name: Test on: workflow_dispatch: pull_request: push: branches: [main] concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true permissions: contents: read jobs: test: name: Test runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup pnpm uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - name: Setup Node uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version-file: '.nvmrc' - name: Run pnpm install run: pnpm install --frozen-lockfile - name: Run linter run: pnpm run lint if: ${{ !cancelled() }} - name: Run formatter run: pnpm run format if: ${{ !cancelled() }} - name: Run tsc run: pnpm run check if: ${{ !cancelled() }} - name: Run unit tests run: pnpm run test if: ${{ !cancelled() }} terraform-lock-files: name: Terraform lock files runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Check every module has a committed lock file run: ./deployment/scripts/check-lock-files.sh integration-test-cloudflare-metrics: name: Integration Test (cloudflare-metrics) runs-on: ubuntu-latest permissions: contents: read pull-requests: read # dorny/paths-filter reads changed files via the API on pull_request steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Detect relevant changes id: changes uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 with: filters: | cloudflare-metrics: - 'apps/cloudflare-metrics/**' - '.github/workflows/test.yml' - name: Setup pnpm if: steps.changes.outputs.cloudflare-metrics == 'true' || github.event_name != 'pull_request' uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - name: Setup Node if: steps.changes.outputs.cloudflare-metrics == 'true' || github.event_name != 'pull_request' uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version-file: '.nvmrc' - name: Run pnpm install if: steps.changes.outputs.cloudflare-metrics == 'true' || github.event_name != 'pull_request' run: pnpm install --frozen-lockfile - name: Install 1Password CLI if: steps.changes.outputs.cloudflare-metrics == 'true' || github.event_name != 'pull_request' uses: 1password/install-cli-action@1a3160d5e9de1ae0803eaa08a88746f5ae3daa50 # v4.1.0 - name: Check integration credentials are available id: creds if: steps.changes.outputs.cloudflare-metrics == 'true' || github.event_name != 'pull_request' continue-on-error: true env: OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_DEV_ENV }} run: | if op run --env-file=apps/cloudflare-metrics/.integration.env -- sh -c 'test -n "$CLOUDFLARE_API_TOKEN" && test -n "$CLOUDFLARE_ACCOUNT_ID"' 2>/dev/null; then echo "available=true" >> "$GITHUB_OUTPUT" else echo "available=false" >> "$GITHUB_OUTPUT" echo "::warning::Skipping integration test — credentials not configured in 1Password" fi - name: Run integration tests if: >- (steps.changes.outputs.cloudflare-metrics == 'true' || github.event_name != 'pull_request') && steps.creds.outputs.available == 'true' env: OP_SERVICE_ACCOUNT_TOKEN: ${{ secrets.OP_TF_DEV_ENV }} run: | op run \ --env-file=apps/cloudflare-metrics/.integration.env \ -- pnpm --filter @immich-services/cloudflare-metrics run test:integration