ci: serialize deployments and restore previous release on smoke failure
This commit is contained in:
1 parent
85a6df162b
commit
7c1f109a9d
7 files changed
+369
-234
No files matched your search
@@ -1,104 +1,33 @@
|
||||
import { readFileSync } from "node:fs";
|
||||
import { resolve } from "node:path";
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { expect, it } from "vitest";
|
||||
|
||||
const workflow = readFileSync(
|
||||
resolve(process.cwd(), ".gitea/workflows/ci.yaml"),
|
||||
"utf8",
|
||||
);
|
||||
const deployStart = workflow.indexOf("\n deploy:");
|
||||
const e2eStart = workflow.indexOf("\n e2e:");
|
||||
const deployJob =
|
||||
deployStart > -1
|
||||
? workflow.slice(deployStart, e2eStart > deployStart ? e2eStart : undefined)
|
||||
: "";
|
||||
|
||||
describe("deploy job", () => {
|
||||
it("runs on self-hosted for Docker access", () => {
|
||||
expect(deployJob).toContain("runs-on: self-hosted");
|
||||
});
|
||||
|
||||
it("has checkout step", () => {
|
||||
expect(deployJob).toContain("actions/checkout@v4");
|
||||
});
|
||||
|
||||
it("builds Docker image with BuildKit", () => {
|
||||
expect(deployJob).toContain("DOCKER_BUILDKIT=1");
|
||||
expect(deployJob).toContain("docker build");
|
||||
expect(deployJob).toContain("-t epicnext-cms:latest");
|
||||
});
|
||||
|
||||
it("builds on host network for registry access", () => {
|
||||
expect(deployJob).toContain("--network=host");
|
||||
});
|
||||
|
||||
it("stops old container before starting new one", () => {
|
||||
expect(deployJob).toContain("docker stop epicnext-cms-app");
|
||||
expect(deployJob).toContain("docker rm epicnext-cms-app");
|
||||
});
|
||||
|
||||
it("starts container with correct settings", () => {
|
||||
expect(deployJob).toContain("--restart always");
|
||||
expect(deployJob).toContain("--net=host");
|
||||
expect(deployJob).toContain("--name epicnext-cms-app");
|
||||
});
|
||||
|
||||
it("provides production .env to the build", () => {
|
||||
expect(deployJob).toContain("cp /var/www/atom-nexst/.env .env");
|
||||
});
|
||||
|
||||
it("runs container with production env and volumes", () => {
|
||||
expect(deployJob).toContain(". /var/www/atom-nexst/.env");
|
||||
// biome-ignore lint/suspicious/noTemplateCurlyInString: intentional literal shell snippet
|
||||
expect(deployJob).toContain('"${ENV_ARGS[@]}"');
|
||||
expect(deployJob).toContain("/var/www/Gamedata:/var/www/Gamedata");
|
||||
expect(deployJob).toContain("/app/storage");
|
||||
});
|
||||
|
||||
it("does not use --env-file (it keeps literal quotes)", () => {
|
||||
expect(deployJob).not.toContain("--env-file");
|
||||
});
|
||||
|
||||
it("frees port 3002 by stopping the compose container", () => {
|
||||
expect(deployJob).toContain("docker stop epicnext-cms 2>/dev/null || true");
|
||||
});
|
||||
|
||||
it("rolls back to compose on health check failure", () => {
|
||||
expect(deployJob).toContain("docker compose");
|
||||
});
|
||||
|
||||
it("runs database migrations before replacing the container", () => {
|
||||
expect(deployJob).toContain("pnpm db:migrate");
|
||||
expect(deployJob.indexOf("pnpm db:migrate")).toBeLessThan(
|
||||
deployJob.indexOf("docker stop epicnext-cms-app"),
|
||||
);
|
||||
});
|
||||
|
||||
it("runs health check", () => {
|
||||
expect(deployJob).toContain("/api/health");
|
||||
expect(deployJob).toContain('"database":true');
|
||||
});
|
||||
|
||||
it("preserves recent build cache and avoids pruning application volumes", () => {
|
||||
expect(deployJob).toContain(
|
||||
'docker builder prune -af --filter "until=72h" --keep-storage=2g',
|
||||
);
|
||||
expect(deployJob).toContain('docker image prune -f --filter "until=168h"');
|
||||
expect(deployJob).not.toContain("docker volume prune");
|
||||
expect(deployJob).not.toContain("docker network prune");
|
||||
expect(deployJob).not.toContain("docker container prune");
|
||||
expect(deployJob).not.toContain("docker image prune -af");
|
||||
});
|
||||
|
||||
it("does not run pnpm test in deploy", () => {
|
||||
expect(deployJob).not.toContain("pnpm test");
|
||||
});
|
||||
|
||||
it("shows docker logs on failure", () => {
|
||||
expect(deployJob).toContain("docker logs epicnext-cms-app");
|
||||
});
|
||||
|
||||
it("exits with error on health check failure", () => {
|
||||
expect(deployJob).toContain("exit 1");
|
||||
});
|
||||
const workflow = readFileSync(".gitea/workflows/ci.yaml", "utf8");
|
||||
const deploy = readFileSync("scripts/ci-deploy.sh", "utf8");
|
||||
it("uses two test workers and runs smoke checks in the deployment transaction", () => {
|
||||
expect(workflow).toContain("pnpm test --maxWorkers=2");
|
||||
expect(workflow).not.toContain("\n e2e:");
|
||||
expect(workflow).toContain("bash scripts/ci-deploy.sh");
|
||||
expect(deploy).toContain(
|
||||
"PLAYWRIGHT_BASE_URL=http://127.0.0.1:3002 pnpm test:e2e",
|
||||
);
|
||||
});
|
||||
it("locks CI and scheduled deployments using the same production lock", () => {
|
||||
expect(deploy).toContain('exec 9>"$deploy_dir/.deploy.lock"');
|
||||
expect(deploy).toContain("flock -w 1800 9");
|
||||
const scheduled = readFileSync("scripts/docker-update.sh", "utf8");
|
||||
expect(scheduled).toContain('exec 9>"$DIR/.deploy.lock"');
|
||||
expect(scheduled.indexOf("flock -w 1800 9")).toBeLessThan(
|
||||
scheduled.indexOf("git pull --ff-only"),
|
||||
);
|
||||
});
|
||||
it("preserves production runtime configuration and recent cache", () => {
|
||||
expect(deploy).toContain("--net=host");
|
||||
expect(deploy).toContain("--restart always");
|
||||
expect(deploy).toContain("/var/www/Gamedata:/var/www/Gamedata");
|
||||
expect(deploy).toContain("/app/storage");
|
||||
expect(deploy).not.toContain("--env-file");
|
||||
expect(deploy).toContain(
|
||||
'docker builder prune -af --filter "until=72h" --keep-storage=2g',
|
||||
);
|
||||
expect(deploy).not.toContain("docker volume prune");
|
||||
});
|
||||
Reference in new issue
Block a user