ci: verify isolated Docker news journeys before merging to main
This commit is contained in:
1 parent
043c763484
commit
33a760ab6b
6 files changed
+274
-7
No files matched your search
@@ -0,0 +1,42 @@
|
||||
#!/usr/bin/env bash
|
||||
# Build and browser-test a branch candidate using only disposable services.
|
||||
set -Eeuo pipefail
|
||||
umask 077
|
||||
|
||||
sha="$(git rev-parse HEAD)"
|
||||
[[ "$sha" =~ ^[0-9a-f]{40}$ ]] || { echo "Invalid preflight commit" >&2; exit 1; }
|
||||
temporary="$(mktemp -d "${TMPDIR:-/tmp}/cms-preflight.XXXXXXXXXX")"
|
||||
suffix="${temporary##*.}"
|
||||
image="epicnext-cms:preflight-$sha-$suffix"
|
||||
build_attempted=0
|
||||
|
||||
finish() {
|
||||
local status=$?
|
||||
trap - EXIT
|
||||
if [ "$build_attempted" -eq 1 ]; then
|
||||
# Remove this run's tag only. Never prune, force-remove or touch release tags.
|
||||
if ! docker image rm "$image"; then
|
||||
if [ "$status" -eq 0 ]; then status=1; fi
|
||||
fi
|
||||
fi
|
||||
# The private directory contains no files; never recursively delete a path.
|
||||
if ! rmdir -- "$temporary"; then
|
||||
if [ "$status" -eq 0 ]; then status=1; fi
|
||||
fi
|
||||
if [ "$status" -eq 0 ]; then echo "Branch preflight verified: $sha"; fi
|
||||
exit "$status"
|
||||
}
|
||||
trap finish EXIT
|
||||
trap 'exit 130' INT
|
||||
trap 'exit 143' TERM
|
||||
[[ "$temporary" = /* && -d "$temporary" && ! -L "$temporary" && "$suffix" =~ ^[a-zA-Z0-9]{10}$ ]] || {
|
||||
echo "Invalid private preflight directory" >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
pnpm install --frozen-lockfile
|
||||
pnpm exec playwright install chromium
|
||||
build_attempted=1
|
||||
DOCKER_BUILDKIT=1 docker build --network=host --progress=plain \
|
||||
--build-arg NEXT_DEPLOYMENT_ID="$sha" -t "$image" .
|
||||
NEWS_E2E_IMAGE="$image" NEWS_E2E_RELEASE="$sha" node --import tsx e2e/news-real/run.ts
|
||||
Reference in new issue
Block a user