Check published provider availability #127
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Check published provider availability | |
| on: | |
| workflow_dispatch: | |
| schedule: | |
| # Six low-cost diagnostic checks per day. GitHub schedules use UTC. | |
| - cron: "23 */4 * * *" | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: nuvio-provider-availability | |
| cancel-in-progress: true | |
| jobs: | |
| check: | |
| name: Probe current published providers | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 35 | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout without persisted credentials | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 1 | |
| persist-credentials: false | |
| - name: Set up Python | |
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: "3.12" | |
| - name: Set up Node.js | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: "24" | |
| package-manager-cache: false | |
| - name: Install pinned direct runtime dependencies without lifecycle scripts | |
| run: | | |
| if [ -f package-lock.json ]; then | |
| npm ci --ignore-scripts --no-audit --no-fund | |
| else | |
| npm install --ignore-scripts --no-audit --no-fund --package-lock=false | |
| fi | |
| - name: Stage current published providers | |
| run: python scripts/stage_published.py | |
| - name: Lock staged provider code against modification | |
| run: | | |
| sudo chown -R root:root staging | |
| sudo chmod -R a-w staging | |
| - name: Run low-cost availability diagnostics | |
| env: | |
| NUVIO_HEALTH_OUTPUT: health-output | |
| run: node scripts/health_check.mjs --availability | |
| - name: Upload diagnostic result | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: nuvio-availability-${{ github.run_id }} | |
| path: health-output/health-results.json | |
| retention-days: 2 | |
| if-no-files-found: error | |
| report: | |
| name: Update diagnostic reports only | |
| needs: check | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 12 | |
| permissions: | |
| contents: write | |
| steps: | |
| - name: Checkout current published repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: Set up Python | |
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: "3.12" | |
| - name: Download availability result | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: nuvio-availability-${{ github.run_id }} | |
| path: checked-artifact | |
| - name: Update reports without applying manifest toggles | |
| env: | |
| NUVIO_HEALTH_RESULTS: checked-artifact/health-results.json | |
| run: | | |
| cp manifest.json "$RUNNER_TEMP/manifest.before.json" | |
| cp vf/manifest.json "$RUNNER_TEMP/vf.before.json" | |
| python scripts/update_availability.py | |
| rm -f manifest.next.json | |
| cmp -s manifest.json "$RUNNER_TEMP/manifest.before.json" | |
| cmp -s vf/manifest.json "$RUNNER_TEMP/vf.before.json" | |
| - name: Publish diagnostic reports | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| git config user.name "github-actions[bot]" | |
| git config user.email "41898282+github-actions[bot]@users.noreply.github.com" | |
| git add availability-report.json availability-history.json | |
| if git diff --cached --quiet; then | |
| echo "Availability reports are unchanged." | |
| exit 0 | |
| fi | |
| git commit -m "chore: update provider availability diagnostics" | |
| git reset --hard HEAD | |
| git clean -fd | |
| for attempt in 1 2 3 4 5; do | |
| git fetch origin main | |
| if git rebase origin/main && git push origin HEAD:main; then | |
| exit 0 | |
| fi | |
| git rebase --abort || true | |
| sleep $((attempt * 2)) | |
| done | |
| exit 1 |