name: CI on: push: branches: [main] pull_request: branches: [main, breaking/**] workflow_dispatch: permissions: contents: read # Cancel outdated runs of a pull request but test every commit on main concurrency: group: ci-${{ github.event_name == 'pull_request' && github.event.pull_request.number || github.sha }} cancel-in-progress: ${{ github.event_name == 'pull_request' }} jobs: changes: name: Detect changes runs-on: ubuntu-latest permissions: contents: read pull-requests: read outputs: backend: ${{ steps.filter.outputs.backend }} frontend: ${{ steps.filter.outputs.frontend }} e2e: ${{ steps.filter.outputs.e2e }} locale-files: ${{ steps.filter.outputs.locale-files }} steps: - name: Detect changed areas id: filter env: GH_TOKEN: ${{ github.token }} REPO: ${{ github.repository }} EVENT_NAME: ${{ github.event_name }} PR_NUMBER: ${{ github.event.pull_request.number }} BEFORE: ${{ github.event.before }} SHA: ${{ github.sha }} run: | # List the changed files, including the old path of renamed files all=false files="" case "$EVENT_NAME" in pull_request) files=$(gh api --paginate "repos/$REPO/pulls/$PR_NUMBER/files" --jq '.[] | .filename, (.previous_filename // empty)') ;; push) # The compare API fails for force pushes and new branches, so fall back to running everything files=$(gh api --paginate "repos/$REPO/compare/$BEFORE...$SHA" --jq '.files[]? | .filename, (.previous_filename // empty)') || all=true ;; *) all=true ;; esac # A change to the CI definition itself has to be validated by every job if grep -q -x '.github/workflows/ci.yml' <<< "$files"; then all=true fi matches() { [ "$all" = true ] || grep -q -E "$1" <<< "$2" } # Translated locales only come from Crowdin and don't affect the English end-to-end tests e2e_files=$(grep -v -E '^(docs/|\.github/)|\.md$|^frontend/messages/.+\.json$' <<< "$files" || true) e2e_files+=$'\n'$(grep -x 'frontend/messages/en.json' <<< "$files" || true) { matches '^backend/' "$files" && echo "backend=true" || echo "backend=false" matches '^(frontend/|package\.json$|pnpm-lock\.yaml$|pnpm-workspace\.yaml$|\.node-version$|vite\.config\.ts$|\.github/svelte-check-matcher\.json$)' "$files" && echo "frontend=true" || echo "frontend=false" matches '.' "$e2e_files" && echo "e2e=true" || echo "e2e=false" } >> "$GITHUB_OUTPUT" # Every locale except en.json is committed to main by the Crowdin download workflow, so pull requests must not change them if [ "$EVENT_NAME" = pull_request ]; then locale_files=$(grep -E '^frontend/messages/.+\.json$' <<< "$files" | grep -v -x 'frontend/messages/en.json' | sort -u | tr '\n' ' ' || true) echo "locale-files=${locale_files% }" >> "$GITHUB_OUTPUT" fi cat "$GITHUB_OUTPUT" translations: name: Translations needs: changes if: needs.changes.outputs.locale-files != '' runs-on: ubuntu-latest steps: - name: Reject changes to translated locales env: LOCALE_FILES: ${{ needs.changes.outputs.locale-files }} run: | # Fail with an annotation per file so contributors see why directly on the PR for file in $LOCALE_FILES; do echo "::error file=$file::Translations are managed on Crowdin and can't be changed in this repository. Please contribute translations at https://crowdin.com/project/pocket-id instead." done { echo "### Translation files can't be changed in pull requests" echo echo "Only \`frontend/messages/en.json\` may be edited. All other locales are synced from [Crowdin](https://crowdin.com/project/pocket-id) automatically, so changes here would be overwritten." echo echo "Revert the changes to these files:" echo for file in $LOCALE_FILES; do echo "- \`$file\`"; done } >> "$GITHUB_STEP_SUMMARY" exit 1 backend-lint: name: Backend lint needs: changes if: needs.changes.outputs.backend == 'true' runs-on: depot-ubuntu-latest permissions: contents: read # Needed by the only-new-issues option pull-requests: read steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Set up Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: backend/go.mod cache-dependency-path: backend/go.sum - name: Run Golangci-lint uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0 with: version-file: .golangci-lint-version args: --config=.golangci.yml working-directory: backend backend-test: name: Backend tests (${{ matrix.name }}) needs: changes if: needs.changes.outputs.backend == 'true' strategy: fail-fast: false matrix: include: - name: Linux runner: depot-ubuntu-latest - name: Windows runner: windows-latest runs-on: ${{ matrix.runner }} steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Set up Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: backend/go.mod cache-dependency-path: backend/go.sum - name: Download dependencies working-directory: backend run: go mod download - name: Start Postgres # The SQLite/Postgres schema parity test needs Postgres and fails instead of skipping when POCKET_ID_TEST_POSTGRES_REQUIRED is set if: runner.os == 'Linux' run: | docker run -d --name postgres -e POSTGRES_PASSWORD=postgres -p 5432:5432 --health-cmd "pg_isready -U postgres" --health-interval 1s --health-retries 60 postgres:17 timeout 60 sh -c 'until [ "$(docker inspect -f "{{.State.Health.Status}}" postgres)" = healthy ]; do sleep 1; done' echo "POCKET_ID_TEST_POSTGRES_URL=postgres://postgres:postgres@localhost:5432/postgres?sslmode=disable" >> "$GITHUB_ENV" echo "POCKET_ID_TEST_POSTGRES_REQUIRED=true" >> "$GITHUB_ENV" - name: Run backend unit tests working-directory: backend run: go test "-tags=exclude_frontend,unit" -v ./... backend-test-race: name: Backend tests (race detector) needs: changes if: needs.changes.outputs.backend == 'true' runs-on: depot-ubuntu-latest steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Set up Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: backend/go.mod cache-dependency-path: backend/go.sum - name: Download dependencies working-directory: backend run: go mod download - name: Run backend unit tests with the race detector working-directory: backend run: go test -race "-tags=exclude_frontend,unit" ./... svelte-check: name: Svelte check needs: changes if: needs.changes.outputs.frontend == 'true' runs-on: depot-ubuntu-latest steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Vite+ uses: voidzero-dev/setup-vp@3754dd7dbdb32bd8f6d28b6043de13ad3a75f21f # v1.21.1 with: node-version-file: .node-version cache: true run-install: false - name: Install dependencies run: vp -C frontend install --frozen-lockfile - name: Build Pocket ID Frontend run: vp -C frontend run build - name: Add svelte-check problem matcher run: echo "::add-matcher::.github/svelte-check-matcher.json" - name: Run svelte-check run: vp -C frontend run check e2e: name: E2E (${{ matrix.db }}, ${{ matrix.storage }}, ${{ matrix.francis }}) needs: changes if: needs.changes.outputs.e2e == 'true' runs-on: depot-ubuntu-24.04-32 permissions: contents: read # Needed by Depot to authenticate the Docker builds id-token: write strategy: fail-fast: false matrix: include: - db: sqlite storage: filesystem francis: embedded - db: postgres storage: filesystem francis: embedded - db: sqlite storage: s3 francis: embedded - db: sqlite storage: database francis: embedded - db: postgres storage: database francis: embedded - db: sqlite storage: filesystem francis: remote steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Vite+ uses: voidzero-dev/setup-vp@3754dd7dbdb32bd8f6d28b6043de13ad3a75f21f # v1.21.1 with: node-version-file: .node-version cache: true run-install: false - name: Set up Depot CLI uses: depot/setup-action@91bc8495a33ebfc504ffc89e5674379ccf23c29c # v1.7.2 with: configure-docker: true - name: Cache Playwright Browsers uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 id: playwright-cache with: path: ~/.cache/ms-playwright key: ${{ runner.os }}-playwright-${{ hashFiles('pnpm-lock.yaml') }} - name: Cache PostgreSQL Docker image uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 id: postgres-cache with: path: /tmp/postgres-image.tar key: postgres-17-${{ runner.os }} - name: Pull and save PostgreSQL image if: matrix.db == 'postgres' && steps.postgres-cache.outputs.cache-hit != 'true' run: | docker pull postgres:17 docker save postgres:17 > /tmp/postgres-image.tar - name: Load PostgreSQL image if: matrix.db == 'postgres' && steps.postgres-cache.outputs.cache-hit == 'true' run: docker load < /tmp/postgres-image.tar - name: Cache SCIM Test Server Docker image uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 id: scim-cache with: path: /tmp/scim-test-server-image.tar key: scim-test-server-${{ runner.os }} - name: Pull and save SCIM Test Server image if: steps.scim-cache.outputs.cache-hit != 'true' run: | docker pull ghcr.io/pocket-id/scim-test-server docker save ghcr.io/pocket-id/scim-test-server > /tmp/scim-test-server-image.tar - name: Load SCIM Test Server image if: steps.scim-cache.outputs.cache-hit == 'true' run: docker load < /tmp/scim-test-server-image.tar - name: Cache Localstack S3 Docker image if: matrix.storage == 's3' uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 id: s3-cache with: path: /tmp/localstack-s3-image.tar key: localstack-4.14.0-${{ runner.os }} - name: Pull and save Localstack S3 image if: matrix.storage == 's3' && steps.s3-cache.outputs.cache-hit != 'true' run: | docker pull localstack/localstack:4.14.0 docker save localstack/localstack:4.14.0 > /tmp/localstack-s3-image.tar - name: Load Localstack S3 image if: matrix.storage == 's3' && steps.s3-cache.outputs.cache-hit == 'true' run: docker load < /tmp/localstack-s3-image.tar - name: Resolve Francis runtime image id: francis-image working-directory: ./tests/setup run: | # Read the version of Francis from backend/go.mod and use that runtime VERSION=$(./francis-version.sh) echo "version=$VERSION" >> "$GITHUB_OUTPUT" echo "image=ghcr.io/italypaleale/francis:$VERSION" >> "$GITHUB_OUTPUT" echo "key=francis-$VERSION" >> "$GITHUB_OUTPUT" - name: Cache Francis runtime Docker image if: matrix.francis == 'remote' uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 id: francis-cache with: path: /tmp/francis-image.tar key: ${{ steps.francis-image.outputs.key }}-${{ runner.os }} - name: Pull and save Francis runtime image if: matrix.francis == 'remote' && steps.francis-cache.outputs.cache-hit != 'true' run: | docker pull "${{ steps.francis-image.outputs.image }}" docker save "${{ steps.francis-image.outputs.image }}" > /tmp/francis-image.tar - name: Load Francis runtime image if: matrix.francis == 'remote' && steps.francis-cache.outputs.cache-hit == 'true' run: docker load < /tmp/francis-image.tar - name: Install test dependencies run: vp -C tests install --frozen-lockfile - name: Install Playwright Browsers if: steps.playwright-cache.outputs.cache-hit != 'true' run: vp -C tests exec playwright install --with-deps chromium - name: Run Docker containers working-directory: ./tests/setup run: | DOCKER_COMPOSE_FILE=docker-compose.yml cat > .env <> "$LOG_FILE" docker logs -f --since=0 "$CID" >> "$LOG_FILE" 2>&1 else echo "[$(date)] Container not yet running…" >> "$LOG_FILE" fi sleep 1 done } & if [ "${{ matrix.francis }}" = "remote" ]; then docker compose -f "$DOCKER_COMPOSE_FILE" logs -f --no-log-prefix francis-runtime > /tmp/francis-runtime.log 2>&1 & fi - name: Run Playwright tests run: vp -C tests exec playwright test - name: Upload Test Report uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: always() with: name: playwright-report-${{ matrix.db }}-${{ matrix.storage }}-francis-${{ matrix.francis }} path: tests/.report include-hidden-files: true retention-days: 15 - name: Upload Backend Test Report uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: always() with: name: backend-${{ matrix.db }}-${{ matrix.storage }}-francis-${{ matrix.francis }} path: /tmp/backend.log include-hidden-files: true retention-days: 15 - name: Upload Francis Runtime Report uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: always() && matrix.francis == 'remote' with: name: francis-runtime-${{ matrix.db }}-${{ matrix.storage }} path: /tmp/francis-runtime.log include-hidden-files: true retention-days: 15 # The only check the ruleset requires, so jobs can be added, renamed or skipped without touching the ruleset ci-success: name: CI success needs: [changes, translations, backend-lint, backend-test, backend-test-race, svelte-check, e2e] if: always() runs-on: ubuntu-latest steps: - name: Check job results env: RESULTS: ${{ join(needs.*.result, ' ') }} run: | # Skipped jobs are fine because they didn't apply to the changed files echo "Job results: $RESULTS" for result in $RESULTS; do if [ "$result" = failure ] || [ "$result" = cancelled ]; then echo "::error::At least one CI job failed or was cancelled" exit 1 fi done