Compare commits
4
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f3491ef4a6 | ||
|
|
d6a4f7c41f | ||
|
|
211edc4538 | ||
|
|
14b325b3bf |
+53
-28
@@ -6,37 +6,48 @@ on:
|
|||||||
pull_request:
|
pull_request:
|
||||||
branches: [main]
|
branches: [main]
|
||||||
|
|
||||||
|
env:
|
||||||
|
REGISTRY: git.arthurerlich.de
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test:
|
build-dev:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Set up PHP
|
- name: Set up Docker Buildx
|
||||||
uses: shivammathur/setup-php@v2
|
uses: docker/setup-buildx-action@v3
|
||||||
|
|
||||||
|
# type=gha depends on act_runner's internal cache proxy, which is unreachable
|
||||||
|
# from job containers on this runner (dial tcp ... i/o timeout). Use the
|
||||||
|
# registry cache backend instead, same as docker-publish.yml.
|
||||||
|
- name: Log in to Gitea registry
|
||||||
|
uses: docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
php-version: "8.4"
|
registry: ${{ env.REGISTRY }}
|
||||||
extensions: intl, zip, opcache
|
username: ${{ gitea.actor }}
|
||||||
coverage: none
|
password: ${{ secrets.REGISTRY_TOKEN }}
|
||||||
|
|
||||||
- name: Cache Composer dependencies
|
- name: Build dev image (PHP 8.4 + composer deps)
|
||||||
uses: actions/cache@v4
|
uses: docker/build-push-action@v5
|
||||||
with:
|
with:
|
||||||
path: ~/.composer/cache
|
context: .
|
||||||
key: composer-${{ hashFiles('composer.lock') }}
|
file: Dockerfile.dev
|
||||||
restore-keys: composer-
|
target: dev
|
||||||
|
outputs: type=docker,dest=/tmp/graph-dev.tar
|
||||||
|
tags: graph-dev:ci
|
||||||
|
cache-from: type=registry,ref=${{ env.REGISTRY }}/${{ gitea.repository }}:buildcache-dev
|
||||||
|
cache-to: type=registry,ref=${{ env.REGISTRY }}/${{ gitea.repository }}:buildcache-dev,mode=max
|
||||||
|
|
||||||
- name: Install dependencies
|
- name: Upload dev image
|
||||||
run: composer install --no-interaction --prefer-dist
|
uses: actions/upload-artifact@v3
|
||||||
|
with:
|
||||||
- name: Run PHPUnit
|
name: graph-dev-image
|
||||||
run: vendor/bin/phpunit --testdox
|
path: /tmp/graph-dev.tar
|
||||||
|
retention-days: 1
|
||||||
- name: Run PHPStan
|
build-prod:
|
||||||
run: composer phpstan
|
needs: build-dev
|
||||||
|
|
||||||
docker-build:
|
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
@@ -53,10 +64,24 @@ jobs:
|
|||||||
target: final
|
target: final
|
||||||
push: false
|
push: false
|
||||||
|
|
||||||
- name: Build dev image (dev target)
|
test:
|
||||||
uses: docker/build-push-action@v5
|
needs: build-dev
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Download dev image
|
||||||
|
uses: actions/download-artifact@v3
|
||||||
with:
|
with:
|
||||||
context: .
|
name: graph-dev-image
|
||||||
file: Dockerfile.dev
|
path: /tmp
|
||||||
target: dev
|
|
||||||
push: false
|
- name: Load dev image
|
||||||
|
run: docker load --input /tmp/graph-dev.tar
|
||||||
|
|
||||||
|
- name: Run PHPUnit
|
||||||
|
run: docker run --rm graph-dev:ci vendor/bin/phpunit --testdox
|
||||||
|
|
||||||
|
- name: Run PHPStan
|
||||||
|
run: docker run --rm graph-dev:ci composer phpstan
|
||||||
|
|||||||
@@ -138,12 +138,29 @@ Workflow files live in [.gitea/workflows/](.gitea/workflows/). This project uses
|
|||||||
- Secrets are set under Repository → Settings → Secrets → Actions
|
- Secrets are set under Repository → Settings → Secrets → Actions
|
||||||
- The registry hostname must be derived from `gitea.server_url` (strip the protocol prefix)
|
- The registry hostname must be derived from `gitea.server_url` (strip the protocol prefix)
|
||||||
- Triggers use standard `on:` syntax; `tags: '*.*.*'` matches semver pushes without a `v` prefix
|
- Triggers use standard `on:` syntax; `tags: '*.*.*'` matches semver pushes without a `v` prefix
|
||||||
|
- Do not use `cache-from/cache-to: type=gha` — on this instance's act_runner (v2.0.0), the internal GitHub Actions-cache-compatible proxy is not reachable from job containers (`dial tcp <ip>:<port>: i/o timeout`), a known act_runner docker-executor networking limitation, not a workflow bug. Use `type=registry` instead (push cache blobs to `${{ env.REGISTRY }}/<repo>:buildcache*` — see both `test.yml` and `docker-publish.yml`); it requires a registry login step even for jobs that don't push the final image.
|
||||||
|
|
||||||
**Current workflows:**
|
**Current workflows:**
|
||||||
|
|
||||||
| File | Trigger | Purpose |
|
| File | Trigger | Purpose |
|
||||||
| -------------------- | ---------------- | --------------------------------------------------------- |
|
| -------------------- | ---------------- | --------------------------------------------------------- |
|
||||||
| `docker-publish.yml` | Push tag `*.*.*` | Build & push multi-arch image to Gitea container registry |
|
| `docker-publish.yml` | Push tag `*.*.*` | Build & push multi-arch image to Gitea container registry |
|
||||||
|
| `test.yml` | Push/PR to `main`| Build dev+prod images, run PHPUnit and PHPStan |
|
||||||
|
|
||||||
|
### Release testing with `act`
|
||||||
|
|
||||||
|
Before tagging a release (anything that would trigger `docker-publish.yml`), run `test.yml` locally with [`act`](https://github.com/nektos/act) to catch pipeline failures before pushing. `test.yml` uses plain GitHub Actions syntax (no `gitea.*` contexts), so it runs under `act` unmodified.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
act -j test \
|
||||||
|
-P ubuntu-latest=catthehacker/ubuntu:act-latest \
|
||||||
|
--artifact-server-path /tmp/act-artifacts
|
||||||
|
```
|
||||||
|
|
||||||
|
- `-P ubuntu-latest=catthehacker/ubuntu:act-latest` — default act runner image lacks a Docker CLI, which the `test` job needs for its nested `docker run` steps
|
||||||
|
- `--artifact-server-path` — required for the `upload-artifact`/`download-artifact` steps to work; without it they silently no-op
|
||||||
|
|
||||||
|
**If `act` is not installed:** warn the user it's missing and how to install it (`sudo pacman -S act`, or see the repo above) — do not install it yourself or force the check. `docker-publish.yml` is out of scope for `act` (it needs real `gitea.*` context and a live registry secret); don't try to run it locally.
|
||||||
|
|
||||||
## Docker
|
## Docker
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user