM prefix). Brew refuses to mix
   architectures and exits 1 — surfaced now because xcodegen/node registered
   as outdated and brew tried to upgrade them.
   Prefix the brew call with 'arch -arm64' (brew's own suggested workaround)
   so the subprocess runs natively regardless of the parent shell's arch.

2. Drop ios-deploy, use xcrun devicectl only
   The deploy step previously tried devicectl (WiFi) first, then fell back
   to ios-deploy (USB). devicectl handles both network and wired discovery
   natively, so the separate USB-fallback tool is unnecessary — removed
   from the brew install and the deploy step.
   Implication: a devicectl failure = deploy failure (no second tool to
   fall back to). Acceptable: devicectl covers both transports.

Also updates workflow name/job labels and the 'Prêt à tester' comment to
drop 'WiFi/USB' wording, and aligns AGENTS.md §5 step 4 (arch -arm64 +
tool list) and step 7 (devicectl only).
2026-07-19 20:47:38 +02:00
Millian Lamiaux
244270488a fix(ci): only run pr-iphone-deploy when tabatago-swift or the workflow changes
Some checks failed
CI / Detect Changes (pull_request) Successful in 3s
CI / YouTube Worker (pull_request) Has been skipped
CI / Deploy (pull_request) Has been skipped
PR → Build → WiFi/USB Deploy → LGTM / Build & Deploy to iPhone (WiFi/USB) (pull_request) Failing after 14s
PR → Build → WiFi/USB Deploy → LGTM / Wait for LGTM comment (pull_request) Has been skipped
Add a paths: filter to the pull_request trigger so the iOS build+deploy
only fires when the PR actually touches:
  - tabatago-swift/**   (the iOS/watchOS app source)
  - .github/workflows/pr-iphone-deploy.yml  (this workflow itself)

PRs touching only AGENTS.md, admin-web/, youtube-worker/, supabase/,
docs/, or root config no longer spin up the macOS runner — no point
rebuilding and deploying an unchanged .app.

Including the workflow file itself in paths: ensures a PR that only
edits the workflow logic still triggers it (so this branch's own PR
will run to validate the changes).
2026-07-19 18:44:28 +02:00
Millian Lamiaux
756b1a405c docs(agents): align CI docs (§5/§7/§8) with real workflow behavior
Rewrite AGENTS.md to match the corrected pr-iphone-deploy.yml:

§5 Workflow:
- Clean step: 'GARDE build/spm-cache' (not ../build/spm-cache), explicit
  warning never to 'rm -rf build/', note that Xcode global cache is spared.
- New step 5: write Secrets.xcconfig from Gitea secrets before xcodegen.
- Scheme lists 4 targets (TabataGo, TabataGoWidget, TabataGoWatch,
  TabataGoWatchWidget) — clarify TabataGoWidget is iOS, not watchOS.
- wait-approval: re-fetches all comments each cycle, regex \bLGTM\b/\bKO\b
  anywhere in body, squash-merge.
- Document concurrency block and timeouts.

§5 Secrets table:
- Replace false 'Injectés via Config/Secrets.xcconfig → Info.plist' with
  the real flow (CI writes file from secrets, Info.plist reads $(VAR)).
- Add historical-exposure warning: Secrets.xcconfig was committed before
  the gitignore rule; key rotation recommended.

§5 Pitfalls + §8 anti-patterns:
- 'rm -rf build/' (not just 'rm -rf cache SPM').
- Don't nuke ~/Library/Caches/com.apple.dt.Xcode.
- permissions: block is intentionally absent (no-op under Gitea API).
- Don't remove concurrency block.
- Don't anchor LGTM grep to body start.
- {"Do":"squash"} not {"Do":"merge"}.
- Scheme must list all 4 targets.

§7 rule #9: expanded with the CI-writes-file flow.
2026-07-19 16:51:02 +02:00
Millian Lamiaux
0b476f5871 fix(project.yml): build watch targets in TabataGo scheme
The TabataGo scheme only listed TabataGo + TabataGoWidget (iOS), so
xcodebuild -scheme TabataGo never compiled the watchOS app in CI. Add
TabataGoWatch + TabataGoWatchWidget to the build targets so watch-side
breakage is caught before deploy.

Note: TabataGoWidget is a real iOS widget target (defined at project.yml
line 165, app-extension/iOS), NOT a phantom — the prior review was wrong
on that point. The real gap was the missing watch targets.

Embed deps were already correct (TabataGo embeds TabataGoWatch, which
embeds TabataGoWatchWidget). Verified locally with xcodegen 2.45.4:
the generated xcscheme now lists all 4 BlueprintNames.

⚠️ Risk: if the watch target has latent build issues (never compiled in
CI before), this will surface them on the next PR. Desirable — catch
before merge, not in the field.
2026-07-19 16:50:47 +02:00
Millian Lamiaux
d50e53e4ad fix(ci): pr-iphone-deploy — cache, secrets, LGTM regex, concurrency, squash
10 fixes to .github/workflows/pr-iphone-deploy.yml:

Cache & build hygiene:
- Stop deleting build/spm-cache (was wiped by 'rm -rf build/'); clean only
  build/derived. RevenueCat (~1.1 GiB) is finally actually preserved.
- Stop nuking ~/Library/Caches/com.apple.dt.Xcode (slows every next build).
- Drop '|| true' on brew install — fail loudly if brew is down.
- Bump build-deploy timeout 20m → 30m for cold builds.

Secrets:
- New step writes Config/Secrets.xcconfig from Gitea secrets (SUPABASE_URL,
  SUPABASE_ANON_KEY, REVENUECAT_API_KEY, POSTHOG_API_KEY) before xcodegen.
  Preflight fails loud if a required secret is missing. Heredoc body at
  column 0 (xcconfig keys are whitespace-sensitive).

LGTM/KO handling:
- Regex now matches anywhere in body with word boundary: \bLGTM\b / \bKO\b.
  'Tested, LGTM!' counts; 'KOM' / 'LGTMX' / 'OK' do not.
- Re-fetch ALL comments each poll (not since_id) to catch edits.
- Squash-merge ({"Do":"squash"}) instead of merge commit.

Workflow structure:
- Add concurrency block (per-PR, cancel-in-progress) — prevents double-merge
  and stacked pipelines on successive pushes.
- Remove no-op 'permissions:' block (all mutations go via Gitea API with
  PR_API_TOKEN, native GITHUB_TOKEN is never used).
2026-07-19 16:50:36 +02:00