Skip to content

CI

CI #242

Workflow file for this run

name: CI
on:
push:
branches:
- main
tags:
- 'v*'
pull_request:
workflow_dispatch:
schedule:
- cron: "0 0 * * *" # Every day at midnight
env:
COMPOSER_HOME: ${{ github.workspace }}/.cache/composer
DEFAULT_PHP_VERSION: '8.1'
COMPOSER_TOKEN: ${{ secrets.GITHUB_TOKEN }}
jobs:
php-checks:
name: php checks
if: github.event_name != 'schedule'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2.37.2
with:
php-version: ${{ env.DEFAULT_PHP_VERSION }}
tools: composer:72a8f8e653710e18d83e5dd531eb5a71fc3223e6 # v2.9.5
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: .cache/composer
key: composer-${{ hashFiles('composer.json') }}
- run: composer install
- name: codeStyle
run: make test-php-style
- name: phpStan
run: make test-php-phpstan
- name: phpPhan
run: make test-php-phan
php-unit-tests:
name: php unit tests (${{ matrix.php-version }}-with-coverage)
if: github.event_name != 'schedule'
runs-on: ubuntu-latest
needs: php-checks
strategy:
fail-fast: false
matrix:
php-version : ['8.1', '8.2', '8.3']
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2.37.2
with:
php-version: ${{ matrix.php-version }}
tools: composer:72a8f8e653710e18d83e5dd531eb5a71fc3223e6 # v2.9.5
coverage: xdebug
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: .cache/composer
key: composer-${{ hashFiles('composer.json') }}
- run: composer install
- name: unitTests-${{ matrix.php-version }}
run: make test-php-unit
- name: coverage rename
run: mv tests/output/clover.xml tests/output/clover-php-unit-${{ matrix.php-version }}.xml
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: coverage-unitTests-${{ matrix.php-version }}
path: tests/output/clover-php-unit-${{ matrix.php-version }}.xml
retention-days: 1
build-ocis:
name: buildOcis
runs-on: ubuntu-latest
needs: php-checks
if: always() && (success() || github.event_name == 'schedule')
strategy:
fail-fast: false
matrix:
branch: ['master', 'stable']
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: get ocis commit ID
run: |
source .ci.env
if [ "${{ github.event_name }}" = "schedule" ]; then
echo "Nightly run, fetching latest commit based on branch"
if [ "${{ matrix.branch }}" = "master" ]; then
REF=master
else
REF=stable-8.0
fi
LATEST_OCIS_COMMIT=$(curl -s "https://api.github.com/repos/owncloud/ocis/commits?sha=$REF" | jq -r '.[0].sha')
if [ -z "$LATEST_OCIS_COMMIT" ]; then
echo "Failed to fetch latest commit for $REF"
exit 1
fi
echo "OCIS_COMMIT=$LATEST_OCIS_COMMIT" >> "$GITHUB_ENV"
echo "OCIS_REF=$REF" >> "$GITHUB_ENV"
elif [ "${{ matrix.branch }}" = "master" ]; then
echo "OCIS_COMMIT=$OCIS_COMMITID" >> "$GITHUB_ENV"
echo "OCIS_REF=$OCIS_BRANCH" >> "$GITHUB_ENV"
else
echo "OCIS_COMMIT=$OCIS_STABLE_COMMITID" >> "$GITHUB_ENV"
echo "OCIS_REF=$OCIS_STABLE_BRANCH" >> "$GITHUB_ENV"
fi
- name: cache ocis
id: ocis-cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: |
${{ github.workspace }}/ocis
${{ github.workspace }}/ociswrapper
key: ocis-bin-${{ matrix.branch }}-${{ env.OCIS_COMMIT }}
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
if: steps.ocis-cache.outputs.cache-hit != 'true'
with:
go-version: '1.25'
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
if: steps.ocis-cache.outputs.cache-hit != 'true'
with:
node-version: '20'
- name: install pnpm
if: steps.ocis-cache.outputs.cache-hit != 'true'
run: npm install -g pnpm@9.15.9
- name: clone ocis ${{ matrix.branch }}
if: steps.ocis-cache.outputs.cache-hit != 'true'
run: |
git clone -b "$OCIS_REF" --single-branch https://github.com/owncloud/ocis.git repo_ocis
cd repo_ocis
git checkout "$OCIS_COMMIT"
- name: generate ocis ${{ matrix.branch }}
if: steps.ocis-cache.outputs.cache-hit != 'true'
working-directory: repo_ocis
run: make ci-node-generate
- name: build ocis ${{ matrix.branch }}
if: steps.ocis-cache.outputs.cache-hit != 'true'
working-directory: repo_ocis/ocis
run: |
make build
cp bin/ocis ${{ github.workspace }}
- name: build ociswrapper
if: steps.ocis-cache.outputs.cache-hit != 'true'
run: |
make -C repo_ocis/tests/ociswrapper build
cp repo_ocis/tests/ociswrapper/bin/ociswrapper ${{ github.workspace }}/
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ocis-bin-${{ matrix.branch }}
path: |
${{ github.workspace }}/ocis
${{ github.workspace }}/ociswrapper
retention-days: 1
php-integration-tests:
name: php integration tests (${{ matrix.php-version}}-${{ matrix.branch }}${{ matrix.branch == 'master' && matrix.php-version == '8.1' && '-with-coverage' || '' }})
runs-on: ubuntu-latest
needs: build-ocis
if: always() && (success() || github.event_name == 'schedule')
strategy:
fail-fast: false
matrix:
php-version: ['8.1', '8.2', '8.3']
branch: ['master', 'stable']
services:
postgres:
image: postgres:alpine3.18
env:
POSTGRES_DB: keycloak
POSTGRES_USER: keycloak
POSTGRES_PASSWORD: keycloak
ports:
- 5432:5432
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ocis-bin-${{ matrix.branch }}
path: ${{ github.workspace }}
- uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2.37.2
with:
php-version: ${{ matrix.php-version }}
tools: composer:72a8f8e653710e18d83e5dd531eb5a71fc3223e6 # v2.9.5
coverage: xdebug
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: .cache/composer
key: composer-${{ hashFiles('composer.json') }}
- run: composer install
- name: keycloak
run: |
docker run -d --name keycloak \
--network host \
-e OCIS_DOMAIN=localhost:9200 \
-e KC_HOSTNAME=localhost:8080 \
-e KC_DB=postgres \
-e KC_DB_URL="jdbc:postgresql://localhost:5432/keycloak" \
-e KC_DB_USERNAME=keycloak \
-e KC_DB_PASSWORD=keycloak \
-e KC_FEATURES=impersonation \
-e KEYCLOAK_ADMIN=admin \
-e KEYCLOAK_ADMIN_PASSWORD=admin \
-v ${{ github.workspace }}/tests/integration/docker/keycloak/ocis-ci-realm.dist.json:/opt/keycloak/data/import/ocis-realm.json \
quay.io/keycloak/keycloak:22.0.4 \
start-dev --proxy edge --spi-connections-http-client-default-disable-trust-manager=true --import-realm --health-enabled=true
- name: wait for keycloak
run: timeout 300 bash -c 'until curl -sf http://localhost:8080; do sleep 5; done' || (echo "Keycloak failed to start" && exit 1)
- name: ocis
env:
OCIS_URL: "https://localhost:9200"
OCIS_LOG_LEVEL: "error"
IDM_ADMIN_PASSWORD: "admin" # override the random admin password from `ocis init`
PROXY_AUTOPROVISION_ACCOUNTS: "true"
PROXY_ROLE_ASSIGNMENT_DRIVER: "oidc"
OCIS_OIDC_ISSUER: "http://localhost:8080/realms/oCIS"
PROXY_OIDC_REWRITE_WELLKNOWN: "true"
WEB_OIDC_CLIENT_ID: "web"
PROXY_USER_OIDC_CLAIM: "preferred_username"
PROXY_USER_CS3_CLAIM: "username"
OCIS_ADMIN_USER_ID: ""
OCIS_EXCLUDE_RUN_SERVICES: "idp"
GRAPH_ASSIGN_DEFAULT_USER_ROLE: "false"
GRAPH_USERNAME_MATCH: "none"
run: |
chmod +x ${{ github.workspace }}/ocis ${{ github.workspace }}/ociswrapper
${{ github.workspace }}/ocis init --insecure true
${{ github.workspace }}/ociswrapper serve --bin ${{ github.workspace }}/ocis --url ${{ env.OCIS_URL }} &
- name: wait for ocis
run: timeout 300 bash -c 'until curl -skf https://localhost:9200; do sleep 5; done' || (echo "oCIS failed to start" && exit 1)
- name: php-integration-tests
env:
OCIS_URL: "https://localhost:9200"
OCISWRAPPER_URL: "http://localhost:5200"
OCIS_VERSION: ${{ matrix.branch }}
run: make test-php-integration-ci
- name: coverage rename
if: matrix.branch == 'master' && matrix.php-version == env.DEFAULT_PHP_VERSION
run: mv tests/output/clover.xml tests/output/clover-php-integration-${{ matrix.php-version }}.xml
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: matrix.branch == 'master' && matrix.php-version == env.DEFAULT_PHP_VERSION
with:
name: coverage-integrationTests-${{ matrix.php-version }}
path: tests/output/clover-php-integration-${{ matrix.php-version }}.xml
retention-days: 1
docs:
name: docs
if: github.event_name != 'schedule'
runs-on: ubuntu-latest
needs: [php-unit-tests, php-integration-tests]
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: docs generate
run: docker run --rm -v ${{ github.workspace }}:/data phpdoc/phpdoc@sha256:2b36e4f74937e40246d54ed12dfa4f988f21ed8d19e46f426ac3dc32eac2ff1d # v3.9.1
- name: publish api docs
uses: peaceiris/actions-gh-pages@84c30a85c19949d7eee79c4ff27748b70285e453 # v4.1.0
if: github.event_name != 'pull_request'
with:
github_token: ${{ secrets.GITHUB_TOKEN }}
publish_dir: docs
publish_branch: docs
force_orphan: true
- name: compile docs hugo
run: |
mkdir docs-hugo
cat docs-hugo-header.md README.md > docs-hugo/_index.md
- name: publish docs hugo
uses: peaceiris/actions-gh-pages@84c30a85c19949d7eee79c4ff27748b70285e453 # v4.1.0
if: github.event_name != 'pull_request'
with:
github_token: ${{ secrets.GITHUB_TOKEN }}
publish_dir: docs-hugo
publish_branch: docs-hugo
force_orphan: true
sonar-analysis:
name: sonar analysis
if: github.event_name != 'schedule'
runs-on: ubuntu-latest
needs: [php-unit-tests, php-integration-tests]
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
fetch-depth: '0'
- name: download tests coverage
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: coverage-*
path: results/
merge-multiple: 'true'
- name: list-coverage-results
run: ls -l results
- name: sonarcloud
uses: SonarSource/sonarqube-scan-action@299e4b793aaa83bf2aba7c9c14bedbb485688ec4 # v7.1.0
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}