Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
139 lines
5.0 KiB
YAML
139 lines
5.0 KiB
YAML
name: Tests
|
|
|
|
# Shared by test.yml (push/PR) and deploy.yml (tags). These jobs used to be
|
|
# copy-pasted between the two, which is how the go-test cache bug survived in
|
|
# one copy after being noticed in the other.
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
release-certs:
|
|
description: Use the long-lived TTL certs from secrets instead of generating throwaway ones. Tag builds only.
|
|
type: boolean
|
|
default: false
|
|
skip-staticcheck:
|
|
description: Skip staticcheck. Tag builds set this so a lint failure cannot block a release, matching what deploy.yml gated on before these jobs were shared.
|
|
type: boolean
|
|
default: false
|
|
secrets:
|
|
TTL_KEY:
|
|
required: false
|
|
TTL_CERT:
|
|
required: false
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
npm-test:
|
|
name: JavaScript Tests
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
name: Install Node
|
|
with:
|
|
node-version: latest
|
|
- run: npm install --global corepack@latest
|
|
- run: corepack enable
|
|
- run: pnpm --version
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: latest
|
|
cache: "pnpm"
|
|
cache-dependency-path: "**/pnpm-lock.yaml"
|
|
- name: Install dependencies
|
|
run: pnpm install --frozen-lockfile --prefer-offline
|
|
- name: Run Typecheck
|
|
run: pnpm run typecheck
|
|
# Runs even when typecheck fails, so one job still reports both signals
|
|
- name: Run Tests
|
|
if: ${{ !cancelled() }}
|
|
run: pnpm run test -- --outputTruncateLength=500
|
|
|
|
go-test:
|
|
name: Go Tests
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
# Checkout must come first so setup-go can key its module/build cache on go.sum
|
|
- name: Checkout code
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
- name: Install Go
|
|
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
|
with:
|
|
go-version: "1.26.6"
|
|
check-latest: true
|
|
- name: Run Go Tests with Coverage
|
|
run: make test-ci
|
|
|
|
staticcheck:
|
|
name: Go Staticcheck
|
|
runs-on: ubuntu-latest
|
|
if: ${{ !inputs.skip-staticcheck }}
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
- name: Setup Go
|
|
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
|
|
with:
|
|
go-version: "1.26.6"
|
|
check-latest: true
|
|
# This job shares a cache key with go-test (go version + go.sum hash) and
|
|
# setup-go only writes on a miss. Staticcheck is much faster, so it always
|
|
# won the race to populate, and its build cache has no -race artifacts in
|
|
# it, which made the restore worthless for go-test. Let go-test own the key.
|
|
cache: false
|
|
- name: Generate dependencies
|
|
run: make fake_assets shared_key.pem shared_cert.pem
|
|
- name: Stactic checker
|
|
uses: dominikh/staticcheck-action@9716614d4101e79b4340dd97b10e54d68234e431 # v1.4.1
|
|
with:
|
|
install-go: false
|
|
|
|
int-test:
|
|
name: Integration Tests
|
|
timeout-minutes: 60
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
name: Install Node
|
|
with:
|
|
node-version: latest
|
|
- run: npm install --global corepack@latest
|
|
- run: corepack enable
|
|
- run: pnpm --version
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: latest
|
|
cache: "pnpm"
|
|
cache-dependency-path: "**/pnpm-lock.yaml"
|
|
- name: Install dependencies
|
|
run: pnpm install --frozen-lockfile --prefer-offline
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
|
|
- name: Generate certs
|
|
if: ${{ !inputs.release-certs }}
|
|
run: make shared_key.pem shared_cert.pem
|
|
- name: Writing certs to file
|
|
if: ${{ inputs.release-certs }}
|
|
run: |
|
|
echo "${{ secrets.TTL_KEY }}" > shared_key.pem
|
|
echo "${{ secrets.TTL_CERT }}" > shared_cert.pem
|
|
- name: Build
|
|
uses: docker/bake-action@d3418bd7d0e9324001bca92fa8ba175ea7e6dc9b # v7.3.0
|
|
with:
|
|
source: .
|
|
load: true
|
|
set: |
|
|
*.cache-from=type=gha
|
|
*.cache-to=type=gha,mode=max
|
|
- name: Run Playwright tests
|
|
run: docker compose up --exit-code-from playwright
|
|
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
if: always()
|
|
with:
|
|
name: playwright-report
|
|
path: playwright-report/
|
|
retention-days: 30
|