CI #281
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: | |
| - main | |
| tags: | |
| - 'v*' | |
| pull_request: | |
| workflow_dispatch: | |
| schedule: | |
| - cron: "0 0 * * *" # Every day at midnight | |
| env: | |
| COMPOSER_HOME: ${{ github.workspace }}/.cache/composer | |
| DEFAULT_PHP_VERSION: '8.1' | |
| COMPOSER_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| jobs: | |
| php-checks: | |
| name: php checks | |
| if: github.event_name != 'schedule' | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2.37.2 | |
| with: | |
| php-version: ${{ env.DEFAULT_PHP_VERSION }} | |
| tools: composer:72a8f8e653710e18d83e5dd531eb5a71fc3223e6 # v2.9.5 | |
| - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 | |
| with: | |
| path: .cache/composer | |
| key: composer-${{ hashFiles('composer.json') }} | |
| - run: composer install | |
| - name: codeStyle | |
| run: make test-php-style | |
| - name: phpStan | |
| run: make test-php-phpstan | |
| - name: phpPhan | |
| run: make test-php-phan | |
| php-unit-tests: | |
| name: php unit tests (${{ matrix.php-version }}-with-coverage) | |
| if: github.event_name != 'schedule' | |
| runs-on: ubuntu-latest | |
| needs: php-checks | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| php-version : ['8.1', '8.2', '8.3'] | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2.37.2 | |
| with: | |
| php-version: ${{ matrix.php-version }} | |
| tools: composer:72a8f8e653710e18d83e5dd531eb5a71fc3223e6 # v2.9.5 | |
| coverage: xdebug | |
| - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 | |
| with: | |
| path: .cache/composer | |
| key: composer-${{ hashFiles('composer.json') }} | |
| - run: composer install | |
| - name: unitTests-${{ matrix.php-version }} | |
| run: make test-php-unit | |
| - name: coverage rename | |
| run: mv tests/output/clover.xml tests/output/clover-php-unit-${{ matrix.php-version }}.xml | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: coverage-unitTests-${{ matrix.php-version }} | |
| path: tests/output/clover-php-unit-${{ matrix.php-version }}.xml | |
| retention-days: 1 | |
| build-ocis: | |
| name: buildOcis | |
| runs-on: ubuntu-latest | |
| needs: php-checks | |
| if: always() && (success() || github.event_name == 'schedule') | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| branch: ['master', 'stable'] | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - name: get ocis commit ID | |
| run: | | |
| source .ci.env | |
| if [ "${{ github.event_name }}" = "schedule" ]; then | |
| echo "Nightly run, fetching latest commit based on branch" | |
| if [ "${{ matrix.branch }}" = "master" ]; then | |
| REF=master | |
| else | |
| REF=stable-8.0 | |
| fi | |
| LATEST_OCIS_COMMIT=$(curl -s "https://api.github.com/repos/owncloud/ocis/commits?sha=$REF" | jq -r '.[0].sha') | |
| if [ -z "$LATEST_OCIS_COMMIT" ]; then | |
| echo "Failed to fetch latest commit for $REF" | |
| exit 1 | |
| fi | |
| echo "OCIS_COMMIT=$LATEST_OCIS_COMMIT" >> "$GITHUB_ENV" | |
| echo "OCIS_REF=$REF" >> "$GITHUB_ENV" | |
| elif [ "${{ matrix.branch }}" = "master" ]; then | |
| echo "OCIS_COMMIT=$OCIS_COMMITID" >> "$GITHUB_ENV" | |
| echo "OCIS_REF=$OCIS_BRANCH" >> "$GITHUB_ENV" | |
| else | |
| echo "OCIS_COMMIT=$OCIS_STABLE_COMMITID" >> "$GITHUB_ENV" | |
| echo "OCIS_REF=$OCIS_STABLE_BRANCH" >> "$GITHUB_ENV" | |
| fi | |
| - name: cache ocis | |
| id: ocis-cache | |
| uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 | |
| with: | |
| path: | | |
| ${{ github.workspace }}/ocis | |
| ${{ github.workspace }}/ociswrapper | |
| key: ocis-bin-${{ matrix.branch }}-${{ env.OCIS_COMMIT }} | |
| - uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0 | |
| if: steps.ocis-cache.outputs.cache-hit != 'true' | |
| with: | |
| go-version: '1.25' | |
| - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 | |
| if: steps.ocis-cache.outputs.cache-hit != 'true' | |
| with: | |
| node-version: '20' | |
| - name: install pnpm | |
| if: steps.ocis-cache.outputs.cache-hit != 'true' | |
| run: npm install -g pnpm@9.15.9 | |
| - name: clone ocis ${{ matrix.branch }} | |
| if: steps.ocis-cache.outputs.cache-hit != 'true' | |
| run: | | |
| git clone -b "$OCIS_REF" --single-branch https://github.com/owncloud/ocis.git repo_ocis | |
| cd repo_ocis | |
| git checkout "$OCIS_COMMIT" | |
| - name: generate ocis ${{ matrix.branch }} | |
| if: steps.ocis-cache.outputs.cache-hit != 'true' | |
| working-directory: repo_ocis | |
| run: make ci-node-generate | |
| - name: build ocis ${{ matrix.branch }} | |
| if: steps.ocis-cache.outputs.cache-hit != 'true' | |
| working-directory: repo_ocis/ocis | |
| run: | | |
| make build | |
| cp bin/ocis ${{ github.workspace }} | |
| - name: build ociswrapper | |
| if: steps.ocis-cache.outputs.cache-hit != 'true' | |
| run: | | |
| make -C repo_ocis/tests/ociswrapper build | |
| cp repo_ocis/tests/ociswrapper/bin/ociswrapper ${{ github.workspace }}/ | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: ocis-bin-${{ matrix.branch }} | |
| path: | | |
| ${{ github.workspace }}/ocis | |
| ${{ github.workspace }}/ociswrapper | |
| retention-days: 1 | |
| php-integration-tests: | |
| name: php integration tests (${{ matrix.php-version}}-${{ matrix.branch }}${{ matrix.branch == 'master' && matrix.php-version == '8.1' && '-with-coverage' || '' }}) | |
| runs-on: ubuntu-latest | |
| needs: build-ocis | |
| if: always() && (success() || github.event_name == 'schedule') | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| php-version: ['8.1', '8.2', '8.3'] | |
| branch: ['master', 'stable'] | |
| services: | |
| postgres: | |
| image: postgres:alpine3.18 | |
| env: | |
| POSTGRES_DB: keycloak | |
| POSTGRES_USER: keycloak | |
| POSTGRES_PASSWORD: keycloak | |
| ports: | |
| - 5432:5432 | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: ocis-bin-${{ matrix.branch }} | |
| path: ${{ github.workspace }} | |
| - uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2.37.2 | |
| with: | |
| php-version: ${{ matrix.php-version }} | |
| tools: composer:72a8f8e653710e18d83e5dd531eb5a71fc3223e6 # v2.9.5 | |
| coverage: xdebug | |
| - uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 | |
| with: | |
| path: .cache/composer | |
| key: composer-${{ hashFiles('composer.json') }} | |
| - run: composer install | |
| - name: keycloak | |
| run: | | |
| docker run -d --name keycloak \ | |
| --network host \ | |
| -e OCIS_DOMAIN=localhost:9200 \ | |
| -e KC_HOSTNAME=localhost:8080 \ | |
| -e KC_DB=postgres \ | |
| -e KC_DB_URL="jdbc:postgresql://localhost:5432/keycloak" \ | |
| -e KC_DB_USERNAME=keycloak \ | |
| -e KC_DB_PASSWORD=keycloak \ | |
| -e KC_FEATURES=impersonation \ | |
| -e KEYCLOAK_ADMIN=admin \ | |
| -e KEYCLOAK_ADMIN_PASSWORD=admin \ | |
| -v ${{ github.workspace }}/tests/integration/docker/keycloak/ocis-ci-realm.dist.json:/opt/keycloak/data/import/ocis-realm.json \ | |
| quay.io/keycloak/keycloak:22.0.4 \ | |
| start-dev --proxy edge --spi-connections-http-client-default-disable-trust-manager=true --import-realm --health-enabled=true | |
| - name: wait for keycloak | |
| run: timeout 300 bash -c 'until curl -sf http://localhost:8080; do sleep 5; done' || (echo "Keycloak failed to start" && exit 1) | |
| - name: ocis | |
| env: | |
| OCIS_URL: "https://localhost:9200" | |
| OCIS_LOG_LEVEL: "error" | |
| IDM_ADMIN_PASSWORD: "admin" # override the random admin password from `ocis init` | |
| PROXY_AUTOPROVISION_ACCOUNTS: "true" | |
| PROXY_ROLE_ASSIGNMENT_DRIVER: "oidc" | |
| OCIS_OIDC_ISSUER: "http://localhost:8080/realms/oCIS" | |
| PROXY_OIDC_REWRITE_WELLKNOWN: "true" | |
| WEB_OIDC_CLIENT_ID: "web" | |
| PROXY_USER_OIDC_CLAIM: "preferred_username" | |
| PROXY_USER_CS3_CLAIM: "username" | |
| OCIS_ADMIN_USER_ID: "" | |
| OCIS_EXCLUDE_RUN_SERVICES: "idp" | |
| GRAPH_ASSIGN_DEFAULT_USER_ROLE: "false" | |
| GRAPH_USERNAME_MATCH: "none" | |
| run: | | |
| chmod +x ${{ github.workspace }}/ocis ${{ github.workspace }}/ociswrapper | |
| ${{ github.workspace }}/ocis init --insecure true | |
| ${{ github.workspace }}/ociswrapper serve --bin ${{ github.workspace }}/ocis --url ${{ env.OCIS_URL }} & | |
| - name: wait for ocis | |
| run: timeout 300 bash -c 'until curl -skf https://localhost:9200; do sleep 5; done' || (echo "oCIS failed to start" && exit 1) | |
| - name: php-integration-tests | |
| env: | |
| OCIS_URL: "https://localhost:9200" | |
| OCISWRAPPER_URL: "http://localhost:5200" | |
| OCIS_VERSION: ${{ matrix.branch }} | |
| run: make test-php-integration-ci | |
| - name: coverage rename | |
| if: matrix.branch == 'master' && matrix.php-version == env.DEFAULT_PHP_VERSION | |
| run: mv tests/output/clover.xml tests/output/clover-php-integration-${{ matrix.php-version }}.xml | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| if: matrix.branch == 'master' && matrix.php-version == env.DEFAULT_PHP_VERSION | |
| with: | |
| name: coverage-integrationTests-${{ matrix.php-version }} | |
| path: tests/output/clover-php-integration-${{ matrix.php-version }}.xml | |
| retention-days: 1 | |
| docs: | |
| name: docs | |
| if: github.event_name != 'schedule' | |
| runs-on: ubuntu-latest | |
| needs: [php-unit-tests, php-integration-tests] | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - name: docs generate | |
| run: docker run --rm -v ${{ github.workspace }}:/data phpdoc/phpdoc@sha256:2b36e4f74937e40246d54ed12dfa4f988f21ed8d19e46f426ac3dc32eac2ff1d # v3.9.1 | |
| - name: publish api docs | |
| uses: peaceiris/actions-gh-pages@84c30a85c19949d7eee79c4ff27748b70285e453 # v4.1.0 | |
| if: github.event_name != 'pull_request' | |
| with: | |
| github_token: ${{ secrets.GITHUB_TOKEN }} | |
| publish_dir: docs | |
| publish_branch: docs | |
| force_orphan: true | |
| - name: compile docs hugo | |
| run: | | |
| mkdir docs-hugo | |
| cat docs-hugo-header.md README.md > docs-hugo/_index.md | |
| - name: publish docs hugo | |
| uses: peaceiris/actions-gh-pages@84c30a85c19949d7eee79c4ff27748b70285e453 # v4.1.0 | |
| if: github.event_name != 'pull_request' | |
| with: | |
| github_token: ${{ secrets.GITHUB_TOKEN }} | |
| publish_dir: docs-hugo | |
| publish_branch: docs-hugo | |
| force_orphan: true | |
| sonar-analysis: | |
| name: sonar analysis | |
| if: github.event_name != 'schedule' | |
| runs-on: ubuntu-latest | |
| needs: [php-unit-tests, php-integration-tests] | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| with: | |
| fetch-depth: '0' | |
| - name: download tests coverage | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| pattern: coverage-* | |
| path: results/ | |
| merge-multiple: 'true' | |
| - name: list-coverage-results | |
| run: ls -l results | |
| - name: sonarcloud | |
| uses: SonarSource/sonarqube-scan-action@299e4b793aaa83bf2aba7c9c14bedbb485688ec4 # v7.1.0 | |
| env: | |
| SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} |