140 lines
5.4 KiB
YAML
140 lines
5.4 KiB
YAML
name: MobilityOps acceptance
|
|
|
|
on:
|
|
push:
|
|
branches: [master]
|
|
pull_request:
|
|
schedule:
|
|
- cron: "17 3 * * 1"
|
|
|
|
concurrency:
|
|
group: mobilityops-ci-${{ gitea.repository }}-${{ gitea.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
backend:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
|
- name: Secret scan
|
|
uses: trufflesecurity/trufflehog@b9dd330365132cd2d01dd5dc8a857a056a2544e1 # v3.79.0
|
|
with:
|
|
path: ./
|
|
extra_args: --only-verified
|
|
- name: Backend tests in isolated PostgreSQL stack
|
|
run: sh scripts/run-isolated-tests.sh
|
|
- name: Backend static checks
|
|
run: |
|
|
docker compose -p mobilityops-ci -f compose.yaml -f compose.test.yaml run --build --rm api ruff check app tests
|
|
docker compose -p mobilityops-ci -f compose.yaml -f compose.test.yaml run --rm api mypy app
|
|
- name: Contract drift gate
|
|
run: |
|
|
docker compose -p mobilityops-ci -f compose.yaml -f compose.test.yaml run --rm \
|
|
-v "$PWD:/repo:ro" api python /repo/scripts/check-contracts.py
|
|
python scripts/check-source-budgets.py
|
|
- name: Build production API image for vulnerability scan
|
|
run: |
|
|
docker build --target runtime --build-arg VCS_REF="$GITHUB_SHA" \
|
|
--tag mobilityops-api-ci --file backend/Dockerfile .
|
|
- name: Production API image vulnerability scan (HIGH/CRITICAL)
|
|
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30.0
|
|
with:
|
|
scan-type: image
|
|
image-ref: mobilityops-api-ci
|
|
format: table
|
|
severity: HIGH,CRITICAL
|
|
exit-code: "1"
|
|
ignore-unfixed: true
|
|
- name: Build production web image for vulnerability scan
|
|
run: |
|
|
docker build --build-arg VCS_REF="$GITHUB_SHA" \
|
|
--tag mobilityops-web-ci frontend
|
|
- name: Production web image vulnerability scan (HIGH/CRITICAL)
|
|
uses: aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30.0
|
|
with:
|
|
scan-type: image
|
|
image-ref: mobilityops-web-ci
|
|
format: table
|
|
severity: HIGH,CRITICAL
|
|
exit-code: "1"
|
|
ignore-unfixed: true
|
|
- name: Remove CI stack
|
|
if: always()
|
|
run: docker compose -p mobilityops-ci -f compose.yaml -f compose.test.yaml down -v --remove-orphans
|
|
|
|
frontend:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
|
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
|
|
with:
|
|
node-version: 22
|
|
cache: npm
|
|
cache-dependency-path: frontend/package-lock.json
|
|
- name: Install locked dependencies
|
|
working-directory: frontend
|
|
run: npm ci --no-audit --no-fund
|
|
- name: Lint (tsc + ESLint with react-hooks and jsx-a11y)
|
|
working-directory: frontend
|
|
run: npm run lint
|
|
- name: Typecheck and production build
|
|
working-directory: frontend
|
|
run: npm run build && npm run budget
|
|
- name: Dependency audit
|
|
working-directory: frontend
|
|
run: npm audit --audit-level=high
|
|
|
|
e2e:
|
|
# The five-minute Playwright demo is part of the definition of done
|
|
# (docs/14-testing-and-acceptance.md); run it against the real Compose stack.
|
|
runs-on: ubuntu-latest
|
|
needs: [backend, frontend]
|
|
steps:
|
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
|
|
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
|
|
with:
|
|
node-version: 22
|
|
cache: npm
|
|
cache-dependency-path: frontend/package-lock.json
|
|
- name: Start the demo stack
|
|
run: |
|
|
cp .env.example .env
|
|
docker compose -p mobilityops-e2e up --build -d db api web
|
|
for _attempt in $(seq 1 60); do
|
|
if curl -fsS http://localhost:1228/health/ready >/dev/null 2>&1; then break; fi
|
|
sleep 2
|
|
done
|
|
curl -fsS http://localhost:1228/health/ready
|
|
docker compose -p mobilityops-e2e exec -T api python -m app.cli seed --reset
|
|
- name: Install Playwright
|
|
working-directory: frontend
|
|
run: |
|
|
npm ci --no-audit --no-fund
|
|
npx playwright install --with-deps chromium firefox
|
|
- name: Run browser acceptance suite
|
|
working-directory: frontend
|
|
env:
|
|
MOBILITYOPS_PUBLIC_URL: http://localhost:1228
|
|
run: npx playwright test
|
|
- name: Run non-destructive Chromium and Firefox smoke suite
|
|
working-directory: frontend
|
|
env:
|
|
MOBILITYOPS_PUBLIC_URL: http://localhost:1228
|
|
run: npx playwright test --config=playwright.live.config.ts
|
|
- name: Run concurrent persisted-read smoke
|
|
run: python scripts/run-readonly-load-smoke.py --base-url http://localhost:1228
|
|
- name: Upload Playwright report
|
|
if: failure()
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
|
|
with:
|
|
name: playwright-report
|
|
path: |
|
|
frontend/playwright-report
|
|
frontend/playwright-live-report
|
|
- name: Stack logs on failure
|
|
if: failure()
|
|
run: docker compose -p mobilityops-e2e logs --tail=200 api web
|
|
- name: Remove e2e stack
|
|
if: always()
|
|
run: docker compose -p mobilityops-e2e down -v --remove-orphans
|