mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
156 lines
6.4 KiB
YAML
156 lines
6.4 KiB
YAML
name: ci
|
|
|
|
on:
|
|
pull_request:
|
|
push:
|
|
branches: [main]
|
|
|
|
# Every job only reads the repo (checkout + tool downloads); nothing writes
|
|
# back through the token.
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: ci-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
checks:
|
|
name: Checks & Unit Tests
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Mise
|
|
uses: immich-app/devtools/actions/use-mise@cd24790a7f5f6439ac32cc94f5523cb2de8bfa8c # use-mise-action-v1.1.0
|
|
env:
|
|
# mise downloads tools from GitHub releases; anonymous requests hit
|
|
# API rate limits with four parallel jobs.
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
- run: mise prepare
|
|
|
|
- name: Run checks
|
|
run: mise check
|
|
|
|
k8s-validate:
|
|
name: Validate Kubernetes Surface
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
steps:
|
|
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Mise
|
|
uses: immich-app/devtools/actions/use-mise@cd24790a7f5f6439ac32cc94f5523cb2de8bfa8c # use-mise-action-v1.1.0
|
|
env:
|
|
# mise downloads tools from GitHub releases; anonymous requests hit
|
|
# API rate limits with four parallel jobs.
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
# helm template + kubeconform per chart, then flux-local builds the whole
|
|
# kubernetes/ tree the way Flux would. No cluster involved. One retry:
|
|
# flux-local downloads third-party charts (rook is still a classic
|
|
# HelmRepository) and a transient network reset shouldn't fail the build.
|
|
- name: Validate charts + Flux tree
|
|
run: mise run k8s:validate || { echo "::warning::k8s:validate failed once (transient chart fetch?); retrying"; mise run k8s:validate; }
|
|
|
|
integration:
|
|
name: Integration Tests
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 40
|
|
steps:
|
|
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Mise
|
|
uses: immich-app/devtools/actions/use-mise@cd24790a7f5f6439ac32cc94f5523cb2de8bfa8c # use-mise-action-v1.1.0
|
|
env:
|
|
# mise downloads tools from GitHub releases; anonymous requests hit
|
|
# API rate limits with four parallel jobs.
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
# The stack (dev images, k3s) is heavy; the stock runner has ~14GB free,
|
|
# so drop the biggest unused toolchains up front.
|
|
- name: Free runner disk space
|
|
run: sudo rm -rf /usr/local/lib/android /usr/share/dotnet /opt/ghc || true
|
|
|
|
# Cluster bring-up and the workspace install touch none of the same files,
|
|
# so they overlap. Only the @common/* libs are built: the suites run from
|
|
# TypeScript source via ts-jest, so `mise prepare`'s other packages are
|
|
# never loaded here.
|
|
- name: Stand up k3d infra, install deps and build shared libs
|
|
run: |
|
|
( mise k3d:up && mise tilt:ci-infra ) > /tmp/k3d-infra.log 2>&1 &
|
|
infra=$!
|
|
mise run install:frozen
|
|
mise run common:server:build
|
|
mise run common:emails:build
|
|
wait "$infra" || { echo "::error::k3d infra failed"; cat /tmp/k3d-infra.log; exit 1; }
|
|
echo "::group::k3d infra log"; cat /tmp/k3d-infra.log; echo "::endgroup::"
|
|
|
|
- name: Run integration tests against the cluster
|
|
run: mise test:integration:k3d
|
|
|
|
e2e:
|
|
name: End-to-end Tests
|
|
# This job hosts the whole k3d stack — Ceph, postgres, michael, a vite dev
|
|
# server — and runs restic against it. Both halves are CPU-bound, so the
|
|
# 4-vCPU hosted runner starved them; pokedex-large is 8 cores / 32 GB.
|
|
runs-on: pokedex-large
|
|
timeout-minutes: 60
|
|
env:
|
|
# restic runs on the runner, so yucca-api must advertise a localhost
|
|
# rest_url; rendering it that way up front spares a yucca-api rollout.
|
|
YUCCA_TOPOLOGY_LOCAL_REST: '1'
|
|
YUCCA_E2E_PREBUILT: '1'
|
|
steps:
|
|
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Mise
|
|
uses: immich-app/devtools/actions/use-mise@cd24790a7f5f6439ac32cc94f5523cb2de8bfa8c # use-mise-action-v1.1.0
|
|
env:
|
|
# mise downloads tools from GitHub releases; anonymous requests hit
|
|
# API rate limits with four parallel jobs.
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
# Paths from the GitHub-hosted image; absent on a self-hosted runner, and
|
|
# -n so a runner without passwordless sudo fails instead of hanging.
|
|
- name: Free runner disk space
|
|
run: sudo -n rm -rf /usr/local/lib/android /usr/share/dotnet /opt/ghc || true
|
|
|
|
- name: Create the k3d cluster
|
|
run: mise k3d:up
|
|
|
|
# Rook-Ceph converging is the long pole of this job and is nearly all
|
|
# waiting. `tilt:ci-ceph` builds no images, so unlike the full stack it
|
|
# never tars the workspace and cannot race the build writing into it —
|
|
# which is what makes running these together safe.
|
|
- name: Start Ceph converging while installing deps and Playwright
|
|
run: |
|
|
( mise tilt:ci-ceph ) > /tmp/k3d-ceph.log 2>&1 &
|
|
ceph=$!
|
|
mise run install:frozen
|
|
pnpm --filter web exec playwright install --with-deps chromium > /tmp/playwright.log 2>&1 &
|
|
playwright=$!
|
|
mise run build
|
|
wait "$playwright" || { echo "::error::playwright install failed"; cat /tmp/playwright.log; exit 1; }
|
|
wait "$ceph" || { echo "::error::Ceph failed to converge"; cat /tmp/k3d-ceph.log; exit 1; }
|
|
echo "::group::Ceph bring-up log"; cat /tmp/k3d-ceph.log; echo "::endgroup::"
|
|
|
|
# Images build here while Rook finishes; yucca-michael mounts the
|
|
# object-user Secret, so this is where the job blocks on Ceph serving S3.
|
|
- name: Deploy the app stack
|
|
run: mise tilt:ci-e2e
|
|
|
|
# Here rather than in the integration job because this stack already runs
|
|
# Ceph, and standing a second one up there cost more than its whole suite.
|
|
- name: Run S3-backed integration tests against the cluster
|
|
run: mise test:integration:s3
|
|
|
|
- name: Run end-to-end tests against the cluster
|
|
run: mise test:e2e:k3d
|