#1 docs: GCP provisioning runbook (bucket, writer SA, grants, key) #7
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| # Cancel superseded runs on the same PR; never cancel runs on main (every commit | |
| # that lands keeps its signal). | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| lint: | |
| name: lint | |
| runs-on: ubuntu-latest | |
| # A run takes ~2 min; bound a hang well short of GitHub's 360-minute default. | |
| timeout-minutes: 15 | |
| # WIF: an OIDC token for google-github-actions/auth to impersonate the | |
| # read-only co-pypi-reader SA and pull the cannobserv wheelhouse, as in the | |
| # other cohort repos. Job-scoped, so no other step gains cloud access. | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| # Submodules: tests/test_skills.py walks skills-vendor/ (#3). | |
| - uses: actions/checkout@v5 | |
| with: | |
| submodules: true | |
| - name: Install uv | |
| uses: astral-sh/setup-uv@v7 | |
| with: | |
| enable-cache: true | |
| - name: Install Python | |
| run: uv python install 3.12 | |
| - name: Authenticate to Google Cloud (WIF, read-only) | |
| uses: google-github-actions/auth@v3 | |
| with: | |
| workload_identity_provider: ${{ vars.GCP_WIF_PROVIDER }} | |
| service_account: co-pypi-reader@co-gcs.iam.gserviceaccount.com | |
| # co-core resolves from ./.wheelhouse (find-links), so it must exist before | |
| # any project-aware uv command, `uv lock --locked` included. --no-config: | |
| # `--no-project` alone still reads [tool.uv] find-links, and a fresh checkout | |
| # has no ./.wheelhouse yet (the script creates it). | |
| - name: Sync cannobserv wheelhouse | |
| run: uv run --no-project --no-config --with 'google-cloud-storage>=2,<4' python scripts/sync_wheelhouse.py | |
| - name: uv sync | |
| run: uv sync --locked | |
| - name: ruff check | |
| run: uv run ruff check . | |
| - name: ruff format --check | |
| run: uv run ruff format --check . | |
| - name: uv lock --locked | |
| run: uv lock --locked | |
| test: | |
| name: test | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| permissions: | |
| contents: read | |
| id-token: write | |
| # The broker's exact Redis, 7.0.15 (broker deploy/redis-acl.conf), as on | |
| # co-processor's scratch server. Not a newer 7.x: from 7.2 redis-py's CLIENT | |
| # SETINFO is an ACL denial the broker's grant cannot cover until it upgrades | |
| # (granting it is a required step of that upgrade, per the broker). The | |
| # integration suite runs here in full: db 15, a throwaway ACL user, and briefly | |
| # maxmemory, all of which a service container absorbs. | |
| services: | |
| redis: | |
| image: redis:7.0.15 | |
| ports: | |
| - 6379:6379 | |
| options: >- | |
| --health-cmd "redis-cli ping" | |
| --health-interval 5s | |
| --health-timeout 3s | |
| --health-retries 10 | |
| steps: | |
| - uses: actions/checkout@v5 | |
| with: | |
| submodules: true | |
| - name: Install uv | |
| uses: astral-sh/setup-uv@v7 | |
| with: | |
| enable-cache: true | |
| - name: Install Python | |
| run: uv python install 3.12 | |
| - name: Authenticate to Google Cloud (WIF, read-only) | |
| uses: google-github-actions/auth@v3 | |
| with: | |
| workload_identity_provider: ${{ vars.GCP_WIF_PROVIDER }} | |
| service_account: co-pypi-reader@co-gcs.iam.gserviceaccount.com | |
| - name: Sync cannobserv wheelhouse | |
| run: uv run --no-project --no-config --with 'google-cloud-storage>=2,<4' python scripts/sync_wheelhouse.py | |
| - name: uv sync | |
| run: uv sync --locked | |
| # No marker filter: the integration tests are the bus contract. Host-bound | |
| # tests (live tailscaled, installed drop-ins) skip off co-processor. | |
| - name: pytest | |
| run: uv run pytest |