Files
EpicNext-Cms/.gitea/workflows/ci.yaml
T
openhands 64ad9baf39
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m48s
CI / tests-unit (push) Failing after 1m54s
CI / tests-ui (push) Successful in 2m46s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
fix(deploy): trust the nginx upstream when picking the live slot
The deploy failed with "Expected release never became healthy" after 30
attempts. Root cause: read_active_port() counted the slots answering
/api/health and only consulted the nginx upstream when the count was not
exactly one. On this host both slots were healthy, so it fell back to the
upstream file, but a leftover epicnext-cms:local replica was holding slot A
(3002). The candidate was assigned that occupied port, docker run died with
EADDRINUSE, and the health probe then answered from the pre-existing
container on that port. That container reports release "unknown" because it
was built without NEXT_DEPLOYMENT_ID, so the release comparison could never
match and the deploy timed out blaming a release that was never serving.

read_active_port() now orders its sources by how well they describe reality:

1. The nginx upstream file. It is the only source that says where public
   traffic actually enters; everything below it is a consequence.
2. A healthy slot matching that pointer.
3. The other slot when the pointer names a dead port.
4. The pointer itself when nothing answers, so rollback still has a target.
5. Slot A when no upstream file exists at all.

answers_health() was added as a retry-free sibling of healthy(); port
detection should not spend 90 seconds per slot on a process that is either
running now or never will.

start_candidate() now calls assert_port_free() before docker run, so an
occupied port fails immediately and names the listener and the containers
involved, instead of surfacing later as a misleading health-check timeout.

Added scripts/ci-deploy-ports.test.sh, which extracts the two functions from
the real script rather than copying them, and covers the regression: with
both slots healthy and nginx serving slot B, the result must not be slot A.
Verified the test fails against the old logic and passes against the new.
Wired into the check job so this is caught before an image is built.
2026-10-03 18:22:40 +02:00

208 lines
7.0 KiB
YAML

name: CI
on:
push:
branches: [main, master, "codex/**"]
tags: ["v*"]
pull_request:
branches: [main, master]
workflow_dispatch:
# Reuse the Playwright browsers that ship with the host runner (snapped to
# the root HOME cache instead of a fresh per-job HOME) so `playwright install`
# is a near-instant no-op instead of a ~100s CDN download on every run.
env:
PLAYWRIGHT_BROWSERS_PATH: /opt/ms-playwright
jobs:
# ─────────────────────────────────────────────
# Fast quality gate: toolchain, install, dependabot audit,
# lint, i18n contracts & typecheck. No heavy test suites here.
# Draait op de host (self-hosted) waar Node 26 + pnpm 11
# geïnstalleerd zijn en internet beschikbaar is.
# ─────────────────────────────────────────────
check:
runs-on: self-hosted
steps:
- name: Checkout
uses: actions/checkout@v4
with:
repository: ${{ gitea.repository }}
token: ${{ gitea.token }}
- name: Toolchain check
run: node scripts/check-node-toolchain.mjs
# Port selection decides which blue/green slot stays live. Getting it
# wrong starts the candidate on an occupied port, so the regression that
# caused a failed deploy is covered here, before any image is built.
- name: Deploy port-selection tests
run: bash scripts/ci-deploy-ports.test.sh
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Dependency security audit
run: pnpm deps:audit
- name: Lint
run: pnpm biome:lint
- name: CMS translation contracts
run: pnpm i18n:check
- name: Typecheck
run: pnpm typecheck
# ─────────────────────────────────────────────
# Test suites. Parallel jobs (host runner capacity >= 3) so unit,
# integration and UI tests each get a worker instead of running
# back-to-back inside the check job (~2min wall-time saving).
# ─────────────────────────────────────────────
tests-unit:
needs: check
runs-on: self-hosted
steps:
- name: Checkout
uses: actions/checkout@v4
with:
repository: ${{ gitea.repository }}
token: ${{ gitea.token }}
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Unit & coverage tests
env:
SKIP_ENV_VALIDATION: 1
NODE_ENV: test
DATABASE_URL: "mysql://test:test@localhost:3306/test?charset=utf8mb4"
REDIS_URL: "redis://127.0.0.1:6379?connect_timeout=2"
AUTH_SECRET: "ci-test-secret-key-that-is-long-enough"
BCRYPT_ROUNDS: 4
run: |
if [ -x /usr/bin/time ]; then
/usr/bin/time -f 'Tests: %e seconds; peak process RSS: %M KiB' pnpm test:coverage --maxWorkers=4
else
time pnpm test:coverage --maxWorkers=4
fi
tests-integration:
needs: check
runs-on: self-hosted
steps:
- name: Checkout
uses: actions/checkout@v4
with:
repository: ${{ gitea.repository }}
token: ${{ gitea.token }}
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: MariaDB and Redis integration tests
run: pnpm test:integration
tests-ui:
needs: check
runs-on: self-hosted
steps:
- name: Checkout
uses: actions/checkout@v4
with:
repository: ${{ gitea.repository }}
token: ${{ gitea.token }}
- name: Install dependencies
run: pnpm install --frozen-lockfile
# Compare against reviewed Linux references; updates are explicit.
- name: Install UI test browser
run: pnpm exec playwright install chromium
- name: Accessibility and UI regression checks
run: pnpm test:ui
- name: Upload UI results
if: always()
uses: https://gitea.com/actions/gitea-upload-artifact@62ac910c5d3dfa85c7cb2df15afe2e342b2407c2
with:
name: ui-results
path: |
e2e/ui/__screenshots__/linux/
playwright-report/ui/
test-results/ui/
retention-days: 14
# Validate branch/PR Docker images before integration into a deployment branch.
preflight:
needs: [tests-unit, tests-integration, tests-ui]
if: gitea.event_name == 'pull_request' || (gitea.event_name == 'push' && startsWith(gitea.ref, 'refs/heads/codex/'))
runs-on: self-hosted
steps:
- name: Checkout
uses: actions/checkout@v4
with:
repository: ${{ gitea.repository }}
token: ${{ gitea.token }}
- name: Toolchain check
run: node scripts/check-node-toolchain.mjs
- name: Build and verify isolated candidate
shell: bash
run: bash scripts/ci-preflight.sh
- name: Upload preflight news browser results
if: always()
uses: https://gitea.com/actions/gitea-upload-artifact@62ac910c5d3dfa85c7cb2df15afe2e342b2407c2
with:
name: preflight-news-browser-results
path: |
test-results/news-real/
playwright-report/news-real/
if-no-files-found: warn
retention-days: 14
# ─────────────────────────────────────────────
# Docker build & deploy
# Draait op de host (self-hosted) zodat Docker
# toegang heeft tot de daemon en volumes.
# ─────────────────────────────────────────────
deploy:
needs: [tests-unit, tests-integration, tests-ui]
if: gitea.event_name == 'push' && (gitea.ref_name == 'main' || gitea.ref_name == 'master')
runs-on: self-hosted
steps:
- name: Checkout
uses: actions/checkout@v4
with:
repository: ${{ gitea.repository }}
token: ${{ gitea.token }}
- name: Build, deploy and smoke test
shell: bash
env:
DEPLOY_BRANCH: ${{ gitea.ref_name }}
run: bash scripts/ci-deploy.sh
- name: Upload isolated news browser results
if: always()
uses: https://gitea.com/actions/gitea-upload-artifact@62ac910c5d3dfa85c7cb2df15afe2e342b2407c2
with:
name: news-browser-results
path: |
test-results/news-real/
playwright-report/news-real/
if-no-files-found: warn
retention-days: 14
- name: Upload JavaScript size report
if: always()
uses: https://gitea.com/actions/gitea-upload-artifact@62ac910c5d3dfa85c7cb2df15afe2e342b2407c2
with:
name: javascript-size-report
path: build-reports/
if-no-files-found: warn
retention-days: 14