-
Notifications
You must be signed in to change notification settings - Fork 14
Expand file tree
/
Copy path.gitlab-ci.yml
More file actions
78 lines (72 loc) · 2.59 KB
/
Copy path.gitlab-ci.yml
File metadata and controls
78 lines (72 loc) · 2.59 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
variables:
IMAGE: $CI_REGISTRY/$CI_PROJECT_PATH:main
DOCKER_TLS_CERTDIR: "/certs"
default:
services:
- docker:25.0.5-dind
stages:
- test
- build
- deploy
pytest:
stage: test
image: python:3.12-slim
variables:
# db.py resolves DATABASE_URL and calls create_engine() at import time, so
# importing anything in the package needs this set. create_engine does not
# connect, so a syntactically valid bogus URI is enough — and it must stay
# bogus, so a test that escapes its mocks fails instead of touching a real DB.
POSTGRES_URI: "postgresql://ci:ci@localhost:5432/ci"
before_script:
# git is required, not optional: pyproject pins imbalanced-learn to a git
# source ([tool.uv.sources]), so `uv sync` shells out to git to fetch it and
# fails with "Git executable not found" on python:3.12-slim, which ships
# without it. The failure happens during dependency resolution, so the whole
# job dies before a single test runs.
- apt-get update -qq && apt-get install -y -qq --no-install-recommends git
- pip install uv
# --extra dev is the optional-dependencies group holding pytest/pytest-mock;
# the [dependency-groups] dev group (ruff, mypy) is synced by default.
- uv sync --frozen --extra dev
script:
- uv run ruff check .
- uv run ruff format --check .
- uv run pytest tests/ -q
build-docker:
stage: build
image: docker:25.0.5-git
needs:
- pytest
# tags:
# - dfserver
script:
- echo "$CI_REGISTRY_PASSWORD" | docker login $CI_REGISTRY -u $CI_REGISTRY_USER --password-stdin
- docker build --pull -t $IMAGE .
- docker push $IMAGE
helm-kubectl-deploy:
stage: deploy
# Only main deploys. Without this a refactor branch would deploy itself, which
# makes it impossible to land a multi-commit change (e.g. an import rewrite and
# its matching CronJob invocation) as one atomic production cutover.
rules:
- if: $CI_COMMIT_BRANCH == "main"
tags:
- dfserver
image:
name: dtzar/helm-kubectl
entrypoint: [ '' ]
dependencies:
- build-docker
script:
# Deploy trading bots and PostgreSQL using Helm, pinned to the tag build-docker
# just pushed. This MUST match $IMAGE above: build-docker only ever pushes
# :main, so deploying :latest pins every CronJob to a tag nothing publishes and
# the whole fleet goes ImagePullBackOff ("manifest unknown") until the next
# deploy. That is exactly what happened between 2026-08-18 and 2026-08-21.
- |
helm upgrade --install tradingbots \
./helm/tradingbots \
--create-namespace \
--namespace tradingbots-2025 \
--set image.tag=main
environment: production