mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
158 lines
5.3 KiB
TOML
158 lines
5.3 KiB
TOML
monorepo_root = true
|
|
|
|
[monorepo]
|
|
config_roots = [
|
|
"ansible/ceph",
|
|
"ansible/talos",
|
|
"packages/common",
|
|
"packages/docs",
|
|
"packages/emails",
|
|
"packages/futo-backups-bot",
|
|
"packages/restic-proxy",
|
|
"packages/standalone-app",
|
|
"packages/web",
|
|
"packages/yucca-admin-api",
|
|
"packages/yucca-api",
|
|
"packages/yucca-api-client",
|
|
"packages/yucca-metrics-worker",
|
|
"packages/yucca-sdk/orchestration-api",
|
|
"packages/yucca-sdk/orchestration-ui",
|
|
]
|
|
|
|
[tools]
|
|
node = "25.9.0"
|
|
pnpm = "10.28.1"
|
|
wrangler = "4.127.0"
|
|
go = "1.27.1"
|
|
golangci-lint = "2.13.2"
|
|
restic = "0.19.1"
|
|
|
|
gh = "2.100.0"
|
|
"github:git-town/git-town" = "22.7.1"
|
|
|
|
k3d = "5.9.0"
|
|
kubectl = "1.37.0"
|
|
helm = "3.22.0"
|
|
tilt = "0.37.7"
|
|
|
|
# Static validation of the k8s surface (mise run k8s:validate, used by CI).
|
|
# flux-local runs via `uvx` (see .mise/tasks/k8s/validate): uv auto-fetches a
|
|
# Python matching its requires-python, so the host's Python version (3.12 on
|
|
# GitHub runners, 3.14 on dev machines) doesn't matter.
|
|
kubeconform = "0.8.0"
|
|
kustomize = "5.8.1" # flux-local shells out to it
|
|
flux2 = "2.9.5" # ...and to the flux CLI
|
|
uv = "0.12.12"
|
|
|
|
# github backend: the aqua backend fails to verify cosign v3's sigstore
|
|
# bundles ("No bundle found in attestation").
|
|
"github:sigstore/cosign" = "v3.1.3"
|
|
"github:grafana/dashboard-linter" = "v0.3.0"
|
|
|
|
# Infrastructure tooling (added for tf/ and ansible/ subtrees)
|
|
opentofu = "1.12.6"
|
|
terragrunt = "0.99.5"
|
|
# ansible/mgmt convergence (mgmt:ansible task, run from CI on prod apply).
|
|
"pipx:ansible-core" = "2.21.4"
|
|
|
|
[tasks.dev]
|
|
description = "Start all services in development mode"
|
|
depends = ["install:deps", "common:build", "docker:start"]
|
|
run = [
|
|
{ tasks = [
|
|
"michael:dev",
|
|
"//packages/restic-proxy:dev",
|
|
"//packages/web:dev",
|
|
"//packages/yucca-admin-api:dev",
|
|
"//packages/yucca-api:dev",
|
|
"//packages/yucca-metrics-worker:dev",
|
|
"//packages/yucca-sdk/orchestration-api:dev",
|
|
"//packages/yucca-sdk/orchestration-ui:dev",
|
|
] },
|
|
]
|
|
|
|
[tasks.build]
|
|
description = "Build all packages"
|
|
depends = ["*:build", "//packages/...:build"]
|
|
|
|
[tasks."common:build"]
|
|
description = "Build all common packages"
|
|
run = [{ task = "install:deps" }, { tasks = ["//packages/common:build", "//packages/emails:build"] }]
|
|
|
|
[tasks.test]
|
|
description = "Run all unit tests"
|
|
depends = ["*:test", "//packages/...:test"]
|
|
|
|
[tasks."test:integration"]
|
|
description = "Run all integration tests"
|
|
# NB: mise flags must precede the task pattern — anything after it is forwarded
|
|
# to the tasks themselves (jest/go test choke on a stray --jobs).
|
|
run = "mise run --jobs 1 '*:test:integration' ::: '//packages/...:test:integration'"
|
|
|
|
[tasks."test:e2e:web"]
|
|
description = "Run all web e2e tests"
|
|
run = [{ task = "test:e2e:wait" }, { task = "//packages/...:test:e2e:web" }]
|
|
|
|
[tasks."prepare"]
|
|
description = "Install and build packages"
|
|
run = [{ task = "install:frozen" }, { task = "build" }]
|
|
|
|
[tasks."check"]
|
|
description = "Run checks & unit tests"
|
|
run = [{ tasks = ["lint", "lint:go", "//packages/...:check"] }, { task = "format" }, { task = "test" }]
|
|
|
|
[tasks.fix]
|
|
description = "Run all possible code fixes"
|
|
run = [{ task = "*:fix" }, { task = "//packages/web:lingui" }]
|
|
|
|
[tasks."o11y:render"]
|
|
description = "Render the o11y bundle"
|
|
usage = '''
|
|
arg "<output-dir>" default="/tmp/yucca-o11y"
|
|
arg "<repo>" default="immich-app/yucca"
|
|
'''
|
|
run = '.github/scripts/render-o11y-manifests.sh "${usage_output_dir?}" "${usage_repo?}"'
|
|
|
|
[tasks."o11y:lint"]
|
|
description = "Lint dashboards"
|
|
run = "for f in o11y/dashboards/*.json; do dashboard-linter lint --strict \"$f\"; done"
|
|
|
|
# ─── Infrastructure (tf + ansible) ──────────────────────────────────────────
|
|
# tf:* tasks wrap terragrunt with tf/op-run.sh, which injects secrets from
|
|
# tf/.env via 1Password (op run) and appends a clear "unlock 1Password" hint
|
|
# when op can't authorize, instead of letting terragrunt die on empty creds.
|
|
# No literal secrets in the .env file — just op:// references.
|
|
|
|
[tasks."tf:init"]
|
|
description = "Terragrunt init for a given stack (default: deployment/staging/austin/ceph)"
|
|
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/staging/austin/ceph} init"
|
|
|
|
[tasks."tf:plan"]
|
|
description = "Terragrunt plan for a given stack"
|
|
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/staging/austin/ceph} plan"
|
|
|
|
[tasks."tf:apply"]
|
|
description = "Terragrunt apply for a given stack"
|
|
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/staging/austin/ceph} apply"
|
|
|
|
[tasks."tf:destroy"]
|
|
description = "Terragrunt destroy for a given stack (use with care)"
|
|
run = "tf/op-run.sh terragrunt --working-dir ${TF_STACK_DIR:-tf/deployment/staging/austin/ceph} destroy"
|
|
|
|
[tasks."tf:fmt"]
|
|
description = "Format terraform + terragrunt files recursively"
|
|
run = "tofu fmt -recursive tf/ && terragrunt hcl format --working-dir tf/"
|
|
|
|
[tasks."tf:check-dns-roster"]
|
|
description = "Drift-check the prod S3 RGW DNS roster against the ceph node roster (credential-free, no state)"
|
|
run = "tf/scripts/check-s3-dns-roster.py"
|
|
|
|
[env]
|
|
NODE_ENV = "development"
|
|
LOG_LEVEL = "debug"
|
|
|
|
OTLP_METRICS_ENDPOINT = "localhost:8428"
|
|
OTLP_METRICS_URL_PATH = "/opentelemetry/v1/metrics"
|
|
OTLP_LOGS_ENDPOINT = "localhost:9428"
|
|
OTLP_LOGS_URL_PATH = "/insert/opentelemetry/v1/logs"
|