v0.2.0 fix: 收口 E1 审批授权与幂等审计 #523
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| # 手动触发:pull_request 自动触发偶发不跑时,可在 Actions 页对任意分支重跑 CI。 | |
| workflow_dispatch: | |
| # PR 同分支新 push 取消旧 run(main 推送不取消,保证每个 commit 都跑) | |
| # Cancel in-progress runs on new pushes to the same PR branch; main pushes never cancel. | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| consistency: | |
| name: Cross-file consistency check / 跨文件一致性检验 | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Run check-consistency.sh | |
| run: bash scripts/check-consistency.sh | |
| - name: Validate self-host Compose | |
| run: | | |
| bash scripts/selfhost.sh init | |
| test "$(stat --format=%a infra/.env.selfhost)" = "600" | |
| ! grep -Eq '__[A-Z_]+__' infra/.env.selfhost | |
| ENV_FILE=.env.selfhost docker compose -f infra/docker-compose.prod.yml -f infra/docker-compose.selfhost.yml --env-file infra/.env.selfhost config --quiet | |
| rm infra/.env.selfhost | |
| selfhost-smoke: | |
| name: self-host · build + health smoke | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Initialize self-host environment | |
| run: | | |
| bash scripts/selfhost.sh init | |
| test "$(stat --format=%a infra/.env.selfhost)" = "600" | |
| ! grep -Eq '__[A-Z_]+__' infra/.env.selfhost | |
| - name: Build and start self-host stack | |
| run: | | |
| docker compose -f infra/docker-compose.prod.yml -f infra/docker-compose.selfhost.yml --env-file infra/.env.selfhost build | |
| docker compose -f infra/docker-compose.prod.yml -f infra/docker-compose.selfhost.yml --env-file infra/.env.selfhost up -d --wait --wait-timeout 600 | |
| - name: Create self-host user | |
| run: | | |
| printf 'smoke-password' | docker compose -f infra/docker-compose.prod.yml -f infra/docker-compose.selfhost.yml --env-file infra/.env.selfhost run --rm -T paper \ | |
| uv run python scripts/create_user.py --email smoke@example.invalid --subject console:smoke --password-stdin | |
| - name: Diagnose failed self-host smoke | |
| if: failure() | |
| run: | | |
| docker compose -f infra/docker-compose.prod.yml -f infra/docker-compose.selfhost.yml --env-file infra/.env.selfhost ps | |
| docker compose -f infra/docker-compose.prod.yml -f infra/docker-compose.selfhost.yml --env-file infra/.env.selfhost logs | |
| - name: Remove self-host stack | |
| if: always() | |
| run: docker compose -f infra/docker-compose.prod.yml -f infra/docker-compose.selfhost.yml --env-file infra/.env.selfhost down -v --remove-orphans | |
| orchestration-typecheck: | |
| name: orchestration · typecheck + test | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: packages/orchestration | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: pnpm/action-setup@v4 | |
| with: | |
| version: 11 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "22" | |
| cache: pnpm | |
| cache-dependency-path: packages/orchestration/pnpm-lock.yaml | |
| - name: pnpm install | |
| run: pnpm install --frozen-lockfile | |
| - name: Type check | |
| run: pnpm typecheck | |
| - name: Unit tests | |
| run: pnpm test | |
| orchestration-agent-eval: | |
| name: orchestration · agent eval | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| defaults: | |
| run: | |
| working-directory: packages/orchestration | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: pnpm/action-setup@v4 | |
| with: | |
| version: 11 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "22" | |
| cache: pnpm | |
| cache-dependency-path: packages/orchestration/pnpm-lock.yaml | |
| - name: pnpm install | |
| run: pnpm install --frozen-lockfile | |
| - name: Run offline agent evals | |
| run: pnpm eval:pr -- --report "$RUNNER_TEMP/agent-eval-pr.json" | |
| - name: Upload agent eval report | |
| if: always() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: agent-eval-pr | |
| path: ${{ runner.temp }}/agent-eval-pr.json | |
| if-no-files-found: warn | |
| retention-days: 14 | |
| web-typecheck: | |
| name: web · typecheck + build | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: apps/web | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: pnpm/action-setup@v4 | |
| with: | |
| version: 11.1.2 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "22" | |
| cache: pnpm | |
| cache-dependency-path: apps/web/pnpm-lock.yaml | |
| - name: pnpm install | |
| run: pnpm install --frozen-lockfile | |
| - name: Type check | |
| run: pnpm typecheck | |
| - name: Unit tests | |
| run: pnpm test | |
| - name: Static export build | |
| run: pnpm build | |
| - name: Static export checks | |
| run: pnpm test:export | |
| dashboard-typecheck: | |
| name: dashboard · typecheck + build | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: apps/dashboard | |
| steps: | |
| - uses: actions/checkout@v4 | |
| # 钉 11.1.2(= packageManager):`version: 11` 取最新 11.x 不认 package.json 的 | |
| # pnpm.onlyBuiltDependencies → @swc/core/sharp/@parcel-watcher build script 被判 | |
| # ignored 后 install exit 1。11.1.2 认该字段(全新 store 实测 exit 0)。 | |
| - uses: pnpm/action-setup@v4 | |
| with: | |
| version: 11.1.2 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "22" | |
| cache: pnpm | |
| cache-dependency-path: apps/dashboard/pnpm-lock.yaml | |
| - name: pnpm install | |
| run: pnpm install --frozen-lockfile | |
| - name: Type check | |
| run: pnpm typecheck | |
| - name: Unit tests | |
| run: pnpm test | |
| - name: Build (Next.js dynamic app) | |
| run: pnpm build | |
| python-services-lint: | |
| name: python services · ruff + mypy | |
| runs-on: ubuntu-latest | |
| strategy: | |
| matrix: | |
| service: [data, paper, research, factor, evolver] | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Install uv | |
| uses: astral-sh/setup-uv@v3 | |
| with: | |
| enable-cache: true | |
| - name: Set up Python | |
| run: uv python install 3.12 | |
| - name: Sync dependencies | |
| working-directory: services/${{ matrix.service }} | |
| run: uv sync --frozen | |
| - name: Ruff | |
| working-directory: services/${{ matrix.service }} | |
| run: uv run ruff check . | |
| - name: Mypy (best-effort, allow failure) | |
| working-directory: services/${{ matrix.service }} | |
| run: uv run mypy . || true | |
| python-e1-tests: | |
| name: E1 · ${{ matrix.service }} pytest | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| service: [paper, evolver] | |
| services: | |
| timescaledb: | |
| image: timescale/timescaledb:2.27.2-pg17 | |
| env: | |
| POSTGRES_USER: quant | |
| POSTGRES_PASSWORD: devpass | |
| POSTGRES_DB: inalpha_migration_ci_test | |
| ports: | |
| - 5432:5432 | |
| options: >- | |
| --health-cmd "pg_isready -U quant -d inalpha_migration_ci_test" | |
| --health-interval 5s | |
| --health-timeout 5s | |
| --health-retries 20 | |
| env: | |
| DATABASE_URL: postgresql+psycopg://quant:devpass@localhost:5432/inalpha_test | |
| INALPHA_MIGRATION_TEST_DATABASE_URL: postgresql+psycopg://quant:devpass@localhost:5432/inalpha_migration_ci_test | |
| EVOLVER_TEST_DATABASE_URL: postgresql+psycopg://quant:devpass@localhost:5432/inalpha_migration_ci_test | |
| JWT_SECRET: test-secret-do-not-use-in-prod-please-and-thank-you | |
| DATA_SERVICE_URL: http://data-mock.test | |
| PAPER_POOL_DISABLED: "1" | |
| INALPHA_LIVE_RUNNER_RESUME_ON_STARTUP: "false" | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Install uv | |
| uses: astral-sh/setup-uv@v3 | |
| with: | |
| enable-cache: true | |
| - name: Set up Python | |
| run: uv python install 3.12 | |
| - name: Sync dependencies | |
| working-directory: services/${{ matrix.service }} | |
| run: uv sync --frozen | |
| - name: Apply schema for Evolver tests | |
| if: matrix.service == 'evolver' | |
| working-directory: infra/migrations | |
| run: uv run --project ../../services/evolver alembic upgrade head | |
| env: | |
| DATABASE_URL: postgresql+psycopg://quant:devpass@localhost:5432/inalpha_migration_ci_test | |
| - name: Run service tests | |
| working-directory: services/${{ matrix.service }} | |
| run: uv run pytest -q tests | |
| - name: Verify migration round trip | |
| if: matrix.service == 'evolver' | |
| working-directory: services/evolver | |
| run: uv run pytest -q ../../infra/migrations/tests/test_migration_0038.py |