Skip to content

mandate constitution upload #1331

mandate constitution upload

mandate constitution upload #1331

# ========================================
# Note: If you make changes to this CI/CD, please include someone from DevOps in the list of reviewers for the PR.
# ========================================
name: Build and Deploy Clubs
on: push
jobs:
backend-check:
name: Backend Check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Dependencies
run: |-
cd backend
uv sync --frozen
- name: Lint
run: |-
cd backend
uv run ruff check .
- name: Format
run: |-
cd backend
uv run ruff format .
- name: Test (run in parallel)
run: |-
cd backend
uv run coverage run --concurrency=multiprocessing manage.py test --settings=pennclubs.settings.ci --parallel
uv run coverage combine
uv run coverage xml
- name: Upload Code Coverage
uses: codecov/codecov-action@v4
with:
token: ${{ secrets.CODECOV_TOKEN }}
directory: backend
fail_ci_if_error: true
files: coverage.xml
name: codecov-umbrella
verbose: true
container:
image: ghcr.io/astral-sh/uv:0.6.10-python3.13-bookworm
env:
DATABASE_URL: postgres://postgres:postgres@postgres:5432/postgres
services:
postgres:
image: postgres:17
env:
POSTGRES_USER: postgres
POSTGRES_DB: postgres
POSTGRES_PASSWORD: postgres
options: "--health-cmd pg_isready --health-interval 10s --health-timeout 5s --health-retries 5"
frontend-check:
name: "Frontend Check"
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Dependencies
run: |-
cd frontend
bun install --frozen-lockfile
- name: Lint
run: |-
cd frontend
bun lint
container:
image: oven/bun:1.2.6-slim
build-backend:
name: Build backend
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: docker/setup-qemu-action@v1
- uses: docker/setup-buildx-action@v1
- name: Cache Docker layers
uses: actions/cache@v4
with:
path: /tmp/.buildx-cache
key: buildx-build-backend
- name: Build/Publish
uses: docker/build-push-action@v2
with:
context: backend
file: backend/Dockerfile
push: false
cache-from: type=local,src=/tmp/.buildx-cache,type=registry,ref=pennlabs/penn-clubs-backend:latest
cache-to: type=local,dest=/tmp/.buildx-cache
tags: pennlabs/penn-clubs-backend:latest,pennlabs/penn-clubs-backend:${{ github.sha }}
outputs: type=docker,dest=/tmp/image.tar
- uses: actions/upload-artifact@v4
with:
name: build-backend
path: /tmp/image.tar
needs: backend-check
build-frontend:
name: Build frontend
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: docker/setup-qemu-action@v1
- uses: docker/setup-buildx-action@v1
- name: Cache Docker layers
uses: actions/cache@v4
with:
path: /tmp/.buildx-cache
key: buildx-build-frontend
- name: Build/Publish
uses: docker/build-push-action@v2
with:
context: frontend
file: frontend/Dockerfile
push: false
cache-from: type=local,src=/tmp/.buildx-cache,type=registry,ref=pennlabs/penn-clubs-frontend:latest
cache-to: type=local,dest=/tmp/.buildx-cache
tags: pennlabs/penn-clubs-frontend:latest,pennlabs/penn-clubs-frontend:${{ github.sha }}
outputs: type=docker,dest=/tmp/image.tar
- uses: actions/upload-artifact@v4
with:
name: build-frontend
path: /tmp/image.tar
needs: frontend-check
publish:
name: Publish Images
runs-on: ubuntu-latest
if: github.ref == 'refs/heads/master'
steps:
- uses: actions/checkout@v4
- uses: actions/download-artifact@v4
- uses: geekyeggo/delete-artifact@v5
with:
name: |-
build-backend
build-frontend
- name: Load docker images
run: |-
docker load --input build-backend/image.tar
docker load --input build-frontend/image.tar
- uses: docker/login-action@v1
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Push docker images
run: |-
docker push -a pennlabs/penn-clubs-backend
docker push -a pennlabs/penn-clubs-frontend
needs:
- build-backend
- build-frontend
deploy:
name: "Deploy"
uses: pennlabs/shared-actions/.github/workflows/deployment.yaml@v0.1.9
with:
githubRef: ${{ github.ref }}
gitSha: ${{ github.sha }}
secrets:
AWS_ACCOUNT_ID: ${{ secrets.AWS_ACCOUNT_ID }}
GH_AWS_ACCESS_KEY_ID: ${{ secrets.GH_AWS_ACCESS_KEY_ID }}
GH_AWS_SECRET_ACCESS_KEY: ${{ secrets.GH_AWS_SECRET_ACCESS_KEY }}
needs:
- publish