Files
yucca/.github/workflows/ci.yml
T

156 lines
6.4 KiB
YAML

name: ci
on:
pull_request:
push:
branches: [main]
# Every job only reads the repo (checkout + tool downloads); nothing writes
# back through the token.
permissions:
contents: read
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
checks:
name: Checks & Unit Tests
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
with:
persist-credentials: false
- name: Setup Mise
uses: immich-app/devtools/actions/use-mise@cd24790a7f5f6439ac32cc94f5523cb2de8bfa8c # use-mise-action-v1.1.0
env:
# mise downloads tools from GitHub releases; anonymous requests hit
# API rate limits with four parallel jobs.
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- run: mise prepare
- name: Run checks
run: mise check
k8s-validate:
name: Validate Kubernetes Surface
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
with:
persist-credentials: false
- name: Setup Mise
uses: immich-app/devtools/actions/use-mise@cd24790a7f5f6439ac32cc94f5523cb2de8bfa8c # use-mise-action-v1.1.0
env:
# mise downloads tools from GitHub releases; anonymous requests hit
# API rate limits with four parallel jobs.
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# helm template + kubeconform per chart, then flux-local builds the whole
# kubernetes/ tree the way Flux would. No cluster involved. One retry:
# flux-local downloads third-party charts (rook is still a classic
# HelmRepository) and a transient network reset shouldn't fail the build.
- name: Validate charts + Flux tree
run: mise run k8s:validate || { echo "::warning::k8s:validate failed once (transient chart fetch?); retrying"; mise run k8s:validate; }
integration:
name: Integration Tests
runs-on: ubuntu-latest
timeout-minutes: 40
steps:
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
with:
persist-credentials: false
- name: Setup Mise
uses: immich-app/devtools/actions/use-mise@cd24790a7f5f6439ac32cc94f5523cb2de8bfa8c # use-mise-action-v1.1.0
env:
# mise downloads tools from GitHub releases; anonymous requests hit
# API rate limits with four parallel jobs.
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# The stack (dev images, k3s) is heavy; the stock runner has ~14GB free,
# so drop the biggest unused toolchains up front.
- name: Free runner disk space
run: sudo rm -rf /usr/local/lib/android /usr/share/dotnet /opt/ghc || true
# Cluster bring-up and the workspace install touch none of the same files,
# so they overlap. Only the @common/* libs are built: the suites run from
# TypeScript source via ts-jest, so `mise prepare`'s other packages are
# never loaded here.
- name: Stand up k3d infra, install deps and build shared libs
run: |
( mise k3d:up && mise tilt:ci-infra ) > /tmp/k3d-infra.log 2>&1 &
infra=$!
mise run install:frozen
mise run common:server:build
mise run common:emails:build
wait "$infra" || { echo "::error::k3d infra failed"; cat /tmp/k3d-infra.log; exit 1; }
echo "::group::k3d infra log"; cat /tmp/k3d-infra.log; echo "::endgroup::"
- name: Run integration tests against the cluster
run: mise test:integration:k3d
e2e:
name: End-to-end Tests
# This job hosts the whole k3d stack — Ceph, postgres, michael, a vite dev
# server — and runs restic against it. Both halves are CPU-bound, so the
# 4-vCPU hosted runner starved them; pokedex-large is 8 cores / 32 GB.
runs-on: pokedex-large
timeout-minutes: 60
env:
# restic runs on the runner, so yucca-api must advertise a localhost
# rest_url; rendering it that way up front spares a yucca-api rollout.
YUCCA_TOPOLOGY_LOCAL_REST: '1'
YUCCA_E2E_PREBUILT: '1'
steps:
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
with:
persist-credentials: false
- name: Setup Mise
uses: immich-app/devtools/actions/use-mise@cd24790a7f5f6439ac32cc94f5523cb2de8bfa8c # use-mise-action-v1.1.0
env:
# mise downloads tools from GitHub releases; anonymous requests hit
# API rate limits with four parallel jobs.
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# Paths from the GitHub-hosted image; absent on a self-hosted runner, and
# -n so a runner without passwordless sudo fails instead of hanging.
- name: Free runner disk space
run: sudo -n rm -rf /usr/local/lib/android /usr/share/dotnet /opt/ghc || true
- name: Create the k3d cluster
run: mise k3d:up
# Rook-Ceph converging is the long pole of this job and is nearly all
# waiting. `tilt:ci-ceph` builds no images, so unlike the full stack it
# never tars the workspace and cannot race the build writing into it —
# which is what makes running these together safe.
- name: Start Ceph converging while installing deps and Playwright
run: |
( mise tilt:ci-ceph ) > /tmp/k3d-ceph.log 2>&1 &
ceph=$!
mise run install:frozen
pnpm --filter web exec playwright install --with-deps chromium > /tmp/playwright.log 2>&1 &
playwright=$!
mise run build
wait "$playwright" || { echo "::error::playwright install failed"; cat /tmp/playwright.log; exit 1; }
wait "$ceph" || { echo "::error::Ceph failed to converge"; cat /tmp/k3d-ceph.log; exit 1; }
echo "::group::Ceph bring-up log"; cat /tmp/k3d-ceph.log; echo "::endgroup::"
# Images build here while Rook finishes; yucca-michael mounts the
# object-user Secret, so this is where the job blocks on Ceph serving S3.
- name: Deploy the app stack
run: mise tilt:ci-e2e
# Here rather than in the integration job because this stack already runs
# Ceph, and standing a second one up there cost more than its whole suite.
- name: Run S3-backed integration tests against the cluster
run: mise test:integration:s3
- name: Run end-to-end tests against the cluster
run: mise test:e2e:k3d