Rust tooling cicd
Skill fusengine/agents/plugins/rust-expert/skills/rust-tooling-cicd
Use when structuring a Cargo workspace, wiring features, or building a Rust CI pipeline — fmt, clippy, cargo-deny, cargo-audit, nextest, doc-tests, coverage, MSRV. Covers the canonical CI gate order and supply-chain checks. Do NOT use for writing the tests themselves (use rust-testing-quality) or non-Rust CI.From its SKILL.md
npx -y skills add fusengine/agents --skill rust-tooling-cicdAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 22 stars22 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
4.6 KB, ~1.0k tokens by cl100k_base, as published. Nobody here has run it
Rust Tooling & CI/CD
Agent Workflow (MANDATORY)
Before ANY tooling/CI work, use TeamCreate to spawn 3 agents:
- fuse-ai-pilot:explore-codebase - Inspect existing
Cargo.toml, workspace layout,.github/workflows - fuse-ai-pilot:research-expert - Verify current cargo / cargo-deny / nextest docs via Context7/Exa
- mcp__context7__query-docs - Check workspace-inheritance and feature-unification specifics
After implementation, run fuse-ai-pilot:sniper for validation.
Overview
| Layer | Tool(s) | Purpose |
|---|---|---|
| Layout | Cargo workspaces | One Cargo.lock, one target/, shared metadata |
| Config | features, workspace.dependencies | Optional functionality, single source of versions |
| Format/lint | cargo fmt, cargo clippy | Style + correctness lints, warnings as errors |
| Supply chain | cargo deny, cargo audit | Licenses, bans, duplicate/yanked/vulnerable crates |
| Test | cargo nextest, cargo test --doc | Fast parallel run + doc-tests |
| Coverage/MSRV | cargo llvm-cov, cargo hack | Line coverage, minimum-supported-Rust matrix |
Critical Rules
- Gate order is fixed - fmt → clippy → deny → audit → nextest →
test --doc→ coverage. Cheap, fast-failing checks run first. -D warningson clippy in CI -cargo clippy --all-targets --all-features -- -D warnings. A warning must fail the build.- Commit
deny.toml- supply-chain policy is code; it must be reviewed and versioned. - Centralize versions in
workspace.dependencies- members inherit withdep.workspace = true; never pin the same crate twice. cargo test --docis a separate step - nextest never runs doc-tests (see rust-testing-quality).
Architecture
my-workspace/
├── Cargo.toml # [workspace] members + workspace.dependencies + lints
├── Cargo.lock # single lockfile, committed
├── deny.toml # supply-chain policy, committed
├── crates/
│ ├── core/Cargo.toml # inherits version.workspace = true
│ └── cli/Cargo.toml
└── .github/workflows/ci.yml
→ See ci-workflow.md and deny-toml.md
Reference Guide
Concepts
| Topic | Reference | When to Consult |
|---|---|---|
| Workspaces & features | workspaces-features.md | Structuring members, inheriting deps, feature design, MSRV |
| CI gate | ci-gate.md | Ordering checks, cargo-deny/audit, coverage |
Templates
| Template | When to Use |
|---|---|
| ci-workflow.md | GitHub Actions pipeline |
| deny-toml.md | Supply-chain policy + workspace root |
Quick Reference
The full local gate
cargo fmt --all -- --check
cargo clippy --all-targets --all-features -- -D warnings
cargo deny check
cargo audit
cargo nextest run --all-features
cargo test --doc
cargo llvm-cov --all-features --workspace
Workspace dependency inheritance
# root Cargo.toml
[workspace.dependencies]
serde = { version = "1", features = ["derive"] }
# member Cargo.toml
[dependencies]
serde = { workspace = true }
→ See deny-toml.md for the complete root manifest
Best Practices
DO
- Fail fast: run
fmtandclippybefore the expensive test/coverage steps - Keep one
[workspace.dependencies]as the version source of truth - Run
cargo hack --feature-powerset checkto catch broken feature combinations - Run
cargo macheteto prune unused dependencies
DON'T
- Let clippy warnings pass CI (use
-D warnings) - Duplicate crate versions across members instead of inheriting
- Skip
cargo denybecause "audit already ran" — they check different things - Forget
cargo test --docafter nextest
What ships with it: 5 files
13.7 KB alongside SKILL.md
references/
- ci-gate.md3.9 KB
- templates/ci-workflow.md2.7 KB
- templates/deny-toml.md2.9 KB
- workspaces-features.md4.2 KB
- .gitkeep0 B