Load shared instructions directly from root AGENTS.md #112
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| pull_request: | |
| push: | |
| branches: | |
| - main | |
| - master | |
| workflow_dispatch: | |
| concurrency: | |
| group: server-2-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| packages: write | |
| env: | |
| IMAGE_NAME: ghcr.io/${{ github.repository }} | |
| jobs: | |
| verify: | |
| name: Verify | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 45 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@v6 | |
| with: | |
| run_install: false | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: 25 | |
| cache: pnpm | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Start integration services | |
| run: | | |
| set -euo pipefail | |
| docker compose up -d postgres rabbitmq minio | |
| timeout 120 bash -c 'until docker compose exec -T postgres pg_isready -U solid -d solid_stats; do sleep 2; done' | |
| timeout 120 bash -c 'until docker compose exec -T rabbitmq rabbitmq-diagnostics -q ping; do sleep 2; done' | |
| timeout 120 bash -c 'until curl -fsS http://127.0.0.1:9000/minio/health/live; do sleep 2; done' | |
| docker compose run --rm minio-create-bucket | |
| - name: Run verification | |
| run: pnpm run verify | |
| - name: Stop integration services | |
| if: always() | |
| run: docker compose down --volumes --remove-orphans | |
| golden-oracle: | |
| name: Golden oracle (master-only) | |
| runs-on: ubuntu-latest | |
| # Master-only, slow, pre-deploy behavioral regression gate. NOT part of `verify` | |
| # and NOT a PR-required check — it needs the docker-compose services and may run | |
| # for several minutes. It pins the current ingest→stats behavior so a | |
| # behavior-preserving refactor stays green and any drift turns red. | |
| if: github.event_name == 'push' && (github.ref == 'refs/heads/master' || github.ref == 'refs/heads/main') | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@v6 | |
| with: | |
| run_install: false | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: 25 | |
| cache: pnpm | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Start integration services | |
| run: | | |
| set -euo pipefail | |
| docker compose up -d postgres rabbitmq minio | |
| timeout 120 bash -c 'until docker compose exec -T postgres pg_isready -U solid -d solid_stats; do sleep 2; done' | |
| timeout 120 bash -c 'until docker compose exec -T rabbitmq rabbitmq-diagnostics -q ping; do sleep 2; done' | |
| timeout 120 bash -c 'until curl -fsS http://127.0.0.1:9000/minio/health/live; do sleep 2; done' | |
| docker compose run --rm minio-create-bucket | |
| - name: Run golden oracle | |
| run: pnpm run test:golden | |
| - name: Stop integration services | |
| if: always() | |
| run: docker compose down --volumes --remove-orphans | |
| contract-diff: | |
| name: Contract diff | |
| runs-on: ubuntu-latest | |
| if: github.event_name == 'pull_request' | |
| timeout-minutes: 10 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| with: | |
| fetch-depth: 0 | |
| - name: Classify OpenAPI breaking changes | |
| uses: oasdiff/oasdiff-action/breaking@5ffbc910f1d1742f0dd9bf846a7f86954353556b # v0.0.56 | |
| with: | |
| base: "origin/${{ github.base_ref }}:openapi/server-2.openapi.json" | |
| revision: "HEAD:openapi/server-2.openapi.json" | |
| fail-on: ERR | |
| image: | |
| name: Build image | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| needs: verify | |
| if: github.event_name != 'pull_request' | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Login to GHCR | |
| uses: docker/login-action@v4 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Docker metadata | |
| id: meta | |
| uses: docker/metadata-action@v6 | |
| with: | |
| images: ${{ env.IMAGE_NAME }} | |
| tags: | | |
| type=raw,value=${{ github.sha }} | |
| type=ref,event=branch | |
| - name: Build and push | |
| uses: docker/build-push-action@v7 | |
| with: | |
| context: . | |
| push: true | |
| tags: ${{ steps.meta.outputs.tags }} | |
| labels: ${{ steps.meta.outputs.labels }} |