feat(decdn_node): validate manual binaries are ELF + drain-safe stop timeout #79
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| --- | |
| name: Molecule | |
| # Containerised converge + idempotence + verify for the decdn_node role. | |
| # Heavy (privileged systemd Docker container) — scoped to ansible/ changes and | |
| # blocking. Mark it a required status check in branch protection once proven. | |
| on: | |
| pull_request: | |
| paths: ['ansible/**'] | |
| push: | |
| branches: [main] | |
| paths: ['ansible/**'] | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: molecule-${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| molecule: | |
| runs-on: ubuntu-latest # Docker is preinstalled | |
| defaults: | |
| run: | |
| working-directory: ansible | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: '3.12' | |
| - name: Install molecule + Ansible | |
| run: | | |
| python -m pip install --upgrade \ | |
| molecule "molecule-plugins[docker]" ansible ansible-lint docker | |
| - name: Install Galaxy collections | |
| run: make deps | |
| - name: molecule test | |
| # --all runs every scenario under ansible/molecule/: default | |
| # (operator-provisioned keystore + rendered-value assertions), schema | |
| # (config key-set drift against the upstream field list), validation | |
| # (bad knobs must be rejected by the role's own asserts), generate-keystore | |
| # (opt-in host-side wallet generation), host-env (host-provisioned | |
| # /etc/decdn/decdn.env — no secret on the control machine), and | |
| # slow-readiness (advisory /metrics probe timeout). | |
| run: molecule test --all |