-
Notifications
You must be signed in to change notification settings - Fork 38
400 lines (374 loc) · 13.3 KB
/
Copy pathtests.yml
File metadata and controls
400 lines (374 loc) · 13.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
name: Tests
on:
pull_request:
push:
branches: [master]
# Cancel a superseded run when new commits are pushed to the same PR. Besides saving
# CI minutes, this closes the narrow window where two overlapping runs of the same
# branch could publish a new runtime-log cache mid-matrix and desync the 8-way split.
# Push runs on master are never cancelled, so every master run persists its log.
concurrency:
group: tests-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
gems-caching:
name: GEMs caching
runs-on: ubuntu-latest
container: ghcr.io/yeti-switch/yeti-web/build-image:trixie
steps:
- uses: actions/checkout@v6
- name: Fetching gems cache
uses: actions/cache@v5
with:
path: |
vendor
.bundle
/opt/yeti-web/vendor/rbenv
key: gems-deb13-${{runner.os}}-${{hashFiles('Gemfile.lock')}}-${{hashFiles('.ruby-version')}}
- name: install gems
run: make gems-test
- name: verify production gems install
run: make gems
- name: Caching gems
uses: actions/cache@v5
with:
path: |
vendor
.bundle
/opt/yeti-web/vendor/rbenv
key: gems-deb13-${{runner.os}}-${{hashFiles('Gemfile.lock')}}-${{hashFiles('.ruby-version')}}
lint:
name: Rubocop
runs-on: ubuntu-latest
container: ghcr.io/yeti-switch/yeti-web/build-image:trixie
needs: gems-caching
steps:
- uses: actions/checkout@v6
- name: use cache
uses: actions/cache@v5
with:
path: |
vendor
.bundle
/opt/yeti-web/vendor/rbenv
key: gems-deb13-${{runner.os}}-${{hashFiles('Gemfile.lock')}}-${{hashFiles('.ruby-version')}}
- name: Rubocop
run: make lint
audit:
name: Bundle audit
runs-on: ubuntu-latest
container: ghcr.io/yeti-switch/yeti-web/build-image:trixie
needs: gems-caching
steps:
- uses: actions/checkout@v6
- name: use cache
uses: actions/cache@v5
with:
path: |
vendor
.bundle
/opt/yeti-web/vendor/rbenv
key: gems-deb13-${{runner.os}}-${{hashFiles('Gemfile.lock')}}-${{hashFiles('.ruby-version')}}
- name: Bundle audit
run: make audit
database_consistency:
name: DB consistency check
runs-on: ubuntu-latest
container: ghcr.io/yeti-switch/yeti-web/build-image:trixie
services:
db:
image: ghcr.io/yeti-switch/yeti-web/pgsql:18
needs: gems-caching
steps:
- uses: actions/checkout@v6
- name: use cache
uses: actions/cache@v5
with:
path: |
vendor
.bundle
/opt/yeti-web/vendor/rbenv
key: gems-deb13-${{runner.os}}-${{hashFiles('Gemfile.lock')}}-${{hashFiles('.ruby-version')}}
- name: run make database_consistency
continue-on-error: true
run: make database_consistency
env:
YETI_DB_HOST: db
YETI_DB_PORT: 5432
CDR_DB_HOST: db
CDR_DB_PORT: 5432
SEED_WORKERS: 4
- name: Save artifacts
if: always()
uses: actions/upload-artifact@v6
with:
name: database_consistency-artifacts
if-no-files-found: ignore
include-hidden-files: true
path: |
log/
annotations:
name: Model annotations
runs-on: ubuntu-latest
container: ghcr.io/yeti-switch/yeti-web/build-image:trixie
services:
db:
image: ghcr.io/yeti-switch/yeti-web/pgsql:18
needs: gems-caching
steps:
- uses: actions/checkout@v6
- name: use cache
uses: actions/cache@v5
with:
path: |
vendor
.bundle
/opt/yeti-web/vendor/rbenv
key: gems-deb13-${{runner.os}}-${{hashFiles('Gemfile.lock')}}-${{hashFiles('.ruby-version')}}
- name: run make annotations
run: make annotations
env:
YETI_DB_HOST: db
YETI_DB_PORT: 5432
CDR_DB_HOST: db
CDR_DB_PORT: 5432
SEED_WORKERS: 4
brakeman:
name: Brakeman
runs-on: ubuntu-latest
container: ghcr.io/yeti-switch/yeti-web/build-image:trixie
needs: gems-caching
steps:
- uses: actions/checkout@v6
- name: use cache
uses: actions/cache@v5
with:
path: |
vendor
.bundle
/opt/yeti-web/vendor/rbenv
key: gems-deb13-${{runner.os}}-${{hashFiles('Gemfile.lock')}}-${{hashFiles('.ruby-version')}}
- name: brakeman
continue-on-error: true
run: make brakeman
rspec:
name: Rspec tests
runs-on: ubuntu-latest
container: ghcr.io/yeti-switch/yeti-web/build-image:trixie
services:
db:
image: ghcr.io/yeti-switch/yeti-web/pgsql:18
needs: gems-caching
strategy:
fail-fast: false
matrix:
# Set N number of parallel jobs you want to run tests on.
# Use higher number if you have slow tests to split them on more parallel jobs.
# Remember to update ci_node_index below to 0..N-1
ci_node_total: [8]
# set N-1 indexes for parallel jobs
# When you run 2 parallel jobs then first job will have index 0, the second job will have index 1 etc
ci_node_index: [0, 1, 2, 3, 4, 5, 6, 7]
steps:
- uses: actions/checkout@v6
- name: use cache
uses: actions/cache@v5
with:
path: |
vendor
.bundle
/opt/yeti-web/vendor/rbenv
key: gems-deb13-${{runner.os}}-${{hashFiles('Gemfile.lock')}}-${{hashFiles('.ruby-version')}}
- name: Clear tmp cache
run: rm -rf tmp
# Exact key never hits (keyed by this run's sha); the restore-keys prefix picks the
# newest rspec-runtime-* cache visible to this ref — the PR's own previous run
# first, then master's. Missing on a brand-new branch => filesize fallback in the
# Makefile (safe).
- name: Restore rspec runtime log
uses: actions/cache/restore@v5
with:
path: log/parallel_runtime_rspec_full.log
key: rspec-runtime-${{ github.sha }}
restore-keys: |
rspec-runtime-
- name: Run rspec
run: make rspec
env:
PARALLEL_TEST_PROCESSORS: ${{ matrix.ci_node_total }}
TEST_GROUP: ${{ matrix.ci_node_index }}
RSPEC_RUNTIME_LOG: log/parallel_runtime_rspec_full.log
YETI_DB_HOST: db
YETI_DB_PORT: 5432
CDR_DB_HOST: db
CDR_DB_PORT: 5432
CI: true
SEED_WORKERS: 4
- name: Save artifacts
if: always()
uses: actions/upload-artifact@v6
with:
name: rspec-artifacts-${{matrix.ci_node_index}}
if-no-files-found: ignore
include-hidden-files: true
path: |
tmp/capybara
coverage
- name: Upload runtime log slice
if: always()
uses: actions/upload-artifact@v6
with:
name: rspec-runtime-${{ matrix.ci_node_index }}
path: log/parallel_runtime_rspec.log
if-no-files-found: ignore
# Merge the 8 per-group partial runtime logs into one complete log and persist it via
# cache for the next run's runtime-based grouping. Runs on PRs too: GitHub scopes
# caches per branch, so a PR's log lands in the PR's own scope (it cannot poison
# master's) and later runs of that PR read it first, falling back to master's log via
# the restore-keys prefix. Fork PRs get read-only cache access, so their save no-ops
# and they keep reading master's log. Gated on !cancelled() (not success()) so a
# single flaky matrix node does not skip persistence — every finished node's slice
# (uploaded with if: always()) still merges in.
rspec_runtime_log:
name: Persist rspec runtime log
runs-on: ubuntu-latest
# MUST run in the same container as the rspec jobs. actions/cache versions each
# entry by (path + compression method); the trixie image has no zstd, so the rspec
# jobs save/restore with gzip (cache.tgz). A bare ubuntu-latest host has zstd and
# would save this log with zstd (cache.tzst) under a DIFFERENT version — invisible
# to the gzip restore in the rspec job ("Cache not found" despite matching key+ref),
# so runtime grouping silently never activates and the split falls back to filesize.
container: ghcr.io/yeti-switch/yeti-web/build-image:trixie
needs: rspec
if: ${{ !cancelled() }}
steps:
- uses: actions/download-artifact@v4
with:
pattern: rspec-runtime-*
path: runtime-slices
- name: Merge slices
# Write to log/ so the saved path matches the path the rspec job restores
# with. actions/cache derives its cache version from the path input, so a
# mismatched save/restore path would never resolve (and would extract to
# the wrong location on a hit).
run: |
mkdir -p log
cat runtime-slices/*/parallel_runtime_rspec.log > log/parallel_runtime_rspec_full.log
- uses: actions/cache/save@v5
with:
path: log/parallel_runtime_rspec_full.log
key: rspec-runtime-${{ github.sha }}
- name: Report slowest spec files
# Print the top 50 slowest spec files (from the merged runtime log) to the job
# log and the run summary, so heavy files can be spotted for future splitting.
# Runs after the cache save so a reporting glitch never blocks log persistence.
# `awk 'NR<=50'` (not `head`) reads the full stream so the sort pipeline cannot
# SIGPIPE-fail under `set -o pipefail`.
run: |
log=log/parallel_runtime_rspec_full.log
if [ ! -s "$log" ]; then
echo "No runtime log to report."
exit 0
fi
total=$(wc -l < "$log")
# Runtime-log lines are "path:seconds"; split on the LAST colon so paths with
# colons still parse. Emit "seconds<TAB>path", sort desc, keep the top 50.
rows=$(awk -F: '{ sec=$NF; path=substr($0,1,length($0)-length($NF)-1); printf "%s\t%s\n", sec, path }' "$log" \
| sort -rn \
| awk 'NR<=50')
echo "Top 50 slowest spec files (of $total total):"
echo "$rows" | awk -F'\t' '{ printf "%3d %8.1fs %s\n", NR, $1, $2 }'
{
echo "## Slowest spec files (top 50 of $total)"
echo ""
echo "| # | seconds | file |"
echo "|--:|--------:|------|"
echo "$rows" | awk -F'\t' '{ printf "| %d | %.1f | %s |\n", NR, $1, $2 }'
} >> "$GITHUB_STEP_SUMMARY"
rspec_oidc:
name: Rspec tests for OIDC auth
runs-on: ubuntu-latest
container: ghcr.io/yeti-switch/yeti-web/build-image:trixie
services:
db:
image: ghcr.io/yeti-switch/yeti-web/pgsql:18
needs: gems-caching
strategy:
fail-fast: false
steps:
- uses: actions/checkout@v6
- name: use cache
uses: actions/cache@v5
with:
path: |
vendor
.bundle
/opt/yeti-web/vendor/rbenv
key: gems-deb13-${{runner.os}}-${{hashFiles('Gemfile.lock')}}-${{hashFiles('.ruby-version')}}
- name: Run rspec
run: cp -v config/oidc.yml.distr config/oidc.yml && make rspec
env:
PARALLEL_TEST_PROCESSORS: 1
TEST_GROUP: 0
YETI_DB_HOST: db
YETI_DB_PORT: 5432
CDR_DB_HOST: db
CDR_DB_PORT: 5432
CI: true
CI_RUN_OIDC: true
SEED_WORKERS: 4
- name: Save artifacts
if: always()
uses: actions/upload-artifact@v6
with:
name: rspec-artifacts-oidc
if-no-files-found: ignore
include-hidden-files: true
path: |
tmp/capybara
coverage
coverage:
name: Coverage
runs-on: ubuntu-latest
container: ghcr.io/yeti-switch/yeti-web/build-image:trixie
needs:
- gems-caching
- rspec
- rspec_oidc
steps:
- uses: actions/checkout@v6
- name: use cache
uses: actions/cache@v5
with:
path: |
vendor
.bundle
/opt/yeti-web/vendor/rbenv
key: gems-deb13-${{runner.os}}-${{hashFiles('Gemfile.lock')}}-${{hashFiles('.ruby-version')}}
- name: Download Coverage Outputs
uses: actions/download-artifact@v4
with:
path: coverage
- name: Merge Coverage results
run: make coverage_report
- name: Code Coverage Report
uses: irongut/CodeCoverageSummary@v1.3.0
with:
filename: coverage/coverage.xml
badge: true
fail_below_min: true
format: markdown
hide_branch_rate: false
hide_complexity: true
indicators: true
output: both
thresholds: "60 80"
- name: Adding coverage report to summary
run: cat code-coverage-results.md >> $GITHUB_STEP_SUMMARY
# - name: Add Coverage PR Comment
# uses: marocchino/sticky-pull-request-comment@v2
# if: github.event_name == 'pull_request'
# with:
# recreate: true
# path: code-coverage-results.md
# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}