2.2 KiB
Docker and news checks before merging
Push work to a codex/** branch and open a pull request targeting main or master. CI runs the existing check job first. After it passes, the new preflight job builds the production Dockerfile and runs the isolated news browser suite against that exact image. Review both results before merging; repository branch protection can require check and preflight for pull requests.
Each execution uses epicnext-cms:preflight-<commit>-<random suffix>, including retries and separate push/PR runs of the same commit. The full checked-out commit is passed as NEXT_DEPLOYMENT_ID and NEWS_E2E_RELEASE; NEWS_E2E_IMAGE identifies that execution's image. Failures in dependency/browser setup, Docker build, news tests or cleanup fail the job. News browser artifacts are uploaded even when the gate fails.
The script installs dependencies with the frozen lockfile and installs Chromium on the CI runner. The real Docker build uses the existing Dockerfile's fixture build settings. It never copies or sources a deployment .env, connects to a VPS, runs live migrations, updates live containers, publishes a registry image or changes release tags. The existing isolated news runner owns its disposable MariaDB, Redis and application containers. Cleanup removes only the preflight tag and its empty private temporary directory; it does not prune Docker resources.
The deploy and publish-container conditions remain restricted to pushes on main/master. Deployment still runs its own news gate before live migrations/cutover. A successful branch preflight supplies earlier evidence; the deployed commit is independently checked again.
On a Linux development or CI host with the project toolchain, Docker Engine and normal browser prerequisites, the same gate can be run from a clean checkout:
bash scripts/ci-preflight.sh
Shell orchestration is covered by pnpm exec vitest run --coverage.enabled=false src/lib/ci-preflight.test.ts. Those tests execute the real shell script with external command boundaries simulated; they prove ordering, failure propagation, unique tags and cleanup scope. They do not build an image or run the news browser suite. The branch/PR CI job provides that Docker/browser evidence.