Skip to content

ci: adopt org runner-policy gate #38

ci: adopt org runner-policy gate

ci: adopt org runner-policy gate #38

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
workflow_dispatch:
concurrency:
group: ngms-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
lint:
runs-on: [self-hosted, node-b, linux, x64]
steps:
- uses: actions/checkout@v7
# The self-hosted runner image has no Rust toolchain preinstalled,
# unlike ubuntu-latest. Pinned to match rust-toolchain.toml.
- uses: dtolnay/rust-toolchain@master
with:
toolchain: "1.95.0"
components: clippy,rustfmt
- uses: Swatinem/rust-cache@v2
- uses: actions/setup-node@v7
with:
node-version: 24
- name: Build embedded web assets
run: |
npm --prefix ui ci --no-audit --no-fund
npm --prefix ui run build
npm --prefix client ci --no-audit --no-fund
npm --prefix client run build
- name: Verify public dependency boundary
run: python3 scripts/check_dependency_sources.py
- name: Verify workspace documentation
run: python3 scripts/check_workspace_docs.py
- run: cargo fmt --all -- --check
- run: cargo clippy --workspace --all-features --locked -- -D warnings
test:
runs-on: [self-hosted, node-b, linux, x64]
steps:
- uses: actions/checkout@v7
# The self-hosted runner image has no Rust toolchain preinstalled,
# unlike ubuntu-latest. Pinned to match rust-toolchain.toml.
- uses: dtolnay/rust-toolchain@master
with:
toolchain: "1.95.0"
components: clippy,rustfmt
- uses: Swatinem/rust-cache@v2
- uses: actions/setup-node@v7
with:
node-version: 24
- name: Build embedded web assets
run: |
npm --prefix ui ci --no-audit --no-fund
npm --prefix ui run build
npm --prefix client ci --no-audit --no-fund
npm --prefix client run build
- run: cargo test --workspace --all-features --locked
build:
runs-on: [self-hosted, node-b, linux, x64]
steps:
- uses: actions/checkout@v7
# The self-hosted runner image has no Rust toolchain preinstalled,
# unlike ubuntu-latest. Pinned to match rust-toolchain.toml.
- uses: dtolnay/rust-toolchain@master
with:
toolchain: "1.95.0"
components: clippy,rustfmt
- uses: Swatinem/rust-cache@v2
- uses: actions/setup-node@v7
with:
node-version: 24
- name: Build embedded web assets
run: |
npm --prefix ui ci --no-audit --no-fund
npm --prefix ui run build
npm --prefix client ci --no-audit --no-fund
npm --prefix client run build
- run: cargo build --workspace --all-features --locked
ui:
runs-on: [self-hosted, node-b, linux, x64]
strategy:
matrix:
project: [ui, client]
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: 24
cache: npm
cache-dependency-path: ${{ matrix.project }}/package-lock.json
- working-directory: ${{ matrix.project }}
run: npm ci --no-audit --no-fund
- working-directory: ${{ matrix.project }}
run: npm run build
ui-e2e:
runs-on: [self-hosted, node-b, linux, x64]
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: 24
cache: npm
cache-dependency-path: ui/package-lock.json
- working-directory: ui
run: npm ci --no-audit --no-fund
- working-directory: ui
run: npx playwright install --with-deps chromium
- working-directory: ui
run: npm run test:e2e
container:
if: github.event_name == 'push'
needs: [lint, test, build, ui, ui-e2e]
runs-on: [self-hosted, node-b, linux, x64, publish, docker]
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v7
- uses: docker/setup-buildx-action@v4
- uses: docker/login-action@v4
if: github.event_name == 'push'
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- uses: docker/build-push-action@v7
with:
context: .
file: docker/Dockerfile
push: ${{ github.event_name == 'push' }}
tags: |
ghcr.io/thedancingdeveloper-org/ngms:latest
ghcr.io/thedancingdeveloper-org/ngms:sha-${{ github.sha }}
cache-from: type=gha
# The first canonical push uploaded the image successfully, then
# wedged for more than 20 minutes exporting its optional GHA cache.
# Keep cache reads, but do not let cache publication hold the image
# delivery gate open indefinitely on the self-hosted publisher.