-
Notifications
You must be signed in to change notification settings - Fork 0
203 lines (188 loc) · 10.1 KB
/
Copy pathci.yml
File metadata and controls
203 lines (188 loc) · 10.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
# Base CI – minute-saving without breaking required gates (SYSTEM.md §11)
# Adapted from Entwicklungsplan/templates/base/ci.yml: pnpm + Node 24 (TS app), uv (Python AI service),
# action majors as of 2026-09-22 (template still pins v4).
#
# No workflow-wide paths-ignore: a skipped required workflow stays "Pending" and blocks doc PRs.
# The required job `check` always runs, detects doc-only changes internally and is green at once –
# expensive steps run only for code changes with a manifest.
name: CI
# No branches filter: stacked PRs on slice branches must be checked too.
# Explicit types: the defaults (opened, synchronize, reopened) never re-run the PR guard when a draft is
# marked ready (verify-green rule) or when the description is edited; `labeled` starts the full run when
# `verify-full` is added to an open PR (#89).
on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review, edited, labeled]
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
check:
runs-on: ubuntu-latest # Linux only: Windows counts 2x, macOS 10x minutes.
timeout-minutes: 15
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- name: Detect doc-only changes
id: diff
run: |
# The label `verify-full` counts as a code change (#89): a release PR changes only Markdown
# but must still run verify:full (AGENTS.md).
forced="${{ contains(github.event.pull_request.labels.*.name, 'verify-full') }}"
if [ "$forced" = "true" ] || git diff --name-only "origin/${{ github.base_ref }}...HEAD" | grep -qvE '^docs/|\.md$'; then
echo "code=true" >> "$GITHUB_OUTPUT"
else
echo "code=false" >> "$GITHUB_OUTPUT"
fi
if [ "$forced" = "true" ] || git diff --name-only "origin/${{ github.base_ref }}...HEAD" | grep -qE '^(services/ai|contracts)/'; then
echo "ai=true" >> "$GITHUB_OUTPUT"
else
echo "ai=false" >> "$GITHUB_OUTPUT"
fi
# Docs guard: runs on EVERY PR. Seconds, no dependencies. (SYSTEM.md §2, §9)
- name: Docs guard
run: bash scripts/doku-check.sh
# The Vercel image of the AI service must not drift from the service Dockerfile (#79). Seconds.
- name: AI Dockerfiles in step
run: bash scripts/check-ai-dockerfiles.sh
# PR guard: plain language, plan gate, exactly one docs decision, file-size gate,
# before-creating proof, next step for drafts, green verify for ready-for-review.
- name: PR guard
env:
PR_BODY: ${{ github.event.pull_request.body }}
PR_DRAFT: ${{ github.event.pull_request.draft }}
PR_TITLE: ${{ github.event.pull_request.title }}
BASE_REF: origin/${{ github.base_ref }}
run: bash scripts/pr-check.sh
- name: Doc-only result
if: steps.diff.outputs.code == 'false'
run: echo "Docs only – docs guard green, base gate green."
# Foundation phase: no manifest yet. Report honestly instead of faking green tests.
- name: Foundation phase (TS)
if: steps.diff.outputs.code == 'true' && hashFiles('package.json') == ''
run: echo "No package.json – foundation phase, TS verify not applicable yet. Disappears with the first code issue."
# --- TS app: verify (lint, types, tests, architecture check, build, audit) ---------------
- uses: pnpm/action-setup@v6
if: steps.diff.outputs.code == 'true' && hashFiles('package.json') != ''
- uses: actions/setup-node@v7
if: steps.diff.outputs.code == 'true' && hashFiles('package.json') != ''
with:
node-version: 24
cache: pnpm
- run: pnpm install --frozen-lockfile
if: steps.diff.outputs.code == 'true' && hashFiles('package.json') != ''
# Integration tests run against real PostgreSQL + SeaweedFS from compose.yaml (same images,
# init script and local-default credentials as on a developer machine – no CI secrets).
- name: Start PostgreSQL + SeaweedFS
if: steps.diff.outputs.code == 'true' && hashFiles('package.json') != ''
run: |
docker compose up -d postgres storage
for _ in $(seq 1 60); do
s3="$(curl -s -o /dev/null -w '%{http_code}' http://127.0.0.1:8333/ || true)"
if docker compose exec -T postgres pg_isready -h 127.0.0.1 -U postgres -d requestflow >/dev/null 2>&1 && [ "$s3" != "000" ]; then
echo "postgres ready, storage answers HTTP $s3"; exit 0
fi
sleep 2
done
docker compose logs --tail 50
exit 1
- run: pnpm verify
if: steps.diff.outputs.code == 'true' && hashFiles('package.json') != ''
# verify:full (integration + E2E smoke + eval gate): P2 always, otherwise only with label verify-full.
- name: Read stage from profile
id: profile
if: steps.diff.outputs.code == 'true' && hashFiles('package.json') != ''
run: echo "stage=$(sed -n 's/^[[:space:]]*stage:[[:space:]]*\([a-z]*\).*/\1/p' project-profile.yml | head -1)" >> "$GITHUB_OUTPUT"
# verify:full ends with the eval gate (`uv run …`): uv must exist before it, also without AI changes (#90 review).
- uses: astral-sh/setup-uv@v10.2.0 # no floating v10 tag exists (verified 2026-09-22)
if: hashFiles('services/ai/pyproject.toml') != '' && (steps.diff.outputs.ai == 'true' || (steps.diff.outputs.code == 'true' && hashFiles('package.json') != '' && (steps.profile.outputs.stage == 'production' || contains(github.event.pull_request.labels.*.name, 'verify-full'))))
with:
enable-cache: true
- name: Install Playwright Chromium (E2E smoke)
if: steps.diff.outputs.code == 'true' && hashFiles('package.json') != '' && (steps.profile.outputs.stage == 'production' || contains(github.event.pull_request.labels.*.name, 'verify-full'))
run: pnpm exec playwright install --with-deps chromium
- run: pnpm verify:full
if: steps.diff.outputs.code == 'true' && hashFiles('package.json') != '' && (steps.profile.outputs.stage == 'production' || contains(github.event.pull_request.labels.*.name, 'verify-full'))
# --- Python AI service: path-targeted (services/ai, contracts) ---------------------------
# The AI eval gate (ADR-0001 D8, #24) runs in replay mode on every change under services/ai/:
# recorded model responses, no credentials. Live evals (--live, Vertex) never run in CI.
- name: Foundation phase (AI service)
if: steps.diff.outputs.ai == 'true' && hashFiles('services/ai/pyproject.toml') == ''
run: echo "No services/ai/pyproject.toml – AI service not created yet."
# uv is installed above (before verify:full) whenever this section runs.
- name: AI service verify (ruff, pyright, pytest)
if: steps.diff.outputs.ai == 'true' && hashFiles('services/ai/pyproject.toml') != ''
working-directory: services/ai
run: |
uv sync --frozen
uv run ruff check .
uv run ruff format --check .
uv run pyright
uv run pytest -q
# Eval gate: fails when a key field drops by more than EVAL_GATE_THRESHOLD points against
# services/ai/evals/baseline.json, on any injection violation or case error.
- name: AI eval gate (replay)
if: steps.diff.outputs.ai == 'true' && hashFiles('services/ai/pyproject.toml') != ''
working-directory: services/ai
env:
EVAL_GATE_THRESHOLD: "5"
run: uv run python -m requestflow_ai.evals --replay --report "$RUNNER_TEMP/eval-report.json"
# Image + compose smoke (ADR-0001 D11): only when the Dockerfile or the compose file changes.
compose-smoke:
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- name: Detect image changes
id: diff
run: |
if git diff --name-only "origin/${{ github.base_ref }}...HEAD" | grep -qE '(^|/)Dockerfile$|^compose\.yaml$|^\.dockerignore$|^docker/'; then
echo "image=true" >> "$GITHUB_OUTPUT"
else
echo "image=false" >> "$GITHUB_OUTPUT"
fi
if git diff --name-only "origin/${{ github.base_ref }}...HEAD" | grep -qE '^services/ai/(src/|Dockerfile|Dockerfile\.vercel$|\.dockerignore$|\.vercelignore$|pyproject\.toml$|uv\.lock$|README\.md$)'; then
echo "ai_image=true" >> "$GITHUB_OUTPUT"
else
echo "ai_image=false" >> "$GITHUB_OUTPUT"
fi
- name: docker compose up → /api/health
if: steps.diff.outputs.image == 'true'
run: |
if ! docker compose up -d --build; then
docker compose ps -a
docker compose logs --tail 80
exit 1
fi
for _ in $(seq 1 60); do
if curl -fsS http://127.0.0.1:3000/api/health; then echo; docker compose ps; exit 0; fi
sleep 3
done
docker compose ps
docker compose logs --tail 80
exit 1
- name: Worker is running
if: steps.diff.outputs.image == 'true'
run: docker compose ps --status running --services | grep -qx worker
# The image Vercel runs on the showcase (#79): build it and prove it starts – non-root, on $PORT.
# Runs on every change that reaches the image (source, recipe, ignore files, lock, README); ~1 min.
# Synthetic settings only; the model client is not called by /healthz.
- name: Vercel AI image → /healthz
if: steps.diff.outputs.ai_image == 'true'
run: |
docker build -f services/ai/Dockerfile.vercel -t requestflow-ai-vercel services/ai
docker run -d --name ai-vercel -p 8080:8080 -e PORT=8080 \
-e AI_SERVICE_TOKEN=ci-only-synthetic-token-0123456789 \
-e AI_ALLOW_GEMINI_API_DEV=true -e GEMINI_API_KEY=ci-only-not-a-key \
requestflow-ai-vercel
for _ in $(seq 1 40); do
if curl -fsS http://127.0.0.1:8080/healthz; then echo; exit 0; fi
sleep 3
done
docker logs --tail 80 ai-vercel
exit 1