refactor: refactor tests && registry multiplex authevents and errors #47
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Tests | |
| on: | |
| push: | |
| branches: | |
| - main | |
| - release | |
| tags: | |
| - "v*.*.*" | |
| paths-ignore: | |
| - "**/*.md" | |
| - "**/*.kdl" | |
| - "assets/**" | |
| - "LICENSE" | |
| - "LICENSE.md" | |
| - "AGENTS.md" | |
| pull_request: | |
| branches: | |
| - main | |
| paths-ignore: | |
| - "**/*.md" | |
| - "**/*.kdl" | |
| - "assets/**" | |
| - "LICENSE" | |
| - "LICENSE.md" | |
| - "AGENTS.md" | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| actions: read | |
| concurrency: | |
| group: tests-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| preflight: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| run_tests: ${{ steps.preflight.outputs.run_tests }} | |
| release_prepare_candidate: ${{ steps.preflight.outputs.release_prepare_candidate }} | |
| source_event: ${{ steps.preflight.outputs.source_event }} | |
| source_ref: ${{ steps.preflight.outputs.source_ref }} | |
| source_ref_name: ${{ steps.preflight.outputs.source_ref_name }} | |
| source_sha: ${{ steps.preflight.outputs.source_sha }} | |
| cache_scope: ${{ steps.preflight.outputs.cache_scope }} | |
| reused_run_id: ${{ steps.preflight.outputs.reused_run_id }} | |
| reused_run_url: ${{ steps.preflight.outputs.reused_run_url }} | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v6 | |
| - name: Setup mise and pnpm dependencies | |
| uses: ./.github/actions/setup-mise-pnpm | |
| with: | |
| cache-mode: read-write | |
| - name: Resolve tests preflight | |
| id: preflight | |
| env: | |
| GITHUB_TOKEN: ${{ github.token }} | |
| run: >- | |
| mise exec --command "node scripts/release-cli.ts workflow | |
| tests-preflight --format=github-output" | |
| node-deps: | |
| if: needs.preflight.outputs.run_tests == 'true' | |
| needs: preflight | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v6 | |
| - name: Setup mise and pnpm dependencies | |
| uses: ./.github/actions/setup-mise-pnpm | |
| with: | |
| cache-mode: read-only | |
| rust-debug-cache-prime: | |
| if: needs.preflight.outputs.run_tests == 'true' | |
| needs: | |
| - preflight | |
| - node-deps | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v6 | |
| - name: Setup mise and pnpm dependencies | |
| uses: ./.github/actions/setup-mise-pnpm | |
| with: | |
| cache-mode: read-only | |
| - name: Restore Rust debug build cache | |
| uses: ./.github/actions/setup-rust-cache | |
| with: | |
| shared-key: securitydept-rust-${{ runner.os }}-${{ | |
| needs.preflight.outputs.cache_scope }}-debug | |
| cache-mode: read-write | |
| - name: Prime Rust debug build cache | |
| run: mise exec --command "cargo build --workspace --all-features --all-targets" | |
| lint-and-typecheck: | |
| if: needs.preflight.outputs.run_tests == 'true' | |
| needs: | |
| - preflight | |
| - node-deps | |
| - rust-debug-cache-prime | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v6 | |
| - name: Setup mise and pnpm dependencies | |
| uses: ./.github/actions/setup-mise-pnpm | |
| with: | |
| cache-mode: read-only | |
| - name: Lint repository | |
| run: mise exec --command "pnpm lint" | |
| - name: Typecheck repository | |
| run: mise exec --command "pnpm typecheck" | |
| - name: Restore Rust build cache | |
| uses: ./.github/actions/setup-rust-cache | |
| with: | |
| shared-key: securitydept-rust-${{ runner.os }}-${{ | |
| needs.preflight.outputs.cache_scope }}-debug | |
| cache-mode: read-only | |
| - name: Lint Rust workspace | |
| run: mise exec --command "cargo clippy --workspace --all-features" | |
| rust-tests-except-e2e: | |
| if: needs.preflight.outputs.run_tests == 'true' | |
| needs: | |
| - preflight | |
| - node-deps | |
| - rust-debug-cache-prime | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v6 | |
| - name: Setup mise and pnpm dependencies | |
| uses: ./.github/actions/setup-mise-pnpm | |
| with: | |
| cache-mode: read-only | |
| - name: Restore Rust build cache | |
| uses: ./.github/actions/setup-rust-cache | |
| with: | |
| shared-key: securitydept-rust-${{ runner.os }}-${{ | |
| needs.preflight.outputs.cache_scope }}-debug | |
| cache-mode: read-only | |
| - name: Run Rust unit tests | |
| run: | | |
| mise exec --command "cargo test --workspace --lib --bins --all-features" | |
| mise exec --command "cargo test --workspace --doc --all-features" | |
| - name: Run Rust integration tests | |
| run: | | |
| mise exec --command "cargo test --workspace --test integration --all-features" | |
| ts-tests-except-e2e: | |
| if: needs.preflight.outputs.run_tests == 'true' | |
| needs: | |
| - preflight | |
| - node-deps | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v6 | |
| - name: Setup mise and pnpm dependencies | |
| uses: ./.github/actions/setup-mise-pnpm | |
| with: | |
| cache-mode: read-only | |
| - name: Restore Turbo test cache | |
| id: turbo-test-cache | |
| uses: actions/cache/restore@v5 | |
| with: | |
| path: .turbo | |
| key: turbo-${{ runner.os }}-${{ needs.preflight.outputs.cache_scope }}-test-${{ hashFiles('pnpm-lock.yaml', 'turbo.json') }}-${{ github.sha }} | |
| restore-keys: | | |
| turbo-${{ runner.os }}-${{ needs.preflight.outputs.cache_scope }}-test-${{ hashFiles('pnpm-lock.yaml', 'turbo.json') }}- | |
| - name: Test TypeScript workspace | |
| run: mise exec --command "pnpm test" | |
| - name: Save Turbo test cache | |
| if: steps.turbo-test-cache.outputs.cache-hit != 'true' | |
| uses: actions/cache/save@v5 | |
| with: | |
| path: .turbo | |
| key: ${{ steps.turbo-test-cache.outputs.cache-primary-key }} | |
| rs-tests-e2e: | |
| if: needs.preflight.outputs.run_tests == 'true' | |
| needs: | |
| - preflight | |
| - node-deps | |
| - rust-tests-except-e2e | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v6 | |
| - name: Setup mise and pnpm dependencies | |
| uses: ./.github/actions/setup-mise-pnpm | |
| with: | |
| cache-mode: read-only | |
| - name: Restore Rust build cache | |
| uses: ./.github/actions/setup-rust-cache | |
| with: | |
| shared-key: securitydept-rust-${{ runner.os }}-${{ | |
| needs.preflight.outputs.cache_scope }}-debug | |
| cache-mode: read-only | |
| - name: Restore kube test image cache | |
| id: kube-test-image-cache | |
| uses: actions/cache/restore@v5 | |
| with: | |
| path: /tmp/securitydept-kube-test-images.tar | |
| key: kube-test-images-${{ runner.os }}-${{ hashFiles('packages/realip/tests/fixtures/kube-helper/Dockerfile', 'packages/realip/tests/e2e/kube_provider.rs', 'scripts/lib/kube-test-resources.ts') }} | |
| - name: Load cached kube test images | |
| if: steps.kube-test-image-cache.outputs.cache-hit == 'true' | |
| run: docker load --input /tmp/securitydept-kube-test-images.tar | |
| - name: Run Rust e2e tests | |
| run: | | |
| mise exec --command "cargo test --workspace --test e2e --all-features" | |
| - name: Export kube test image cache | |
| if: steps.kube-test-image-cache.outputs.cache-hit != 'true' | |
| run: | | |
| docker save \ | |
| --output /tmp/securitydept-kube-test-images.tar \ | |
| securitydept-test/kindest-node:v1.31.2 \ | |
| securitydept-test/rancher-k3s:v1.31.4-k3s1 \ | |
| securitydept-realip-kube-integration-test-helper:v1 | |
| - name: Save kube test image cache | |
| if: steps.kube-test-image-cache.outputs.cache-hit != 'true' | |
| uses: actions/cache/save@v5 | |
| with: | |
| path: /tmp/securitydept-kube-test-images.tar | |
| key: ${{ steps.kube-test-image-cache.outputs.cache-primary-key }} | |
| ts-tests-e2e: | |
| if: needs.preflight.outputs.run_tests == 'true' | |
| needs: | |
| - preflight | |
| - node-deps | |
| - rust-tests-except-e2e | |
| - ts-tests-except-e2e | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v6 | |
| - name: Setup mise and pnpm dependencies | |
| uses: ./.github/actions/setup-mise-pnpm | |
| with: | |
| cache-mode: read-only | |
| - name: Restore Turbo test cache | |
| uses: actions/cache/restore@v5 | |
| with: | |
| path: .turbo | |
| key: turbo-${{ runner.os }}-${{ needs.preflight.outputs.cache_scope }}-test-${{ hashFiles('pnpm-lock.yaml', 'turbo.json') }}-${{ github.sha }} | |
| restore-keys: | | |
| turbo-${{ runner.os }}-${{ needs.preflight.outputs.cache_scope }}-test-${{ hashFiles('pnpm-lock.yaml', 'turbo.json') }}- | |
| - name: Restore Rust build cache | |
| uses: ./.github/actions/setup-rust-cache | |
| with: | |
| shared-key: securitydept-rust-${{ runner.os }}-${{ | |
| needs.preflight.outputs.cache_scope }}-debug | |
| cache-mode: read-only | |
| - name: Restore Playwright browser cache | |
| uses: actions/cache@v5 | |
| with: | |
| path: ~/.cache/ms-playwright | |
| key: playwright-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml', | |
| 'apps/webui/package.json') }} | |
| restore-keys: | | |
| playwright-${{ runner.os }}- | |
| - name: Install Playwright browsers and Linux dependencies | |
| run: mise exec -C apps/webui --command "pnpm exec playwright install --with-deps | |
| webkit chromium firefox" | |
| - name: Prebuild SecurityDept server for E2E | |
| run: mise exec --command "cargo build --manifest-path apps/server/Cargo.toml" | |
| - name: Run web UI end-to-end tests | |
| run: mise exec --command "pnpm e2e" | |
| tests-report: | |
| if: always() | |
| needs: | |
| - preflight | |
| - lint-and-typecheck | |
| - rust-tests-except-e2e | |
| - ts-tests-except-e2e | |
| - rs-tests-e2e | |
| - ts-tests-e2e | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Write tests workflow report | |
| shell: bash | |
| env: | |
| RUN_TESTS: ${{ needs.preflight.outputs.run_tests }} | |
| RELEASE_PREPARE_CANDIDATE: ${{ needs.preflight.outputs.release_prepare_candidate }} | |
| SOURCE_EVENT: ${{ needs.preflight.outputs.source_event }} | |
| SOURCE_REF: ${{ needs.preflight.outputs.source_ref }} | |
| SOURCE_REF_NAME: ${{ needs.preflight.outputs.source_ref_name }} | |
| SOURCE_SHA: ${{ needs.preflight.outputs.source_sha }} | |
| CACHE_SCOPE: ${{ needs.preflight.outputs.cache_scope }} | |
| REUSED_RUN_ID: ${{ needs.preflight.outputs.reused_run_id }} | |
| REUSED_RUN_URL: ${{ needs.preflight.outputs.reused_run_url }} | |
| LINT_RESULT: ${{ needs.lint-and-typecheck.result }} | |
| RUST_NOE2E_RESULT: ${{ needs.rust-tests-except-e2e.result }} | |
| TS_NOE2E_RESULT: ${{ needs.ts-tests-except-e2e.result }} | |
| RS_E2E_RESULT: ${{ needs.rs-tests-e2e.result }} | |
| TS_E2E_RESULT: ${{ needs.ts-tests-e2e.result }} | |
| run: | | |
| set -euo pipefail | |
| mkdir -p temp/release/tests | |
| cat > temp/release/tests/report.json <<EOF | |
| { | |
| "schemaVersion": 1, | |
| "createdAt": "$(date -u +%Y-%m-%dT%H:%M:%SZ)", | |
| "runTests": ${RUN_TESTS}, | |
| "releasePrepareCandidate": ${RELEASE_PREPARE_CANDIDATE}, | |
| "sourceEvent": "${SOURCE_EVENT}", | |
| "sourceRef": "${SOURCE_REF}", | |
| "sourceRefName": "${SOURCE_REF_NAME}", | |
| "sourceSha": "${SOURCE_SHA}", | |
| "cacheScope": "${CACHE_SCOPE}", | |
| "reusedRunId": "${REUSED_RUN_ID}", | |
| "reusedRunUrl": "${REUSED_RUN_URL}", | |
| "jobs": { | |
| "lintAndTypecheck": "${LINT_RESULT}", | |
| "rustTests": "${RUST_NOE2E_RESULT}", | |
| "tsTests": "${TS_NOE2E_RESULT}", | |
| "rsE2ETests": "${RS_E2E_RESULT}", | |
| "tsE2ETests": "${TS_E2E_RESULT}" | |
| } | |
| } | |
| EOF | |
| - name: Upload tests workflow report | |
| uses: actions/upload-artifact@v7 | |
| with: | |
| name: tests-workflow-report | |
| path: temp/release/tests/report.json | |
| - name: Enforce test job results | |
| if: needs.preflight.outputs.run_tests == 'true' | |
| shell: bash | |
| env: | |
| LINT_RESULT: ${{ needs.lint-and-typecheck.result }} | |
| RUST_NOE2E_RESULT: ${{ needs.rust-tests-except-e2e.result }} | |
| TS_NOE2E_RESULT: ${{ needs.ts-tests-except-e2e.result }} | |
| RS_E2E_RESULT: ${{ needs.rs-tests-e2e.result }} | |
| TS_E2E_RESULT: ${{ needs.ts-tests-e2e.result }} | |
| run: | | |
| set -euo pipefail | |
| for result in "${LINT_RESULT}" "${RUST_NOE2E_RESULT}" "${TS_NOE2E_RESULT}" "${RS_E2E_RESULT}" "${TS_E2E_RESULT}"; do | |
| if [[ "${result}" != "success" ]]; then | |
| echo "At least one test job failed or was skipped unexpectedly." >&2 | |
| exit 1 | |
| fi | |
| done | |
| dispatch-release: | |
| if: >- | |
| github.event_name == 'push' && | |
| needs.tests-report.result == 'success' && | |
| needs.preflight.outputs.release_prepare_candidate == 'true' && | |
| needs.preflight.outputs.source_ref == 'refs/heads/release' | |
| needs: | |
| - preflight | |
| - tests-report | |
| runs-on: ubuntu-latest | |
| permissions: | |
| actions: write | |
| contents: read | |
| steps: | |
| - name: Dispatch release workflow | |
| shell: bash | |
| env: | |
| GITHUB_TOKEN: ${{ github.token }} | |
| SOURCE_SHA: ${{ needs.preflight.outputs.source_sha }} | |
| run: | | |
| set -euo pipefail | |
| curl -fsS \ | |
| -X POST \ | |
| -H "Authorization: Bearer ${GITHUB_TOKEN}" \ | |
| -H "Accept: application/vnd.github+json" \ | |
| -H "Content-Type: application/json" \ | |
| -H "X-GitHub-Api-Version: 2022-11-28" \ | |
| "${GITHUB_API_URL}/repos/${GITHUB_REPOSITORY}/actions/workflows/release.yml/dispatches" \ | |
| -d @- <<EOF | |
| { | |
| "ref": "release", | |
| "inputs": { | |
| "source_ref": "refs/heads/release", | |
| "source_sha": "${SOURCE_SHA}", | |
| "publish_npm": "true", | |
| "publish_crates": "true", | |
| "publish_docker": "true" | |
| } | |
| } | |
| EOF |