Skip to content

Merge pull request #1082 from maykinmedia/feature/1068-open-product-p… #2991

Merge pull request #1082 from maykinmedia/feature/1068-open-product-p…

Merge pull request #1082 from maykinmedia/feature/1068-open-product-p… #2991

Workflow file for this run

name: Run CI
# Run this workflow every time a new commit pushed to your repository
on:
push:
branches:
- main
- stable/*
tags:
- '*'
pull_request:
workflow_dispatch:
env:
IMAGE_NAME: maykinmedia/open-archiefbeheer
DJANGO_SETTINGS_MODULE: openarchiefbeheer.conf.ci
DOCKER_BUILDKIT: '1'
KEYCLOAK_BASE_URL: http://localhost:28080
PLAYWRIGHT_SAVE_TRACE: yes
jobs:
frontend-build:
name: Build frontend
runs-on: ubuntu-latest
defaults:
run:
working-directory: frontend
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version-file: 'frontend/.nvmrc'
- name: Build Javascript
run: |
npm ci
npm run lint
CI=false npm run build
env:
OAB_API_URL: ""
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: build
path: ${{ github.workspace }}/frontend/dist/
retention-days: 1
if-no-files-found: error
backend-tests:
name: Run the Django test suite
runs-on: ubuntu-latest
defaults:
run:
working-directory: backend
services:
postgres:
image: postgis/postgis:14-3.4
env:
POSTGRES_HOST_AUTH_METHOD: trust
ports:
- 5432:5432
# Needed because the postgres container does not provide a healthcheck
options:
--health-cmd pg_isready --health-interval 10s --health-timeout 5s --health-retries 5
--name postgres
redis:
image: redis:6
ports:
- 6379:6379
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Set up backend environment
uses: maykinmedia/setup-django-backend@4a6c5facc65bb1dd510cf06be20871db11a156b3 # v1.4.2
with:
apt-packages: 'gettext postgresql-client libgdal-dev libyaml-dev gdal-bin'
python-version: '3.12'
optimize-postgres: 'yes'
pg-service: 'postgres'
setup-node: 'no'
working-directory: backend
- name: Run tests
working-directory: backend
run: |
python src/manage.py compilemessages
python src/manage.py collectstatic --noinput --link
coverage run --data-file=coverage_pytest -m pytest src/
coverage run --data-file=coverage_django src/manage.py test openarchiefbeheer --exclude-tag=e2e --exclude-tag=performance
coverage combine --data-file=coverage_combined coverage_django coverage_pytest
coverage xml --data-file=coverage_combined -o coverage.xml
env:
DJANGO_SETTINGS_MODULE: openarchiefbeheer.conf.ci
SECRET_KEY: dummy
DB_USER: postgres
DB_PASSWORD: ''
- name: Publish coverage report
uses: codecov/codecov-action@e79a6962e0d4c0c17b229090214935d2e33f8354 # v6.0.1
with:
working-directory: backend
files: ./coverage.xml
flags: backend
token: ${{ secrets.CODECOV_TOKEN }}
frontend-tests:
name: Run storybook tests
needs: frontend-build
runs-on: ubuntu-latest
defaults:
run:
working-directory: frontend
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
fetch-depth: 0
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version-file: 'frontend/.nvmrc'
- name: Install dependencies
run: npm ci
- name: Install Playwright
run: npx playwright install --with-deps
- name: Build Storybook
run: npm run build-storybook
- name: Publish to Chromatic
uses: chromaui/action@14cfaef73576e69f95f47f60058063f46ca38719 # v18.1.0
with:
projectToken: ${{ secrets.CHROMATIC_PROJECT_TOKEN }}
autoAcceptChanges: "main"
onlyChanged: true
workingDir: frontend
- name: Run vitest tests
run: npm run test:coverage
- name: Serve Storybook and run tests
run: |
npx concurrently -k -s first -n "SB,TEST" -c "magenta,blue" \
"npx http-server storybook-static --port 6006" \
"npx wait-on tcp:127.0.0.1:6006 && npm run test-storybook"
- name: Publish coverage report (storybook)
uses: codecov/codecov-action@e79a6962e0d4c0c17b229090214935d2e33f8354 # v6.0.1
with:
working-directory: frontend/coverage
files: ./storybook/coverage-storybook.json
flags: storybook
token: ${{ secrets.CODECOV_TOKEN }}
- name: Publish coverage report (jest)
uses: codecov/codecov-action@e79a6962e0d4c0c17b229090214935d2e33f8354 # v6.0.1
with:
working-directory: frontend/coverage
files: ./coverage-final.json
flags: jest
token: ${{ secrets.CODECOV_TOKEN }}
e2e-feature-tests:
runs-on: maykin-runner
needs: frontend-build
strategy:
fail-fast: false
matrix:
browser:
- chromium
- firefox
- webkit
name: End-to-end tests (features), ${{ matrix.browser }}
defaults:
run:
working-directory: backend
services:
postgres:
image: postgis/postgis:14-3.4
env:
POSTGRES_HOST_AUTH_METHOD: trust
ports:
- 5432:5432
# Needed because the postgres container does not provide a healthcheck
options:
--health-cmd pg_isready --health-interval 10s --health-timeout 5s --health-retries 5
--name postgres
redis:
image: redis:6
ports:
- 6379:6379
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Set up backend environment
uses: maykinmedia/setup-django-backend@4a6c5facc65bb1dd510cf06be20871db11a156b3 # v1.4.2
with:
apt-packages: 'gettext postgresql-client libgdal-dev libyaml-dev gdal-bin'
python-version: '3.12'
optimize-postgres: 'yes'
pg-service: 'postgres'
setup-node: 'no'
working-directory: backend
- name: Start CI docker services
run: |
docker compose up -d
working-directory: backend/docker-services/keycloak
- name: Wait for Keycloak to be up
run: |
endpoint="${KEYCLOAK_BASE_URL}/realms/openarchiefbeheer-dev/"
realm=""
until [ $realm ]; do
echo "Checking if Keycloak at ${KEYCLOAK_BASE_URL} is up..."
realm=$(curl "$endpoint" -s | jq -r ".realm")
sleep 2
done
echo "Running Keycloak with realm $realm"
# See https://playwright.dev/python/docs/ci#caching-browsers
- name: Cache Playwright browser
id: cache-browser
uses: actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4.2.0
with:
path: /home/runner/.cache/ms-playwright
key:
${{ runner.os }}-${{ matrix.browser }}-playwright-${{ hashFiles('requirements/ci.txt') }}
- name: Install playwright deps
run: playwright install --with-deps ${{ matrix.browser }}
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: build
path: ${{ github.workspace }}/frontend/dist
- name: Run tests
working-directory: backend
run: |
ln -s ${{ github.workspace }}/frontend/dist/static/assets ${{ github.workspace }}/backend/src/openarchiefbeheer/static/assets
ln -s ${{ github.workspace }}/frontend/dist/index.html ${{ github.workspace }}/backend/src/openarchiefbeheer/templates/index.html
python src/manage.py compilemessages
python src/manage.py collectstatic --noinput --link
python src/manage.py test openarchiefbeheer --tag=e2e --exclude-tag=issue --parallel 3
env:
DJANGO_SETTINGS_MODULE: openarchiefbeheer.conf.ci
SECRET_KEY: dummy
DB_USER: postgres
DB_PASSWORD: ''
E2E_SERVE_FRONTEND: yes
PLAYWRIGHT_HEADLESS: yes
PLAYWRIGHT_BROWSER: ${{ matrix.browser }}
PLAYWRIGHT_TRACE_PATH: ${{ matrix.browser }}-playwright-trace.zip
OAB_CACHE_DISABLED: true
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ failure() }}
with:
name: ${{ matrix.browser }}-features-playwright-trace.zip
path: ${{ github.workspace }}/backend/${{ matrix.browser }}-playwright-trace.zip
retention-days: 1
if-no-files-found: error
e2e-issue-tests:
runs-on: maykin-runner
needs: frontend-build
strategy:
fail-fast: false
matrix:
browser:
- chromium
name: End-to-end tests (issues), ${{ matrix.browser }}
defaults:
run:
working-directory: backend
services:
postgres:
image: postgis/postgis:14-3.4
env:
POSTGRES_HOST_AUTH_METHOD: trust
ports:
- 5432:5432
# Needed because the postgres container does not provide a healthcheck
options:
--health-cmd pg_isready --health-interval 10s --health-timeout 5s --health-retries 5
--name postgres
redis:
image: redis:6
ports:
- 6379:6379
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Set up backend environment
uses: maykinmedia/setup-django-backend@4a6c5facc65bb1dd510cf06be20871db11a156b3 # v1.4.2
with:
apt-packages: 'gettext postgresql-client libgdal-dev libyaml-dev gdal-bin'
python-version: '3.12'
optimize-postgres: 'yes'
pg-service: 'postgres'
setup-node: 'no'
working-directory: backend
- name: Start CI docker services
run: |
docker compose up -d
working-directory: backend/docker-services/keycloak
- name: Wait for Keycloak to be up
run: |
endpoint="${KEYCLOAK_BASE_URL}/realms/openarchiefbeheer-dev/"
realm=""
until [ $realm ]; do
echo "Checking if Keycloak at ${KEYCLOAK_BASE_URL} is up..."
realm=$(curl "$endpoint" -s | jq -r ".realm")
sleep 2
done
echo "Running Keycloak with realm $realm"
# See https://playwright.dev/python/docs/ci#caching-browsers
- name: Cache Playwright browser
id: cache-browser
uses: actions/cache@1bd1e32a3bdc45362d1e726936510720a7c30a57 # v4.2.0
with:
path: /home/runner/.cache/ms-playwright
key:
${{ runner.os }}-${{ matrix.browser }}-playwright-${{ hashFiles('requirements/ci.txt') }}
- name: Install playwright deps
run: playwright install --with-deps ${{ matrix.browser }}
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: build
path: ${{ github.workspace }}/frontend/dist
- name: Run tests
working-directory: backend
run: |
ln -s ${{ github.workspace }}/frontend/dist/static/assets ${{ github.workspace }}/backend/src/openarchiefbeheer/static/assets
ln -s ${{ github.workspace }}/frontend/dist/index.html ${{ github.workspace }}/backend/src/openarchiefbeheer/templates/index.html
python src/manage.py compilemessages
python src/manage.py collectstatic --noinput --link
python src/manage.py test openarchiefbeheer --tag=issue --parallel 3
env:
DJANGO_SETTINGS_MODULE: openarchiefbeheer.conf.ci
SECRET_KEY: dummy
DB_USER: postgres
DB_PASSWORD: ''
E2E_SERVE_FRONTEND: yes
PLAYWRIGHT_HEADLESS: yes
PLAYWRIGHT_BROWSER: ${{ matrix.browser }}
PLAYWRIGHT_TRACE_PATH: ${{ matrix.browser }}-playwright-trace.zip
OAB_CACHE_DISABLED: true
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ failure() }}
with:
name: ${{ matrix.browser }}-issue-playwright-trace.zip
path: ${{ github.workspace }}/backend/${{ matrix.browser }}-playwright-trace.zip
retention-days: 1
if-no-files-found: error
docs:
name: Build and check documentation
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
path: open-archiefbeheer
- name: Set up backend environment
uses: maykinmedia/setup-django-backend@4a6c5facc65bb1dd510cf06be20871db11a156b3 # v1.4.2
with:
apt-packages: 'gettext postgresql-client libgdal-dev gdal-bin'
python-version: '3.12'
setup-node: 'no'
working-directory: open-archiefbeheer/backend
- name: Build and test docs
run: |
pytest check_sphinx.py -v --tb=auto
working-directory: open-archiefbeheer/backend/docs
docker_build:
name: Build docker image
strategy:
matrix:
# KEEP IN SYNC WITH docker_push JOB
target:
- target_env: production
image_tag_suffix: ''
settings_module: docker
- target_env: dev
image_tag_suffix: '-dev'
settings_module: dev
uses: ./.github/workflows/build-image.yaml
with:
image_name: maykinmedia/open-archiefbeheer
image_tag_suffix: ${{ matrix.target.image_tag_suffix }}
target_env: ${{ matrix.target.target_env }}
settings_module: ${{ matrix.target.settings_module }}
docker_push:
needs:
- backend-tests
- frontend-build
- e2e-feature-tests
- e2e-issue-tests
- docker_build
name: Push Docker image
runs-on: ubuntu-latest
if: github.event_name == 'push' # Exclude PRs
strategy:
matrix:
# KEEP IN SYNC WITH docker_build JOB
target:
- target_env: production
image_tag_suffix: ''
- target_env: dev
image_tag_suffix: '-dev'
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Extract build args
id: build-args
run: |
# Strip git ref prefix from version
VERSION=$(echo "${{ github.ref }}" | sed -e 's,.*/\(.*\),\1,')
# Use Docker `latest` tag convention
[ "$VERSION" == "main" ] && VERSION=latest
# PRs result in version 'merge' -> transform that into 'latest'
[ "$VERSION" == "merge" ] && VERSION=latest
echo "version=${VERSION}" >> $GITHUB_OUTPUT
- name: Download built image
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: docker-image-${{ steps.build-args.outputs.version }}${{ matrix.target.image_tag_suffix }}
- name: Load image
run: |
docker image load -i image.tar
- name: Log into registry
run:
echo "${{ secrets.DOCKER_TOKEN }}" | docker login -u ${{ secrets.DOCKER_USERNAME }}
--password-stdin
- name: Push the Docker image (production)
run: docker push $IMAGE_NAME:${{ steps.build-args.outputs.version }}${{ matrix.target.image_tag_suffix }}
dockerhub_description:
needs: docker_push
name: Update dockerhub description
runs-on: ubuntu-latest
if: github.event_name == 'push' # Exclude PRs
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Docker Hub Description
uses: peter-evans/dockerhub-description@1b9a80c056b620d92cedb9d9b5a223409c68ddfa # v5.0.0
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_TOKEN }}
repository: maykinmedia/open-archiefbeheer
readme-filepath: ${{ github.workspace }}/README.md