Merge pull request #474 from corbitsdev/cl-7195-stop-the-turn-queue-f… #1807
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| concurrency: | |
| # PRs group by number so a newer push supersedes and cancels the stale | |
| # run. Pushes to main group by commit SHA, giving every commit its own | |
| # group: a constant branch-wide key would let a newer push evict the | |
| # queued run of a commit still waiting behind an in-flight one, and | |
| # that commit would never be validated. cancel-in-progress therefore | |
| # only governs PR supersession. | |
| group: ci-${{ github.event.pull_request.number || github.sha }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| # The four jobs below were one serial `checks` job. Splitting them lets | |
| # GitHub run them concurrently, so a PR's wall-clock is the slowest job | |
| # rather than the sum of all of them, and a lint or structural failure | |
| # reports in about a minute instead of waiting behind the build. | |
| lint: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: ./.github/actions/setup-workbench | |
| - uses: actions/cache@v4 | |
| with: | |
| path: | | |
| .eslintcache | |
| node_modules/.cache/prettier | |
| key: lint-${{ runner.os }}-${{ hashFiles('bun.lock', 'eslint.config.ts', '.prettierrc.json', '.bun-version') }} | |
| - run: bun run lint | |
| typecheck: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - uses: ./.github/actions/setup-workbench | |
| - run: bun run typecheck | |
| env: | |
| WORKBENCH_CHECK_SINCE: ${{ github.event.pull_request.base.sha }} | |
| build-test: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - uses: ./.github/actions/setup-workbench | |
| - run: bun run build | |
| - run: bun run test | |
| env: | |
| WORKBENCH_CHECK_SINCE: ${{ github.event.pull_request.base.sha }} | |
| structural: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - uses: ./.github/actions/setup-workbench | |
| - name: Structural check self-tests | |
| run: bun test scripts/checks/test | |
| - run: bun run check:deletion | |
| - run: bun run check:killdates | |
| - run: bun run check:packages | |
| - run: bun run check:licenses | |
| - run: bun run check:no-product-tenancy | |
| - run: bun run check:browser-safe-subpaths | |
| - run: bun run check:web-utilities | |
| - run: bun run check:tailwind-source | |
| - run: bun run check:ui-vocabulary | |
| - run: bun run check:react-ui-drift | |
| - run: bun run check:react-ui-pin | |
| - run: bun run check:tool-package-pins | |
| - run: bun run check:tool-package-freshness | |
| env: | |
| CHECK_BASE_REF: ${{ github.event.pull_request.base.sha }} | |
| e2e: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| services: | |
| postgres: | |
| # pgvector-enabled Postgres 17, matching the local development | |
| # database (brew postgresql@17 + pgvector). | |
| image: pgvector/pgvector:pg17 | |
| env: | |
| POSTGRES_USER: postgres | |
| POSTGRES_PASSWORD: postgres | |
| ports: | |
| - 5432:5432 | |
| options: >- | |
| --health-cmd "pg_isready -U postgres -d postgres" | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 5 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: ./.github/actions/setup-workbench | |
| # The committed template ships a placeholder secret and a | |
| # credential-less local DATABASE_URL; point the URL at the service | |
| # container's superuser and mint a real session secret in place. | |
| - name: Write env file | |
| run: | | |
| cp .env.example .env | |
| secret=$(openssl rand -hex 32) | |
| sed -i "s|^SESSION_SECRET=.*|SESSION_SECRET=${secret}|" .env | |
| sed -i "s|^DATABASE_URL=.*|DATABASE_URL=postgres://postgres:postgres@localhost:5432/workbench|" .env | |
| # The e2e suite skips itself when DATABASE_URL is absent, so a | |
| # wiring mistake here could otherwise drop the whole suite while | |
| # CI stays green. Fail loudly instead: the env file must exist | |
| # with a usable DATABASE_URL and SESSION_SECRET, Postgres must be | |
| # reachable, and git (the workflow-asset publication path) must be | |
| # present. E2E_REQUIRED=1 below turns any remaining skip into a | |
| # hard failure. | |
| - name: Assert the e2e test env is wired | |
| run: | | |
| test -f .env | |
| grep -q '^DATABASE_URL=postgres://postgres:postgres@localhost:5432/workbench$' .env | |
| grep -Eq '^SESSION_SECRET=.{32,}$' .env | |
| pg_isready -h localhost -p 5432 | |
| git --version | |
| - name: Run the walking skeleton | |
| run: bun run test:e2e | |
| env: | |
| E2E_REQUIRED: "1" | |
| DATABASE_URL: postgres://postgres:postgres@localhost:5432/workbench | |
| isolation: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| services: | |
| postgres: | |
| # pgvector-enabled Postgres 17, matching the local development | |
| # database (brew postgresql@17 + pgvector). | |
| image: pgvector/pgvector:pg17 | |
| env: | |
| POSTGRES_USER: postgres | |
| POSTGRES_PASSWORD: postgres | |
| ports: | |
| - 5432:5432 | |
| options: >- | |
| --health-cmd "pg_isready -U postgres -d postgres" | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 5 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: ./.github/actions/setup-workbench | |
| - name: Write env file | |
| run: | | |
| cp .env.example .env | |
| secret=$(openssl rand -hex 32) | |
| sed -i "s|^SESSION_SECRET=.*|SESSION_SECRET=${secret}|" .env | |
| sed -i "s|^DATABASE_URL=.*|DATABASE_URL=postgres://postgres:postgres@localhost:5432/workbench|" .env | |
| - name: Assert the e2e test env is wired | |
| run: | | |
| test -f .env | |
| grep -q '^DATABASE_URL=postgres://postgres:postgres@localhost:5432/workbench$' .env | |
| grep -Eq '^SESSION_SECRET=.{32,}$' .env | |
| pg_isready -h localhost -p 5432 | |
| git --version | |
| - name: Run the two-org isolation suite | |
| run: bun test test/isolation | |
| env: | |
| E2E_REQUIRED: "1" | |
| DATABASE_URL: postgres://postgres:postgres@localhost:5432/workbench | |
| db-suites: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| services: | |
| postgres: | |
| # pgvector-enabled Postgres 17, matching the local development | |
| # database (brew postgresql@17 + pgvector). | |
| image: pgvector/pgvector:pg17 | |
| env: | |
| POSTGRES_USER: postgres | |
| POSTGRES_PASSWORD: postgres | |
| ports: | |
| - 5432:5432 | |
| options: >- | |
| --health-cmd "pg_isready -U postgres -d postgres" | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 5 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: ./.github/actions/setup-workbench | |
| - name: Write env file | |
| run: | | |
| cp .env.example .env | |
| secret=$(openssl rand -hex 32) | |
| sed -i "s|^SESSION_SECRET=.*|SESSION_SECRET=${secret}|" .env | |
| sed -i "s|^DATABASE_URL=.*|DATABASE_URL=postgres://postgres:postgres@localhost:5432/workbench|" .env | |
| - name: Assert the e2e test env is wired | |
| run: | | |
| test -f .env | |
| grep -q '^DATABASE_URL=postgres://postgres:postgres@localhost:5432/workbench$' .env | |
| grep -Eq '^SESSION_SECRET=.{32,}$' .env | |
| pg_isready -h localhost -p 5432 | |
| git --version | |
| # apps/hub/test and most of the package suites below connect | |
| # straight to DATABASE_URL (or its `_e2e`-suffixed sibling from | |
| # `e2eDatabaseUrl()`) rather than booting through the harness, so | |
| # — unlike e2e and isolation, which provision their own schema — | |
| # this job must create and migrate both databases itself before | |
| # those suites run. | |
| - name: Set up the databases | |
| run: | | |
| DATABASE_URL=postgres://postgres:postgres@localhost:5432/workbench bun scripts/db-setup.ts | |
| DATABASE_URL=postgres://postgres:postgres@localhost:5432/workbench_e2e bun scripts/db-setup.ts | |
| # apps/hub's own DB-backed suites (e.g. the sign-up rate-limit | |
| # proof) never run under the plain `checks` job, which has no | |
| # Postgres. E2E_REQUIRED=1 turns a would-be skip here into a hard | |
| # failure, so a misconfigured invocation can't pass vacuously. | |
| - name: Run the hub's database-backed suites | |
| run: | | |
| set -a | |
| . ./.env | |
| set +a | |
| bun test apps/hub/test | |
| env: | |
| E2E_REQUIRED: "1" | |
| DATABASE_URL: postgres://postgres:postgres@localhost:5432/workbench | |
| # Every DB-gated suite under packages/* and apps/hub/src gates on | |
| # DATABASE_URL and describe.skip's without one, so build-test (no | |
| # Postgres) never runs them. Find them by the same signal they | |
| # gate on rather than hardcoding a file list, so a newly added | |
| # suite gets picked up automatically. E2E_REQUIRED=1 turns a | |
| # would-be skip into a hard failure. | |
| - name: Run the database-backed package suites | |
| run: | | |
| set -a | |
| . ./.env | |
| set +a | |
| bun --env-file="${GITHUB_WORKSPACE}/.env" test $(grep -rl DATABASE_URL --include='*.test.ts' packages apps | grep -v apps/hub/test) | |
| env: | |
| E2E_REQUIRED: "1" | |
| DATABASE_URL: postgres://postgres:postgres@localhost:5432/workbench |