Repository navigation
91 lines (84 loc) · 3.46 KB
/
Copy pathdaily.yml
File metadata and controls
91 lines (84 loc) · 3.46 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
name: daily scan
# Test runs get their own title, so they don't count as the day's scan (see the check job).
run-name: ${{ (inputs.dry_run || inputs.only) && 'daily scan (test)' || 'daily scan' }}
on:
schedule:
# Backup only. Since late August 2026 GitHub has been starting scheduled runs 3-10 hours late
# (ours: about 6), so the 07:20 IST run is started from outside GitHub instead (see README).
# This one stops early unless today's scan is missing or failed.
- cron: "50 1 * * *"
workflow_dispatch:
inputs:
dry_run:
description: "Dry run: read every source and print what would be added (no sheet, no email)"
type: boolean
default: false
only:
description: "Optional: comma-separated companies or boards, e.g. unstop,foundit"
required: false
default: ""
permissions:
contents: read
# The sheet has one writer at a time (a later laptop run for LinkedIn etc. joins this group).
concurrency:
group: jobscan-sheet
cancel-in-progress: false
jobs:
check:
runs-on: ubuntu-latest
permissions:
actions: read # to list this workflow's earlier runs
outputs:
scan: ${{ steps.today.outputs.scan }}
steps:
- name: Has today's scan already run?
id: today
env:
GH_TOKEN: ${{ github.token }}
EVENT: ${{ github.event_name }}
run: |
if [ "$EVENT" != schedule ]; then echo "scan=true" >> "$GITHUB_OUTPUT"; exit 0; fi
# Midnight IST in UTC; run times are UTC ISO-8601 strings, which compare in time order.
since=$(date -u -d "$(TZ=Asia/Kolkata date +%F) 00:00 +0530" +%Y-%m-%dT%H:%M:%SZ)
done=$(gh run list -R "$GITHUB_REPOSITORY" --workflow daily.yml --status success --limit 20 \
--json displayTitle,createdAt \
--jq "map(select(.displayTitle == \"daily scan\" and .createdAt >= \"$since\")) | length")
if [ "$done" -gt 0 ]; then
echo "::notice::Today's scan already ran, so this late scheduled run stops here."
echo "scan=false" >> "$GITHUB_OUTPUT"
else
echo "scan=true" >> "$GITHUB_OUTPUT"
fi
scan:
needs: check
if: needs.check.outputs.scan == 'true'
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v7
- uses: actions/setup-python@v7
with:
python-version: "3.13"
cache: pip
- run: pip install -r requirements.txt
- name: Write the service-account key
if: ${{ !inputs.dry_run }}
env:
KEY: ${{ secrets.GOOGLE_SERVICE_ACCOUNT_JSON }}
run: |
test -n "$KEY" || { echo "::error::Repository secret GOOGLE_SERVICE_ACCOUNT_JSON is not set"; exit 1; }
mkdir -p secrets
printf '%s' "$KEY" > secrets/service_account.json
- name: Scan company feeds and job boards
env:
GOOGLE_SERVICE_ACCOUNT_FILE: secrets/service_account.json
SHEET_ID: ${{ secrets.SHEET_ID }}
GEMINI_API_KEY: ${{ secrets.GEMINI_API_KEY }}
GEMINI_MODEL: ${{ vars.GEMINI_MODEL }}
GMAIL_ADDRESS: ${{ secrets.GMAIL_ADDRESS }}
GMAIL_APP_PASSWORD: ${{ secrets.GMAIL_APP_PASSWORD }}
ALERT_TO: ${{ secrets.ALERT_TO }}
MAX_MIN_YEARS: ${{ vars.MAX_MIN_YEARS }}
DRY_RUN: ${{ inputs.dry_run && '--dry-run' || '' }}
ONLY: ${{ inputs.only }}
run: python -m jobscan $DRY_RUN ${ONLY:+--only "$ONLY"}