Files
pocket-id/.github/workflows/ci.yml
T

465 lines
17 KiB
YAML

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main, breaking/**]
workflow_dispatch:
permissions:
contents: read
# Cancel outdated runs of a pull request but test every commit on main
concurrency:
group: ci-${{ github.event_name == 'pull_request' && github.event.pull_request.number || github.sha }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
changes:
name: Detect changes
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read
outputs:
backend: ${{ steps.filter.outputs.backend }}
frontend: ${{ steps.filter.outputs.frontend }}
e2e: ${{ steps.filter.outputs.e2e }}
locale-files: ${{ steps.filter.outputs.locale-files }}
steps:
- name: Detect changed areas
id: filter
env:
GH_TOKEN: ${{ github.token }}
REPO: ${{ github.repository }}
EVENT_NAME: ${{ github.event_name }}
PR_NUMBER: ${{ github.event.pull_request.number }}
BEFORE: ${{ github.event.before }}
SHA: ${{ github.sha }}
run: |
# List the changed files, including the old path of renamed files
all=false
files=""
case "$EVENT_NAME" in
pull_request)
files=$(gh api --paginate "repos/$REPO/pulls/$PR_NUMBER/files" --jq '.[] | .filename, (.previous_filename // empty)')
;;
push)
# The compare API fails for force pushes and new branches, so fall back to running everything
files=$(gh api --paginate "repos/$REPO/compare/$BEFORE...$SHA" --jq '.files[]? | .filename, (.previous_filename // empty)') || all=true
;;
*)
all=true
;;
esac
# A change to the CI definition itself has to be validated by every job
if grep -q -x '.github/workflows/ci.yml' <<< "$files"; then
all=true
fi
matches() {
[ "$all" = true ] || grep -q -E "$1" <<< "$2"
}
# Translated locales only come from Crowdin and don't affect the English end-to-end tests
e2e_files=$(grep -v -E '^(docs/|\.github/)|\.md$|^frontend/messages/.+\.json$' <<< "$files" || true)
e2e_files+=$'\n'$(grep -x 'frontend/messages/en.json' <<< "$files" || true)
{
matches '^backend/' "$files" && echo "backend=true" || echo "backend=false"
matches '^(frontend/|package\.json$|pnpm-lock\.yaml$|pnpm-workspace\.yaml$|\.node-version$|vite\.config\.ts$|\.github/svelte-check-matcher\.json$)' "$files" && echo "frontend=true" || echo "frontend=false"
matches '.' "$e2e_files" && echo "e2e=true" || echo "e2e=false"
} >> "$GITHUB_OUTPUT"
# Every locale except en.json is committed to main by the Crowdin download workflow, so pull requests must not change them
if [ "$EVENT_NAME" = pull_request ]; then
locale_files=$(grep -E '^frontend/messages/.+\.json$' <<< "$files" | grep -v -x 'frontend/messages/en.json' | sort -u | tr '\n' ' ' || true)
echo "locale-files=${locale_files% }" >> "$GITHUB_OUTPUT"
fi
cat "$GITHUB_OUTPUT"
translations:
name: Translations
needs: changes
if: needs.changes.outputs.locale-files != ''
runs-on: ubuntu-latest
steps:
- name: Reject changes to translated locales
env:
LOCALE_FILES: ${{ needs.changes.outputs.locale-files }}
run: |
# Fail with an annotation per file so contributors see why directly on the PR
for file in $LOCALE_FILES; do
echo "::error file=$file::Translations are managed on Crowdin and can't be changed in this repository. Please contribute translations at https://crowdin.com/project/pocket-id instead."
done
{
echo "### Translation files can't be changed in pull requests"
echo
echo "Only \`frontend/messages/en.json\` may be edited. All other locales are synced from [Crowdin](https://crowdin.com/project/pocket-id) automatically, so changes here would be overwritten."
echo
echo "Revert the changes to these files:"
echo
for file in $LOCALE_FILES; do echo "- \`$file\`"; done
} >> "$GITHUB_STEP_SUMMARY"
exit 1
backend-lint:
name: Backend lint
needs: changes
if: needs.changes.outputs.backend == 'true'
runs-on: depot-ubuntu-latest
permissions:
contents: read
# Needed by the only-new-issues option
pull-requests: read
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: backend/go.mod
- name: Run Golangci-lint
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0
with:
version: v2.13.2
args: --config=.golangci.yml
working-directory: backend
only-new-issues: ${{ github.event_name == 'pull_request' }}
backend-test:
name: Backend tests (${{ matrix.name }})
needs: changes
if: needs.changes.outputs.backend == 'true'
strategy:
fail-fast: false
matrix:
include:
- name: Linux
runner: depot-ubuntu-latest
- name: Windows
runner: windows-latest
runs-on: ${{ matrix.runner }}
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: backend/go.mod
cache-dependency-path: backend/go.sum
- name: Download dependencies
working-directory: backend
run: go mod download
- name: Start Postgres
# The SQLite/Postgres schema parity test needs Postgres and fails instead of skipping when POCKET_ID_TEST_POSTGRES_REQUIRED is set
if: runner.os == 'Linux'
run: |
docker run -d --name postgres -e POSTGRES_PASSWORD=postgres -p 5432:5432 --health-cmd "pg_isready -U postgres" --health-interval 1s --health-retries 60 postgres:17
timeout 60 sh -c 'until [ "$(docker inspect -f "{{.State.Health.Status}}" postgres)" = healthy ]; do sleep 1; done'
echo "POCKET_ID_TEST_POSTGRES_URL=postgres://postgres:postgres@localhost:5432/postgres?sslmode=disable" >> "$GITHUB_ENV"
echo "POCKET_ID_TEST_POSTGRES_REQUIRED=true" >> "$GITHUB_ENV"
- name: Run backend unit tests
working-directory: backend
run: go test "-tags=exclude_frontend,unit" -v ./...
backend-test-race:
name: Backend tests (race detector)
needs: changes
if: needs.changes.outputs.backend == 'true'
runs-on: depot-ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: backend/go.mod
cache-dependency-path: backend/go.sum
- name: Download dependencies
working-directory: backend
run: go mod download
- name: Run backend unit tests with the race detector
working-directory: backend
run: go test -race "-tags=exclude_frontend,unit" ./...
svelte-check:
name: Svelte check
needs: changes
if: needs.changes.outputs.frontend == 'true'
runs-on: depot-ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Setup Vite+
uses: voidzero-dev/setup-vp@3754dd7dbdb32bd8f6d28b6043de13ad3a75f21f # v1.21.1
with:
node-version-file: .node-version
cache: true
run-install: false
- name: Install dependencies
run: vp -C frontend install --frozen-lockfile
- name: Build Pocket ID Frontend
run: vp -C frontend run build
- name: Add svelte-check problem matcher
run: echo "::add-matcher::.github/svelte-check-matcher.json"
- name: Run svelte-check
run: vp -C frontend run check
e2e:
name: E2E (${{ matrix.db }}, ${{ matrix.storage }}, ${{ matrix.francis }})
needs: changes
if: needs.changes.outputs.e2e == 'true'
runs-on: depot-ubuntu-24.04-32
permissions:
contents: read
# Needed by Depot to authenticate the Docker builds
id-token: write
strategy:
fail-fast: false
matrix:
include:
- db: sqlite
storage: filesystem
francis: embedded
- db: postgres
storage: filesystem
francis: embedded
- db: sqlite
storage: s3
francis: embedded
- db: sqlite
storage: database
francis: embedded
- db: postgres
storage: database
francis: embedded
- db: sqlite
storage: filesystem
francis: remote
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Setup Vite+
uses: voidzero-dev/setup-vp@3754dd7dbdb32bd8f6d28b6043de13ad3a75f21f # v1.21.1
with:
node-version-file: .node-version
cache: true
run-install: false
- name: Set up Depot CLI
uses: depot/setup-action@91bc8495a33ebfc504ffc89e5674379ccf23c29c # v1.7.2
with:
configure-docker: true
- name: Cache Playwright Browsers
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
id: playwright-cache
with:
path: ~/.cache/ms-playwright
key: ${{ runner.os }}-playwright-${{ hashFiles('pnpm-lock.yaml') }}
- name: Cache PostgreSQL Docker image
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
id: postgres-cache
with:
path: /tmp/postgres-image.tar
key: postgres-17-${{ runner.os }}
- name: Pull and save PostgreSQL image
if: matrix.db == 'postgres' && steps.postgres-cache.outputs.cache-hit != 'true'
run: |
docker pull postgres:17
docker save postgres:17 > /tmp/postgres-image.tar
- name: Load PostgreSQL image
if: matrix.db == 'postgres' && steps.postgres-cache.outputs.cache-hit == 'true'
run: docker load < /tmp/postgres-image.tar
- name: Cache SCIM Test Server Docker image
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
id: scim-cache
with:
path: /tmp/scim-test-server-image.tar
key: scim-test-server-${{ runner.os }}
- name: Pull and save SCIM Test Server image
if: steps.scim-cache.outputs.cache-hit != 'true'
run: |
docker pull ghcr.io/pocket-id/scim-test-server
docker save ghcr.io/pocket-id/scim-test-server > /tmp/scim-test-server-image.tar
- name: Load SCIM Test Server image
if: steps.scim-cache.outputs.cache-hit == 'true'
run: docker load < /tmp/scim-test-server-image.tar
- name: Cache Localstack S3 Docker image
if: matrix.storage == 's3'
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
id: s3-cache
with:
path: /tmp/localstack-s3-image.tar
key: localstack-4.14.0-${{ runner.os }}
- name: Pull and save Localstack S3 image
if: matrix.storage == 's3' && steps.s3-cache.outputs.cache-hit != 'true'
run: |
docker pull localstack/localstack:4.14.0
docker save localstack/localstack:4.14.0 > /tmp/localstack-s3-image.tar
- name: Load Localstack S3 image
if: matrix.storage == 's3' && steps.s3-cache.outputs.cache-hit == 'true'
run: docker load < /tmp/localstack-s3-image.tar
- name: Resolve Francis runtime image
id: francis-image
working-directory: ./tests/setup
run: |
# Read the version of Francis from backend/go.mod and use that runtime
VERSION=$(./francis-version.sh)
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
echo "image=ghcr.io/italypaleale/francis:$VERSION" >> "$GITHUB_OUTPUT"
echo "key=francis-$VERSION" >> "$GITHUB_OUTPUT"
- name: Cache Francis runtime Docker image
if: matrix.francis == 'remote'
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
id: francis-cache
with:
path: /tmp/francis-image.tar
key: ${{ steps.francis-image.outputs.key }}-${{ runner.os }}
- name: Pull and save Francis runtime image
if: matrix.francis == 'remote' && steps.francis-cache.outputs.cache-hit != 'true'
run: |
docker pull "${{ steps.francis-image.outputs.image }}"
docker save "${{ steps.francis-image.outputs.image }}" > /tmp/francis-image.tar
- name: Load Francis runtime image
if: matrix.francis == 'remote' && steps.francis-cache.outputs.cache-hit == 'true'
run: docker load < /tmp/francis-image.tar
- name: Install test dependencies
run: vp -C tests install --frozen-lockfile
- name: Install Playwright Browsers
if: steps.playwright-cache.outputs.cache-hit != 'true'
run: vp -C tests exec playwright install --with-deps chromium
- name: Run Docker containers
working-directory: ./tests/setup
run: |
DOCKER_COMPOSE_FILE=docker-compose.yml
cat > .env <<EOF
FILE_BACKEND=${{ matrix.storage }}
FRANCIS_VERSION=${{ steps.francis-image.outputs.version }}
SCIM_SERVICE_PROVIDER_URL=http://localhost:18123/v2
SCIM_SERVICE_PROVIDER_URL_INTERNAL=http://scim-test-server:8080/v2
EOF
if [ "${{ matrix.francis }}" = "remote" ]; then
DOCKER_COMPOSE_FILE=docker-compose-francis.yml
elif [ "${{ matrix.db }}" = "postgres" ]; then
DOCKER_COMPOSE_FILE=docker-compose-postgres.yml
elif [ "${{ matrix.storage }}" = "s3" ]; then
DOCKER_COMPOSE_FILE=docker-compose-s3.yml
fi
docker compose -f "$DOCKER_COMPOSE_FILE" up -d --build
{
LOG_FILE="/tmp/backend.log"
while true; do
CID=$(docker compose -f "$DOCKER_COMPOSE_FILE" ps -q pocket-id)
if [ -n "$CID" ]; then
echo "[$(date)] Attaching logs for $CID" >> "$LOG_FILE"
docker logs -f --since=0 "$CID" >> "$LOG_FILE" 2>&1
else
echo "[$(date)] Container not yet running…" >> "$LOG_FILE"
fi
sleep 1
done
} &
if [ "${{ matrix.francis }}" = "remote" ]; then
docker compose -f "$DOCKER_COMPOSE_FILE" logs -f --no-log-prefix francis-runtime > /tmp/francis-runtime.log 2>&1 &
fi
- name: Run Playwright tests
run: vp -C tests exec playwright test
- name: Upload Test Report
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always()
with:
name: playwright-report-${{ matrix.db }}-${{ matrix.storage }}-francis-${{ matrix.francis }}
path: tests/.report
include-hidden-files: true
retention-days: 15
- name: Upload Backend Test Report
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always()
with:
name: backend-${{ matrix.db }}-${{ matrix.storage }}-francis-${{ matrix.francis }}
path: /tmp/backend.log
include-hidden-files: true
retention-days: 15
- name: Upload Francis Runtime Report
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always() && matrix.francis == 'remote'
with:
name: francis-runtime-${{ matrix.db }}-${{ matrix.storage }}
path: /tmp/francis-runtime.log
include-hidden-files: true
retention-days: 15
# The only check the ruleset requires, so jobs can be added, renamed or skipped without touching the ruleset
ci-success:
name: CI success
needs: [changes, translations, backend-lint, backend-test, backend-test-race, svelte-check, e2e]
if: always()
runs-on: ubuntu-latest
steps:
- name: Check job results
env:
RESULTS: ${{ join(needs.*.result, ' ') }}
run: |
# Skipped jobs are fine because they didn't apply to the changed files
echo "Job results: $RESULTS"
for result in $RESULTS; do
if [ "$result" = failure ] || [ "$result" = cancelled ]; then
echo "::error::At least one CI job failed or was cancelled"
exit 1
fi
done