Skip to content

Design system: dual-theme audit-grade frontend + /dashboard/kpis (#16) #42

Design system: dual-theme audit-grade frontend + /dashboard/kpis (#16)

Design system: dual-theme audit-grade frontend + /dashboard/kpis (#16) #42

Workflow file for this run

name: CI
on:
pull_request:
push:
branches: [main]
jobs:
backend:
runs-on: ubuntu-latest
services:
postgres:
image: pgvector/pgvector:pg16
env:
POSTGRES_USER: sentinel
POSTGRES_PASSWORD: sentinel
POSTGRES_DB: sentinel_test
ports: ["5432:5432"]
options: >-
--health-cmd "pg_isready -U sentinel" --health-interval 10s
--health-timeout 5s --health-retries 5
env:
DATABASE_URL: postgresql+psycopg://sentinel:sentinel@localhost:5432/sentinel_test
# LLM + embeddings are mocked in tests; no API keys in CI.
EMBEDDINGS_PROVIDER: fake
steps:
- uses: actions/checkout@v4
- uses: astral-sh/setup-uv@v4
- run: uv sync --all-extras --dev
- run: uv run ruff check .
- run: uv run ruff format --check .
- run: uv run mypy .
# DoD #1 (M1): `make migrate` applies cleanly on a fresh DB. The Postgres service
# container starts empty, so this step exercises the full bootstrap path.
- run: uv run alembic upgrade head
- run: uv run pytest -q
# DoD #1 (M2): `make seed` ingests the synthetic corpus end-to-end with the
# FakeEmbedder. The pytest tests use SAVEPOINT-isolated sessions and roll back,
# so the DB is empty by the time we get here.
- run: make seed
frontend:
runs-on: ubuntu-latest
defaults:
run:
working-directory: frontend
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: npm
cache-dependency-path: frontend/package-lock.json
- run: npm ci
- run: npm run lint
- run: npm test
- run: npm run build
terraform:
runs-on: ubuntu-latest
defaults:
run:
working-directory: infra
steps:
- uses: actions/checkout@v4
- uses: hashicorp/setup-terraform@v3
with:
terraform_version: 1.9.8
# No AWS credentials needed for fmt + validate.
- run: terraform fmt -recursive -check
- run: terraform init -backend=false
- run: terraform validate