diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 1fb5092..e053438 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -60,9 +60,12 @@ jobs: #------------------------------------------------------------------- - name: Build arm64 CI image timeout-minutes: 90 + env: + CI_TOKEN: ${{ secrets.CI_TOKEN }} run: | docker buildx version docker buildx build --platform linux/arm64 --load \ + --secret id=gitea_token,env=CI_TOKEN \ -t "$CI_IMAGE" -f ci/Dockerfile . #------------------------------------------------------------------- diff --git a/ci/Dockerfile b/ci/Dockerfile index 693fecb..29a0286 100755 --- a/ci/Dockerfile +++ b/ci/Dockerfile @@ -4,9 +4,9 @@ # - Ubuntu 20.04 arm64 base (matches the target board) # - MOOS-IvP built from source and installed to /usr/local # - jsoncpp (the only extra dep used by pPowerManger) -# NOTE: github.com is unreachable from the CN runner, so MOOS-IvP -# is fetched as a tarball through a github proxy (with -# fallbacks) instead of `git clone`. +# MOOS-IvP is cloned from the internal Gitea mirror (UUV/moos-ivp) +# via a BuildKit secret (github.com is unreachable from the CN +# runner). PROJ/UTM are disabled to avoid github-based CPM fetches. #======================================================================= FROM arm64v8/ubuntu:20.04 @@ -25,32 +25,26 @@ RUN sed -i \ cmake \ git \ ca-certificates \ - curl \ - tar \ libjsoncpp-dev \ rsync \ && rm -rf /var/lib/apt/lists/* #----------------------------------------------------------------------- -# Fetch MOOS-IvP source tarball (github blocked -> try proxies then direct) +# Clone MOOS-IvP from the internal Gitea mirror +# (token passed via BuildKit secret, not baked into the image) #----------------------------------------------------------------------- -RUN set -eux; \ - ok=0; \ - for p in "https://gh-proxy.com/" "https://ghfast.top/" "https://ghproxy.net/" "https://github.com/"; do \ - if curl -fsSL --retry 3 --max-time 300 \ - "${p}https://github.com/moos-ivp/moos-ivp/archive/refs/heads/main.tar.gz" \ - -o /tmp/moos-ivp.tar.gz; then ok=1; break; fi; \ - done; \ - [ "$ok" = "1" ] || { echo "MOOS-IvP download failed"; exit 1; }; \ - mkdir -p /opt/moos-ivp; \ - tar -xzf /tmp/moos-ivp.tar.gz -C /opt/moos-ivp --strip-components=1; \ - rm -f /tmp/moos-ivp.tar.gz; \ - ls /opt/moos-ivp +RUN --mount=type=secret,id=gitea_token \ + set -eux; \ + TOKEN="$(cat /run/secrets/gitea_token)"; \ + git clone --depth 1 "https://zjk:${TOKEN}@gitea2.zhaojingkui.xyz/UUV/moos-ivp.git" /opt/moos-ivp; \ + git -C /opt/moos-ivp remote set-url origin "https://gitea2.zhaojingkui.xyz/UUV/moos-ivp.git" #----------------------------------------------------------------------- # Build & install MOOS-IvP (bundles MOOS core + essentials + geodesy + ivp) # build-moos.sh -m : skip GUI tools (no FLTK needed) +# --with-proj=off : skip PROJ (its CPM fetch pulls from github) # build-ivp.sh -n : skip GUI apps (no FLTK needed) +# -u : skip UTM (depends on PROJ-backed geodesy) # Installs libMOOS + MOOSConfig.cmake + ivp headers/libs to /usr/local, # matching the layout expected by the project's top-level CMakeLists.txt. #-----------------------------------------------------------------------