feat: bind IBKR order outcomes to reconciliation keys #1185
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [ main ] | |
| pull_request: | |
| permissions: | |
| contents: read | |
| jobs: | |
| test: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Reject public runtime configuration bindings | |
| run: | | |
| set -euo pipefail | |
| if rg -n '\$\{\{[[:space:]]*vars\.(GLOBAL_TELEGRAM_CHAT_ID|CLOUD_RUN_SERVICES|CLOUD_RUN_SERVICE|RUNTIME_HEARTBEAT_REQUIRED_SERVICES|RUNTIME_GUARD_SCHEDULER_JOB_PATTERN)([[:space:]]|\}\}|\|\|)' .github/workflows; then | |
| echo "Sensitive operational runtime configuration must use GitHub Secrets, not GitHub Variables." >&2 | |
| exit 1 | |
| fi | |
| - name: Resolve QuantPlatformKit ref | |
| id: quant-platform-kit-ref | |
| run: | | |
| set -euo pipefail | |
| ref="main" | |
| for candidate in "${GITHUB_HEAD_REF:-}" "${GITHUB_BASE_REF:-}"; do | |
| if [ -n "$candidate" ] && git ls-remote --exit-code --heads https://github.com/QuantStrategyLab/QuantPlatformKit.git "$candidate" >/dev/null 2>&1; then | |
| ref="$candidate" | |
| break | |
| fi | |
| done | |
| echo "ref=${ref}" >> "$GITHUB_OUTPUT" | |
| - name: Resolve UsEquityStrategies ref | |
| id: us-equity-strategies-ref | |
| run: | | |
| set -euo pipefail | |
| ref="main" | |
| for candidate in "${GITHUB_HEAD_REF:-}" "${GITHUB_BASE_REF:-}"; do | |
| if [ -n "$candidate" ] && git ls-remote --exit-code --heads https://github.com/QuantStrategyLab/UsEquityStrategies.git "$candidate" >/dev/null 2>&1; then | |
| ref="$candidate" | |
| break | |
| fi | |
| done | |
| echo "ref=${ref}" >> "$GITHUB_OUTPUT" | |
| - name: Resolve UsEquitySnapshotPipelines ref | |
| id: us-equity-snapshot-pipelines-ref | |
| run: | | |
| set -euo pipefail | |
| ref="main" | |
| for candidate in "${GITHUB_HEAD_REF:-}" "${GITHUB_BASE_REF:-}"; do | |
| if [ -n "$candidate" ] && git ls-remote --exit-code --heads https://github.com/QuantStrategyLab/UsEquitySnapshotPipelines.git "$candidate" >/dev/null 2>&1; then | |
| ref="$candidate" | |
| break | |
| fi | |
| done | |
| echo "ref=${ref}" >> "$GITHUB_OUTPUT" | |
| - name: Checkout QuantPlatformKit | |
| uses: actions/checkout@v6 | |
| with: | |
| repository: QuantStrategyLab/QuantPlatformKit | |
| ref: ${{ steps.quant-platform-kit-ref.outputs.ref }} | |
| path: external/QuantPlatformKit | |
| - name: Checkout UsEquityStrategies | |
| uses: actions/checkout@v6 | |
| with: | |
| repository: QuantStrategyLab/UsEquityStrategies | |
| ref: ${{ steps.us-equity-strategies-ref.outputs.ref }} | |
| path: external/UsEquityStrategies | |
| - name: Checkout UsEquitySnapshotPipelines | |
| uses: actions/checkout@v6 | |
| with: | |
| repository: QuantStrategyLab/UsEquitySnapshotPipelines | |
| ref: ${{ steps.us-equity-snapshot-pipelines-ref.outputs.ref }} | |
| path: external/UsEquitySnapshotPipelines | |
| - name: Setup Python | |
| uses: actions/setup-python@v6 | |
| with: | |
| python-version: "3.12" | |
| - name: Install dependencies | |
| run: | | |
| set -euo pipefail | |
| python -m pip install --upgrade pip uv | |
| uv sync --frozen --extra test | |
| - name: Smoke import pinned shared packages | |
| run: | | |
| set -euo pipefail | |
| uv run --no-sync python - <<'PY' | |
| from quant_platform_kit.common.port_adapters import CallableNotificationPort, CallablePortfolioPort | |
| from hk_equity_strategies import resolve_canonical_profile as resolve_hk_canonical_profile | |
| from us_equity_strategies import resolve_canonical_profile | |
| assert CallableNotificationPort | |
| assert CallablePortfolioPort | |
| assert resolve_canonical_profile("russell_top50_leader_rotation") == "russell_top50_leader_rotation" | |
| assert resolve_hk_canonical_profile("hk_global_etf_tactical_rotation") == "hk_global_etf_tactical_rotation" | |
| PY | |
| - name: Validate production Cloud Run startup | |
| run: uv run --no-sync python scripts/validate_cloud_run_startup.py | |
| - name: Install editable shared repositories | |
| run: | | |
| set -euo pipefail | |
| uv pip install --no-deps -e external/QuantPlatformKit -e external/UsEquityStrategies -e external/UsEquitySnapshotPipelines | |
| - name: Run ruff | |
| run: | | |
| set -euo pipefail | |
| uv run --no-sync ruff check --exclude external . | |
| - name: Check QPK pin consistency | |
| run: | | |
| set -euo pipefail | |
| uv run --no-sync python external/QuantPlatformKit/scripts/check_qpk_pin_consistency.py \ | |
| --root . \ | |
| --pin-file external/QuantPlatformKit/QPK_PIN | |
| - name: Ensure uv.lock matches pyproject.toml | |
| run: uv lock --check | |
| - name: Run P2 scoped unit tests | |
| run: | | |
| set -euo pipefail | |
| # P2 scoped gate; this is not a repository-wide full-suite result. | |
| PYTHONPATH=. PYTEST_DISABLE_PLUGIN_AUTOLOAD=1 uv run --no-sync python -m pytest -q tests/test_broker_reconciliation.py tests/test_execution_service.py tests/test_rebalance_service.py tests/test_ci_unit_test_contract.py | |
| - name: Summarize P2 scoped gate | |
| run: | | |
| echo "P2 scoped gate passed; this is not a repository-wide full-suite result." >> "$GITHUB_STEP_SUMMARY" | |
| legacy-full-suite: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Resolve QuantPlatformKit ref | |
| id: quant-platform-kit-ref | |
| run: | | |
| set -euo pipefail | |
| ref="main" | |
| for candidate in "${GITHUB_HEAD_REF:-}" "${GITHUB_BASE_REF:-}"; do | |
| if [ -n "$candidate" ] && git ls-remote --exit-code --heads https://github.com/QuantStrategyLab/QuantPlatformKit.git "$candidate" >/dev/null 2>&1; then | |
| ref="$candidate" | |
| break | |
| fi | |
| done | |
| echo "ref=${ref}" >> "$GITHUB_OUTPUT" | |
| - name: Resolve UsEquityStrategies ref | |
| id: us-equity-strategies-ref | |
| run: | | |
| set -euo pipefail | |
| ref="main" | |
| for candidate in "${GITHUB_HEAD_REF:-}" "${GITHUB_BASE_REF:-}"; do | |
| if [ -n "$candidate" ] && git ls-remote --exit-code --heads https://github.com/QuantStrategyLab/UsEquityStrategies.git "$candidate" >/dev/null 2>&1; then | |
| ref="$candidate" | |
| break | |
| fi | |
| done | |
| echo "ref=${ref}" >> "$GITHUB_OUTPUT" | |
| - name: Resolve UsEquitySnapshotPipelines ref | |
| id: us-equity-snapshot-pipelines-ref | |
| run: | | |
| set -euo pipefail | |
| ref="main" | |
| for candidate in "${GITHUB_HEAD_REF:-}" "${GITHUB_BASE_REF:-}"; do | |
| if [ -n "$candidate" ] && git ls-remote --exit-code --heads https://github.com/QuantStrategyLab/UsEquitySnapshotPipelines.git "$candidate" >/dev/null 2>&1; then | |
| ref="$candidate" | |
| break | |
| fi | |
| done | |
| echo "ref=${ref}" >> "$GITHUB_OUTPUT" | |
| - name: Checkout QuantPlatformKit | |
| uses: actions/checkout@v6 | |
| with: | |
| repository: QuantStrategyLab/QuantPlatformKit | |
| ref: ${{ steps.quant-platform-kit-ref.outputs.ref }} | |
| path: external/QuantPlatformKit | |
| - name: Checkout UsEquityStrategies | |
| uses: actions/checkout@v6 | |
| with: | |
| repository: QuantStrategyLab/UsEquityStrategies | |
| ref: ${{ steps.us-equity-strategies-ref.outputs.ref }} | |
| path: external/UsEquityStrategies | |
| - name: Checkout UsEquitySnapshotPipelines | |
| uses: actions/checkout@v6 | |
| with: | |
| repository: QuantStrategyLab/UsEquitySnapshotPipelines | |
| ref: ${{ steps.us-equity-snapshot-pipelines-ref.outputs.ref }} | |
| path: external/UsEquitySnapshotPipelines | |
| - name: Setup Python | |
| uses: actions/setup-python@v6 | |
| with: | |
| python-version: "3.12" | |
| - name: Install dependencies | |
| run: | | |
| set -euo pipefail | |
| python -m pip install --upgrade pip uv | |
| uv sync --frozen --extra test | |
| - name: Install editable shared repositories | |
| run: | | |
| set -euo pipefail | |
| uv pip install --no-deps -e external/QuantPlatformKit -e external/UsEquityStrategies -e external/UsEquitySnapshotPipelines | |
| - name: Run legacy full suite | |
| run: | | |
| set -euo pipefail | |
| PYTHONPATH=. PYTEST_DISABLE_PLUGIN_AUTOLOAD=1 uv run --no-sync python -m pytest -q tests --ignore=tests/test_request_handling.py --ignore=tests/test_event_loop.py --ignore=tests/test_monitor_dispatcher.py --ignore=tests/test_notifications.py --ignore=tests/test_connect_timeout_alert.py |