feat: 增加安全自托管与回测一致性路径 #475
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| # 手动触发:pull_request 自动触发偶发不跑时,可在 Actions 页对任意分支重跑 CI。 | |
| workflow_dispatch: | |
| # PR 同分支新 push 取消旧 run(main 推送不取消,保证每个 commit 都跑) | |
| # Cancel in-progress runs on new pushes to the same PR branch; main pushes never cancel. | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| consistency: | |
| name: Cross-file consistency check / 跨文件一致性检验 | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Run check-consistency.sh | |
| run: bash scripts/check-consistency.sh | |
| - name: Validate self-host Compose | |
| run: | | |
| cp infra/.env.selfhost.example infra/.env.selfhost | |
| for key in POSTGRES_PASSWORD REDIS_PASSWORD JWT_SECRET LLM_CONFIG_ENCRYPTION_KEY; do | |
| sed -i "s/^${key}=.*/${key}=ci-test-secret/" infra/.env.selfhost | |
| done | |
| ENV_FILE=.env.selfhost docker compose -f infra/docker-compose.prod.yml -f infra/docker-compose.selfhost.yml --env-file infra/.env.selfhost config --quiet | |
| rm infra/.env.selfhost | |
| orchestration-typecheck: | |
| name: orchestration · typecheck + test | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: packages/orchestration | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: pnpm/action-setup@v4 | |
| with: | |
| version: 11 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "22" | |
| cache: pnpm | |
| cache-dependency-path: packages/orchestration/pnpm-lock.yaml | |
| - name: pnpm install | |
| run: pnpm install --frozen-lockfile | |
| - name: Type check | |
| run: pnpm typecheck | |
| - name: Unit tests | |
| run: pnpm test | |
| web-typecheck: | |
| name: web · typecheck + build | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: apps/web | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: pnpm/action-setup@v4 | |
| with: | |
| version: 11 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "22" | |
| cache: pnpm | |
| cache-dependency-path: apps/web/pnpm-lock.yaml | |
| - name: pnpm install | |
| run: pnpm install --frozen-lockfile | |
| - name: Type check | |
| run: pnpm typecheck | |
| - name: Static export build | |
| run: pnpm build | |
| dashboard-typecheck: | |
| name: dashboard · typecheck + build | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: apps/dashboard | |
| steps: | |
| - uses: actions/checkout@v4 | |
| # 钉 11.1.2(= packageManager):`version: 11` 取最新 11.x 不认 package.json 的 | |
| # pnpm.onlyBuiltDependencies → @swc/core/sharp/@parcel-watcher build script 被判 | |
| # ignored 后 install exit 1。11.1.2 认该字段(全新 store 实测 exit 0)。 | |
| - uses: pnpm/action-setup@v4 | |
| with: | |
| version: 11.1.2 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "22" | |
| cache: pnpm | |
| cache-dependency-path: apps/dashboard/pnpm-lock.yaml | |
| - name: pnpm install | |
| run: pnpm install --frozen-lockfile | |
| - name: Type check | |
| run: pnpm typecheck | |
| - name: Unit tests | |
| run: pnpm test | |
| - name: Build (Next.js dynamic app) | |
| run: pnpm build | |
| python-services-lint: | |
| name: python services · ruff + mypy | |
| runs-on: ubuntu-latest | |
| strategy: | |
| matrix: | |
| service: [data, paper, research, factor] | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Install uv | |
| uses: astral-sh/setup-uv@v3 | |
| with: | |
| enable-cache: true | |
| - name: Set up Python | |
| run: uv python install 3.12 | |
| - name: Sync dependencies | |
| working-directory: services/${{ matrix.service }} | |
| run: uv sync --frozen | |
| - name: Ruff | |
| working-directory: services/${{ matrix.service }} | |
| run: uv run ruff check . | |
| - name: Mypy (best-effort, allow failure) | |
| working-directory: services/${{ matrix.service }} | |
| run: uv run mypy . || true |