refactor(ci): volledig opnieuw geschreven CI workflow
- Check job: lint, typecheck, test in node:26 container - Deploy job: Docker build + deploy + health check op host - Corepack pnpm installatie - BuildKit caching - Contract tests herschreven (18 tests)
This commit is contained in:
1 parent
a52cbead8a
commit
3c0acc3fcf
3 files changed
+91
-83
No files matched your search
+35
-35
@@ -2,76 +2,75 @@ name: CI
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
- master
|
||||
tags:
|
||||
- "v*"
|
||||
branches: [main, master]
|
||||
tags: ["v*"]
|
||||
pull_request:
|
||||
branches:
|
||||
- main
|
||||
- master
|
||||
branches: [main, master]
|
||||
workflow_dispatch:
|
||||
|
||||
env:
|
||||
UV_THREADPOOL_SIZE: 1
|
||||
NODE_OPTIONS: "--max-old-space-size=1536"
|
||||
SKIP_ENV_VALIDATION: 1
|
||||
NODE_ENV: test
|
||||
DATABASE_URL: "mysql://test:test@localhost:3306/test?charset=utf8mb4"
|
||||
REDIS_URL: "redis://127.0.0.1:6379?connect_timeout=2"
|
||||
AUTH_SECRET: "ci-test-secret-key-that-is-long-enough"
|
||||
BCRYPT_ROUNDS: 4
|
||||
|
||||
jobs:
|
||||
# ─────────────────────────────────────────────
|
||||
# Lint, typecheck & unit tests
|
||||
# Draait in een node:26 container op de Epic runner
|
||||
# ─────────────────────────────────────────────
|
||||
check:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out repository code
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
repository: ${{ gitea.repository }}
|
||||
token: ${{ gitea.token }}
|
||||
fetch-depth: 1
|
||||
|
||||
- name: Install pnpm
|
||||
- name: Setup pnpm
|
||||
run: |
|
||||
corepack enable
|
||||
corepack prepare [email protected] --activate
|
||||
|
||||
- name: pnpm install
|
||||
- name: Install dependencies
|
||||
run: pnpm install --frozen-lockfile --jobs 1
|
||||
|
||||
- name: Lint (Biome)
|
||||
run: pnpm biome:lint --workers 1
|
||||
- name: Lint
|
||||
run: pnpm biome:lint
|
||||
|
||||
- name: Typecheck
|
||||
run: pnpm typecheck
|
||||
|
||||
- name: Test
|
||||
env:
|
||||
SKIP_ENV_VALIDATION: 1
|
||||
NODE_ENV: test
|
||||
DATABASE_URL: "mysql://test:test@localhost:3306/test?charset=utf8mb4"
|
||||
REDIS_URL: "redis://127.0.0.1:6379?connect_timeout=2"
|
||||
AUTH_SECRET: "ci-test-secret-key-that-is-long-enough"
|
||||
BCRYPT_ROUNDS: 4
|
||||
run: pnpm test --maxWorkers=1
|
||||
|
||||
# ─────────────────────────────────────────────
|
||||
# Docker build & deploy
|
||||
# Draait op de host (self-hosted) zodat Docker
|
||||
# toegang heeft tot de daemon en volumes.
|
||||
# ─────────────────────────────────────────────
|
||||
deploy:
|
||||
needs: check
|
||||
if: gitea.event_name == 'push' && (gitea.ref_name == 'main' || gitea.ref_name == 'master')
|
||||
runs-on: self-hosted
|
||||
steps:
|
||||
- name: Check out repository code for deploy
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
repository: ${{ gitea.repository }}
|
||||
token: ${{ gitea.token }}
|
||||
|
||||
- name: Build and Deploy Container
|
||||
- name: Build image
|
||||
run: |
|
||||
set -e
|
||||
echo "--- Start Docker Build & Deploy ---"
|
||||
|
||||
DOCKER_BUILDKIT=1 docker build \
|
||||
--build-arg NODE_OPTIONS="--max-old-space-size=1536" \
|
||||
--cache-from epicnext-cms:latest \
|
||||
-t epicnext-cms:latest .
|
||||
|
||||
- name: Deploy container
|
||||
run: |
|
||||
docker stop epicnext-cms-app 2>/dev/null || true
|
||||
docker rm epicnext-cms-app 2>/dev/null || true
|
||||
|
||||
@@ -83,17 +82,18 @@ jobs:
|
||||
|
||||
docker image prune -f
|
||||
|
||||
echo "--- Wachten op health check ---"
|
||||
- name: Health check
|
||||
run: |
|
||||
for i in $(seq 1 30); do
|
||||
BODY="$(curl -sf --max-time 5 http://127.0.0.1:3002/api/health 2>/dev/null || true)"
|
||||
if echo "${BODY}" | grep -q '"database":true'; then
|
||||
echo "Health OK"
|
||||
if curl -sf --max-time 5 http://127.0.0.1:3002/api/health \
|
||||
| grep -q '"database":true'; then
|
||||
echo "Deploy OK"
|
||||
exit 0
|
||||
fi
|
||||
echo "Health attempt ${i}/30, retrying..."
|
||||
echo "Waiting... ($i/30)"
|
||||
sleep 3
|
||||
done
|
||||
|
||||
echo "ERROR: Health check failed!" >&2
|
||||
echo "ERROR: Health check failed" >&2
|
||||
docker logs epicnext-cms-app --tail 50 >&2 || true
|
||||
exit 1
|
||||
@@ -2,32 +2,50 @@ import { readFileSync } from "node:fs";
|
||||
import { resolve } from "node:path";
|
||||
import { describe, expect, it } from "vitest";
|
||||
|
||||
describe("CI workflow", () => {
|
||||
const workflow = readFileSync(
|
||||
resolve(process.cwd(), ".gitea/workflows/ci.yaml"),
|
||||
"utf8",
|
||||
).replace(/\r\n/g, "\n");
|
||||
const workflow = readFileSync(
|
||||
resolve(process.cwd(), ".gitea/workflows/ci.yaml"),
|
||||
"utf8",
|
||||
);
|
||||
|
||||
it("runs check then production deploy on push to main", () => {
|
||||
describe("CI workflow", () => {
|
||||
it("has check and deploy jobs", () => {
|
||||
expect(workflow).toContain("check:");
|
||||
expect(workflow).toContain("deploy:");
|
||||
});
|
||||
|
||||
it("deploy depends on check", () => {
|
||||
expect(workflow).toContain("needs: check");
|
||||
});
|
||||
|
||||
it("deploy only runs on push to main/master", () => {
|
||||
expect(workflow).toContain("gitea.event_name == 'push'");
|
||||
expect(workflow).toContain("gitea.ref_name == 'main'");
|
||||
});
|
||||
|
||||
it("check runs lint, typecheck, and test", () => {
|
||||
expect(workflow).toContain("pnpm biome:lint");
|
||||
expect(workflow).toContain("pnpm typecheck");
|
||||
expect(workflow).toContain("pnpm test");
|
||||
expect(workflow).toContain("needs: check");
|
||||
expect(workflow).toContain("gitea.event_name == 'push'");
|
||||
expect(workflow).toContain("gitea.ref_name == 'main'");
|
||||
expect(workflow).toContain("/api/health");
|
||||
});
|
||||
|
||||
it("deploy uses self-hosted runner", () => {
|
||||
expect(workflow).toContain("runs-on: self-hosted");
|
||||
});
|
||||
|
||||
it("check uses ubuntu-latest runner", () => {
|
||||
expect(workflow).toContain("runs-on: ubuntu-latest");
|
||||
});
|
||||
|
||||
it("installs pnpm via corepack", () => {
|
||||
expect(workflow).toContain("corepack enable");
|
||||
expect(workflow).toContain("corepack prepare [email protected]");
|
||||
});
|
||||
|
||||
it("does not use github context", () => {
|
||||
expect(workflow).not.toContain("github.ref");
|
||||
});
|
||||
|
||||
it("uses Gitea SHA for check checkout", () => {
|
||||
expect(workflow).toContain("SKIP_ENV_VALIDATION");
|
||||
});
|
||||
|
||||
it("includes tag triggers", () => {
|
||||
expect(workflow).toContain('tags:\n - "v*"');
|
||||
});
|
||||
|
||||
it("sets test environment variables as global env", () => {
|
||||
expect(workflow).toContain("SKIP_ENV_VALIDATION: 1");
|
||||
it("has tag trigger", () => {
|
||||
expect(workflow).toContain('tags: ["v*"]');
|
||||
});
|
||||
});
|
||||
@@ -2,63 +2,53 @@ import { readFileSync } from "node:fs";
|
||||
import { resolve } from "node:path";
|
||||
import { describe, expect, it } from "vitest";
|
||||
|
||||
describe("production deploy workflow", () => {
|
||||
const workflow = readFileSync(
|
||||
resolve(process.cwd(), ".gitea/workflows/ci.yaml"),
|
||||
"utf8",
|
||||
);
|
||||
const deployStart = workflow.indexOf("\n deploy:");
|
||||
const deployJob = deployStart > -1 ? workflow.slice(deployStart) : "";
|
||||
const workflow = readFileSync(
|
||||
resolve(process.cwd(), ".gitea/workflows/ci.yaml"),
|
||||
"utf8",
|
||||
);
|
||||
const deployStart = workflow.indexOf("\n deploy:");
|
||||
const deployJob = deployStart > -1 ? workflow.slice(deployStart) : "";
|
||||
|
||||
it("is gated behind the check job", () => {
|
||||
expect(deployJob).toContain("needs: check");
|
||||
expect(deployJob).toContain("gitea.event_name == 'push'");
|
||||
expect(deployJob).toContain("gitea.ref_name == 'main'");
|
||||
});
|
||||
|
||||
it("runs on self-hosted runner for Docker access", () => {
|
||||
describe("deploy job", () => {
|
||||
it("runs on self-hosted for Docker access", () => {
|
||||
expect(deployJob).toContain("runs-on: self-hosted");
|
||||
});
|
||||
|
||||
it("builds Docker image with production settings", () => {
|
||||
it("builds Docker image with BuildKit", () => {
|
||||
expect(deployJob).toContain("DOCKER_BUILDKIT=1");
|
||||
expect(deployJob).toContain("docker build");
|
||||
expect(deployJob).toContain("-t epicnext-cms:latest");
|
||||
expect(deployJob).toContain("--build-arg NODE_OPTIONS");
|
||||
});
|
||||
|
||||
it("stops and removes previous container before starting new one", () => {
|
||||
it("stops old container before starting new one", () => {
|
||||
expect(deployJob).toContain("docker stop epicnext-cms-app");
|
||||
expect(deployJob).toContain("docker rm epicnext-cms-app");
|
||||
});
|
||||
|
||||
it("starts container with host networking and restart policy", () => {
|
||||
it("starts container with correct settings", () => {
|
||||
expect(deployJob).toContain("--restart always");
|
||||
expect(deployJob).toContain("--net=host");
|
||||
expect(deployJob).toContain("--name epicnext-cms-app");
|
||||
});
|
||||
|
||||
it("runs HTTP health check after deployment", () => {
|
||||
it("runs health check", () => {
|
||||
expect(deployJob).toContain("/api/health");
|
||||
expect(deployJob).toContain('"database":true');
|
||||
});
|
||||
|
||||
it("cleans up old Docker images after deploy", () => {
|
||||
it("cleans up old images", () => {
|
||||
expect(deployJob).toContain("docker image prune -f");
|
||||
});
|
||||
|
||||
it("does not override onlyBuiltDependencies (uses pnpm-workspace.yaml)", () => {
|
||||
expect(workflow).not.toContain("PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES");
|
||||
});
|
||||
|
||||
it("does not use pnpm test in deploy", () => {
|
||||
it("does not run pnpm test in deploy", () => {
|
||||
expect(deployJob).not.toContain("pnpm test");
|
||||
});
|
||||
|
||||
it("reports deploy logs on health check failure", () => {
|
||||
it("shows docker logs on failure", () => {
|
||||
expect(deployJob).toContain("docker logs epicnext-cms-app");
|
||||
});
|
||||
|
||||
it("produces meaningful error on health failure", () => {
|
||||
expect(deployJob).toContain("ERROR: Health check failed!");
|
||||
it("exits with error on health check failure", () => {
|
||||
expect(deployJob).toContain("exit 1");
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user