igneum/infra/build-server/ci-red/igneum-ci-red.service
igneum-labs b2262e5dc6 Build box: every red run classified and kept, pre-flight before the slot, one run per worktree, box reds in the red-run file, a 09:00 UK digest
The box's 34 red rows of 6 October classified (docs/analysis/ci-failures-2026-10-06.md section 6): 22 iterations, 12 in three real classes (instant deaths with nothing kept, a shared worktree directory, an unread dry run). remote-run.sh now: pre-flight (subcommand, manifest, -p package, --features) refuses in a second with exit 3 and a class; the last 400 lines of every run kept in /srv/builds/_log/runs; a class on every row (compile-error, link-error, test-failure, instant, no-test-matched, slot-timeout, no-dir, preflight-*); a cargo test whose filter matched no test exits 3; a per-worktree lock in checkout and run mode; every red row appended to /srv/ci-red/red.jsonl as source box. red-watch.mjs never posts a box row alone and sends one digest a day (counts per class with each class's guard); the timer runs tick. Shared group cired on the box so the runner and build append to one file. Shown in a sandbox on the box: pass, failing test, empty filter, bad package, bad feature, missing subcommand, compile error, broken manifest, two concurrent runs of one worktree.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 21:40:07 +00:00

30 lines
1.5 KiB
Desktop File

# The red-master watcher's poster on igneum-build-1: one pass a minute from igneum-ci-red.timer.
# The workflow's `red` job (ci.yml, windows.yml; runs on this box's runner after a failed master or release-* run) appends
# one JSON line per run to /srv/ci-red/red.jsonl as the runner user. This pass, as build, posts every line not yet posted
# to the hidden updates channel (DISCORD_WEBHOOK_UPDATES in /srv/discord-hooks/env) and records the run id in
# /srv/discord-hooks/ci-red-posted.json. One line per run, however many passes. Box rows (remote-run.sh, "source":"box")
# are never posted alone; the first pass at or after 09:00 London posts the day's digest (counts per class with each class's
# guard). `journalctl -u igneum-ci-red -n 30`.
# Installed by infra/build-server/ci-red/install.sh.
[Unit]
Description=Igneum CI red watcher (post failed master and release runs to the updates channel)
After=network-online.target
Wants=network-online.target
[Service]
Type=oneshot
User=build
Group=build
Environment=HOME=/home/build
Environment=PATH=/usr/local/bin:/usr/bin:/bin
Environment=IGNEUM_DISCORD_ENV=/srv/discord-hooks/env
Environment=IGNEUM_CI_RED_STATE=/srv/discord-hooks/ci-red-posted.json
WorkingDirectory=/srv/discord-hooks
ExecStart=/usr/local/bin/node /srv/discord-hooks/bin/red-watch.mjs tick --file /srv/ci-red/red.jsonl --live
TimeoutStartSec=50
Nice=10
# the unit reads one secret file; nothing else on the box may
PrivateTmp=yes
NoNewPrivileges=yes
ProtectSystem=strict
ReadWritePaths=/srv/discord-hooks