polish: a fresh box before setup is a state, not an error #22
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Cross-platform proof: the panel must COMPILE and BOOT on every OS a | |
| # self-hoster might own. All three legs now run the same bar — build, then | |
| # boot the real server against an empty layout and serve /api/health (the | |
| # shape of a first-run install). The client/join gates pick their display | |
| # mode at runtime: xvfb on headless Linux, a small visible window on | |
| # desktop OSes, an honest skip where no display exists. | |
| name: ci | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| jobs: | |
| build: | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, windows-latest, macos-latest] | |
| node: [22] | |
| runs-on: ${{ matrix.os }} | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: ${{ matrix.node }} | |
| cache: npm | |
| - run: npm ci | |
| - run: npm run build -w server | |
| - run: npm run build -w web | |
| # smoke 1: the built server must load its entrypoint cleanly | |
| - run: node -e "import('./server/dist/config.js').then(m => { if (!m.PATHS) throw new Error('config failed'); console.log('config loads on', process.platform); })" | |
| # smoke 2: boot the real panel on an empty layout and hit /api/health | |
| - run: node .github/smoke-boot.mjs | |
| # smoke 3: the whole first-run story — wizard active on an empty layout, | |
| # Crafty admin login mints + persists the token (stub Crafty), wizard | |
| # turns itself off, PIN step returns a cookie that validates | |
| - run: node .github/wizard-e2e.mjs | |
| # the repo is public — every push gets a full-history secret scan | |
| gitleaks: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - uses: gitleaks/gitleaks-action@v2 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} |