Skip to content

Load shared instructions directly from root AGENTS.md #112

Load shared instructions directly from root AGENTS.md

Load shared instructions directly from root AGENTS.md #112

Workflow file for this run

name: CI
on:
pull_request:
push:
branches:
- main
- master
workflow_dispatch:
concurrency:
group: server-2-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
packages: write
env:
IMAGE_NAME: ghcr.io/${{ github.repository }}
jobs:
verify:
name: Verify
runs-on: ubuntu-latest
timeout-minutes: 45
steps:
- name: Checkout
uses: actions/checkout@v6
- name: Setup pnpm
uses: pnpm/action-setup@v6
with:
run_install: false
- name: Setup Node.js
uses: actions/setup-node@v6
with:
node-version: 25
cache: pnpm
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Start integration services
run: |
set -euo pipefail
docker compose up -d postgres rabbitmq minio
timeout 120 bash -c 'until docker compose exec -T postgres pg_isready -U solid -d solid_stats; do sleep 2; done'
timeout 120 bash -c 'until docker compose exec -T rabbitmq rabbitmq-diagnostics -q ping; do sleep 2; done'
timeout 120 bash -c 'until curl -fsS http://127.0.0.1:9000/minio/health/live; do sleep 2; done'
docker compose run --rm minio-create-bucket
- name: Run verification
run: pnpm run verify
- name: Stop integration services
if: always()
run: docker compose down --volumes --remove-orphans
golden-oracle:
name: Golden oracle (master-only)
runs-on: ubuntu-latest
# Master-only, slow, pre-deploy behavioral regression gate. NOT part of `verify`
# and NOT a PR-required check — it needs the docker-compose services and may run
# for several minutes. It pins the current ingest→stats behavior so a
# behavior-preserving refactor stays green and any drift turns red.
if: github.event_name == 'push' && (github.ref == 'refs/heads/master' || github.ref == 'refs/heads/main')
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@v6
- name: Setup pnpm
uses: pnpm/action-setup@v6
with:
run_install: false
- name: Setup Node.js
uses: actions/setup-node@v6
with:
node-version: 25
cache: pnpm
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Start integration services
run: |
set -euo pipefail
docker compose up -d postgres rabbitmq minio
timeout 120 bash -c 'until docker compose exec -T postgres pg_isready -U solid -d solid_stats; do sleep 2; done'
timeout 120 bash -c 'until docker compose exec -T rabbitmq rabbitmq-diagnostics -q ping; do sleep 2; done'
timeout 120 bash -c 'until curl -fsS http://127.0.0.1:9000/minio/health/live; do sleep 2; done'
docker compose run --rm minio-create-bucket
- name: Run golden oracle
run: pnpm run test:golden
- name: Stop integration services
if: always()
run: docker compose down --volumes --remove-orphans
contract-diff:
name: Contract diff
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
timeout-minutes: 10
steps:
- name: Checkout
uses: actions/checkout@v6
with:
fetch-depth: 0
- name: Classify OpenAPI breaking changes
uses: oasdiff/oasdiff-action/breaking@5ffbc910f1d1742f0dd9bf846a7f86954353556b # v0.0.56
with:
base: "origin/${{ github.base_ref }}:openapi/server-2.openapi.json"
revision: "HEAD:openapi/server-2.openapi.json"
fail-on: ERR
image:
name: Build image
runs-on: ubuntu-latest
timeout-minutes: 30
needs: verify
if: github.event_name != 'pull_request'
steps:
- name: Checkout
uses: actions/checkout@v6
- name: Login to GHCR
uses: docker/login-action@v4
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Docker metadata
id: meta
uses: docker/metadata-action@v6
with:
images: ${{ env.IMAGE_NAME }}
tags: |
type=raw,value=${{ github.sha }}
type=ref,event=branch
- name: Build and push
uses: docker/build-push-action@v7
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}