Skip to content

refactor: refactor tests && registry multiplex authevents and errors #47

refactor: refactor tests && registry multiplex authevents and errors

refactor: refactor tests && registry multiplex authevents and errors #47

Workflow file for this run

name: Tests
on:
push:
branches:
- main
- release
tags:
- "v*.*.*"
paths-ignore:
- "**/*.md"
- "**/*.kdl"
- "assets/**"
- "LICENSE"
- "LICENSE.md"
- "AGENTS.md"
pull_request:
branches:
- main
paths-ignore:
- "**/*.md"
- "**/*.kdl"
- "assets/**"
- "LICENSE"
- "LICENSE.md"
- "AGENTS.md"
workflow_dispatch:
permissions:
contents: read
actions: read
concurrency:
group: tests-${{ github.ref }}
cancel-in-progress: true
jobs:
preflight:
runs-on: ubuntu-latest
outputs:
run_tests: ${{ steps.preflight.outputs.run_tests }}
release_prepare_candidate: ${{ steps.preflight.outputs.release_prepare_candidate }}
source_event: ${{ steps.preflight.outputs.source_event }}
source_ref: ${{ steps.preflight.outputs.source_ref }}
source_ref_name: ${{ steps.preflight.outputs.source_ref_name }}
source_sha: ${{ steps.preflight.outputs.source_sha }}
cache_scope: ${{ steps.preflight.outputs.cache_scope }}
reused_run_id: ${{ steps.preflight.outputs.reused_run_id }}
reused_run_url: ${{ steps.preflight.outputs.reused_run_url }}
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Setup mise and pnpm dependencies
uses: ./.github/actions/setup-mise-pnpm
with:
cache-mode: read-write
- name: Resolve tests preflight
id: preflight
env:
GITHUB_TOKEN: ${{ github.token }}
run: >-
mise exec --command "node scripts/release-cli.ts workflow
tests-preflight --format=github-output"
node-deps:
if: needs.preflight.outputs.run_tests == 'true'
needs: preflight
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Setup mise and pnpm dependencies
uses: ./.github/actions/setup-mise-pnpm
with:
cache-mode: read-only
rust-debug-cache-prime:
if: needs.preflight.outputs.run_tests == 'true'
needs:
- preflight
- node-deps
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Setup mise and pnpm dependencies
uses: ./.github/actions/setup-mise-pnpm
with:
cache-mode: read-only
- name: Restore Rust debug build cache
uses: ./.github/actions/setup-rust-cache
with:
shared-key: securitydept-rust-${{ runner.os }}-${{
needs.preflight.outputs.cache_scope }}-debug
cache-mode: read-write
- name: Prime Rust debug build cache
run: mise exec --command "cargo build --workspace --all-features --all-targets"
lint-and-typecheck:
if: needs.preflight.outputs.run_tests == 'true'
needs:
- preflight
- node-deps
- rust-debug-cache-prime
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Setup mise and pnpm dependencies
uses: ./.github/actions/setup-mise-pnpm
with:
cache-mode: read-only
- name: Lint repository
run: mise exec --command "pnpm lint"
- name: Typecheck repository
run: mise exec --command "pnpm typecheck"
- name: Restore Rust build cache
uses: ./.github/actions/setup-rust-cache
with:
shared-key: securitydept-rust-${{ runner.os }}-${{
needs.preflight.outputs.cache_scope }}-debug
cache-mode: read-only
- name: Lint Rust workspace
run: mise exec --command "cargo clippy --workspace --all-features"
rust-tests-except-e2e:
if: needs.preflight.outputs.run_tests == 'true'
needs:
- preflight
- node-deps
- rust-debug-cache-prime
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Setup mise and pnpm dependencies
uses: ./.github/actions/setup-mise-pnpm
with:
cache-mode: read-only
- name: Restore Rust build cache
uses: ./.github/actions/setup-rust-cache
with:
shared-key: securitydept-rust-${{ runner.os }}-${{
needs.preflight.outputs.cache_scope }}-debug
cache-mode: read-only
- name: Run Rust unit tests
run: |
mise exec --command "cargo test --workspace --lib --bins --all-features"
mise exec --command "cargo test --workspace --doc --all-features"
- name: Run Rust integration tests
run: |
mise exec --command "cargo test --workspace --test integration --all-features"
ts-tests-except-e2e:
if: needs.preflight.outputs.run_tests == 'true'
needs:
- preflight
- node-deps
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Setup mise and pnpm dependencies
uses: ./.github/actions/setup-mise-pnpm
with:
cache-mode: read-only
- name: Restore Turbo test cache
id: turbo-test-cache
uses: actions/cache/restore@v5
with:
path: .turbo
key: turbo-${{ runner.os }}-${{ needs.preflight.outputs.cache_scope }}-test-${{ hashFiles('pnpm-lock.yaml', 'turbo.json') }}-${{ github.sha }}
restore-keys: |
turbo-${{ runner.os }}-${{ needs.preflight.outputs.cache_scope }}-test-${{ hashFiles('pnpm-lock.yaml', 'turbo.json') }}-
- name: Test TypeScript workspace
run: mise exec --command "pnpm test"
- name: Save Turbo test cache
if: steps.turbo-test-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@v5
with:
path: .turbo
key: ${{ steps.turbo-test-cache.outputs.cache-primary-key }}
rs-tests-e2e:
if: needs.preflight.outputs.run_tests == 'true'
needs:
- preflight
- node-deps
- rust-tests-except-e2e
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Setup mise and pnpm dependencies
uses: ./.github/actions/setup-mise-pnpm
with:
cache-mode: read-only
- name: Restore Rust build cache
uses: ./.github/actions/setup-rust-cache
with:
shared-key: securitydept-rust-${{ runner.os }}-${{
needs.preflight.outputs.cache_scope }}-debug
cache-mode: read-only
- name: Restore kube test image cache
id: kube-test-image-cache
uses: actions/cache/restore@v5
with:
path: /tmp/securitydept-kube-test-images.tar
key: kube-test-images-${{ runner.os }}-${{ hashFiles('packages/realip/tests/fixtures/kube-helper/Dockerfile', 'packages/realip/tests/e2e/kube_provider.rs', 'scripts/lib/kube-test-resources.ts') }}
- name: Load cached kube test images
if: steps.kube-test-image-cache.outputs.cache-hit == 'true'
run: docker load --input /tmp/securitydept-kube-test-images.tar
- name: Run Rust e2e tests
run: |
mise exec --command "cargo test --workspace --test e2e --all-features"
- name: Export kube test image cache
if: steps.kube-test-image-cache.outputs.cache-hit != 'true'
run: |
docker save \
--output /tmp/securitydept-kube-test-images.tar \
securitydept-test/kindest-node:v1.31.2 \
securitydept-test/rancher-k3s:v1.31.4-k3s1 \
securitydept-realip-kube-integration-test-helper:v1
- name: Save kube test image cache
if: steps.kube-test-image-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@v5
with:
path: /tmp/securitydept-kube-test-images.tar
key: ${{ steps.kube-test-image-cache.outputs.cache-primary-key }}
ts-tests-e2e:
if: needs.preflight.outputs.run_tests == 'true'
needs:
- preflight
- node-deps
- rust-tests-except-e2e
- ts-tests-except-e2e
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Setup mise and pnpm dependencies
uses: ./.github/actions/setup-mise-pnpm
with:
cache-mode: read-only
- name: Restore Turbo test cache
uses: actions/cache/restore@v5
with:
path: .turbo
key: turbo-${{ runner.os }}-${{ needs.preflight.outputs.cache_scope }}-test-${{ hashFiles('pnpm-lock.yaml', 'turbo.json') }}-${{ github.sha }}
restore-keys: |
turbo-${{ runner.os }}-${{ needs.preflight.outputs.cache_scope }}-test-${{ hashFiles('pnpm-lock.yaml', 'turbo.json') }}-
- name: Restore Rust build cache
uses: ./.github/actions/setup-rust-cache
with:
shared-key: securitydept-rust-${{ runner.os }}-${{
needs.preflight.outputs.cache_scope }}-debug
cache-mode: read-only
- name: Restore Playwright browser cache
uses: actions/cache@v5
with:
path: ~/.cache/ms-playwright
key: playwright-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml',
'apps/webui/package.json') }}
restore-keys: |
playwright-${{ runner.os }}-
- name: Install Playwright browsers and Linux dependencies
run: mise exec -C apps/webui --command "pnpm exec playwright install --with-deps
webkit chromium firefox"
- name: Prebuild SecurityDept server for E2E
run: mise exec --command "cargo build --manifest-path apps/server/Cargo.toml"
- name: Run web UI end-to-end tests
run: mise exec --command "pnpm e2e"
tests-report:
if: always()
needs:
- preflight
- lint-and-typecheck
- rust-tests-except-e2e
- ts-tests-except-e2e
- rs-tests-e2e
- ts-tests-e2e
runs-on: ubuntu-latest
steps:
- name: Write tests workflow report
shell: bash
env:
RUN_TESTS: ${{ needs.preflight.outputs.run_tests }}
RELEASE_PREPARE_CANDIDATE: ${{ needs.preflight.outputs.release_prepare_candidate }}
SOURCE_EVENT: ${{ needs.preflight.outputs.source_event }}
SOURCE_REF: ${{ needs.preflight.outputs.source_ref }}
SOURCE_REF_NAME: ${{ needs.preflight.outputs.source_ref_name }}
SOURCE_SHA: ${{ needs.preflight.outputs.source_sha }}
CACHE_SCOPE: ${{ needs.preflight.outputs.cache_scope }}
REUSED_RUN_ID: ${{ needs.preflight.outputs.reused_run_id }}
REUSED_RUN_URL: ${{ needs.preflight.outputs.reused_run_url }}
LINT_RESULT: ${{ needs.lint-and-typecheck.result }}
RUST_NOE2E_RESULT: ${{ needs.rust-tests-except-e2e.result }}
TS_NOE2E_RESULT: ${{ needs.ts-tests-except-e2e.result }}
RS_E2E_RESULT: ${{ needs.rs-tests-e2e.result }}
TS_E2E_RESULT: ${{ needs.ts-tests-e2e.result }}
run: |
set -euo pipefail
mkdir -p temp/release/tests
cat > temp/release/tests/report.json <<EOF
{
"schemaVersion": 1,
"createdAt": "$(date -u +%Y-%m-%dT%H:%M:%SZ)",
"runTests": ${RUN_TESTS},
"releasePrepareCandidate": ${RELEASE_PREPARE_CANDIDATE},
"sourceEvent": "${SOURCE_EVENT}",
"sourceRef": "${SOURCE_REF}",
"sourceRefName": "${SOURCE_REF_NAME}",
"sourceSha": "${SOURCE_SHA}",
"cacheScope": "${CACHE_SCOPE}",
"reusedRunId": "${REUSED_RUN_ID}",
"reusedRunUrl": "${REUSED_RUN_URL}",
"jobs": {
"lintAndTypecheck": "${LINT_RESULT}",
"rustTests": "${RUST_NOE2E_RESULT}",
"tsTests": "${TS_NOE2E_RESULT}",
"rsE2ETests": "${RS_E2E_RESULT}",
"tsE2ETests": "${TS_E2E_RESULT}"
}
}
EOF
- name: Upload tests workflow report
uses: actions/upload-artifact@v7
with:
name: tests-workflow-report
path: temp/release/tests/report.json
- name: Enforce test job results
if: needs.preflight.outputs.run_tests == 'true'
shell: bash
env:
LINT_RESULT: ${{ needs.lint-and-typecheck.result }}
RUST_NOE2E_RESULT: ${{ needs.rust-tests-except-e2e.result }}
TS_NOE2E_RESULT: ${{ needs.ts-tests-except-e2e.result }}
RS_E2E_RESULT: ${{ needs.rs-tests-e2e.result }}
TS_E2E_RESULT: ${{ needs.ts-tests-e2e.result }}
run: |
set -euo pipefail
for result in "${LINT_RESULT}" "${RUST_NOE2E_RESULT}" "${TS_NOE2E_RESULT}" "${RS_E2E_RESULT}" "${TS_E2E_RESULT}"; do
if [[ "${result}" != "success" ]]; then
echo "At least one test job failed or was skipped unexpectedly." >&2
exit 1
fi
done
dispatch-release:
if: >-
github.event_name == 'push' &&
needs.tests-report.result == 'success' &&
needs.preflight.outputs.release_prepare_candidate == 'true' &&
needs.preflight.outputs.source_ref == 'refs/heads/release'
needs:
- preflight
- tests-report
runs-on: ubuntu-latest
permissions:
actions: write
contents: read
steps:
- name: Dispatch release workflow
shell: bash
env:
GITHUB_TOKEN: ${{ github.token }}
SOURCE_SHA: ${{ needs.preflight.outputs.source_sha }}
run: |
set -euo pipefail
curl -fsS \
-X POST \
-H "Authorization: Bearer ${GITHUB_TOKEN}" \
-H "Accept: application/vnd.github+json" \
-H "Content-Type: application/json" \
-H "X-GitHub-Api-Version: 2022-11-28" \
"${GITHUB_API_URL}/repos/${GITHUB_REPOSITORY}/actions/workflows/release.yml/dispatches" \
-d @- <<EOF
{
"ref": "release",
"inputs": {
"source_ref": "refs/heads/release",
"source_sha": "${SOURCE_SHA}",
"publish_npm": "true",
"publish_crates": "true",
"publish_docker": "true"
}
}
EOF