diff --git a/.github/workflows/deploy-backend.yml b/.github/workflows/deploy-backend.yml index 52540c4..38ea4df 100644 --- a/.github/workflows/deploy-backend.yml +++ b/.github/workflows/deploy-backend.yml @@ -287,9 +287,6 @@ jobs: with: suite: functional api_base_url: ${{ vars.DEV_API_BASE_URL }} - # Provider functional is flaky against dev, so it runs report-only in - # provider-functional-report instead of gating the deploy. - skip_provider: true secrets: HOME_URL_DEV: ${{ secrets.HOME_URL_DEV }} TEST_EMAIL_1: ${{ secrets.TEST_EMAIL_1 }} @@ -298,36 +295,12 @@ jobs: TEST_PASSWORD_2: ${{ secrets.TEST_PASSWORD_2 }} KEYCLOAK_CLIENT_SECRET: ${{ secrets.KEYCLOAK_CLIENT_SECRET }} - provider-functional-report: - name: Provider Functional (report-only) - needs: smoke-tests - # Report-only: rollback and finalize do not list this job in needs, so - # its result never rolls back or blocks a dev deploy. Promote it to a - # gate once the provider suite is stable against dev. - if: github.ref_name != 'main' - uses: CivicDataLab/CivicDataSpace-test/.github/workflows/run-smoke.yml@CI - with: - suite: functional - only_provider: true - api_base_url: ${{ vars.DEV_API_BASE_URL }} - secrets: - HOME_URL_DEV: ${{ secrets.HOME_URL_DEV }} - TEST_EMAIL_1: ${{ secrets.TEST_EMAIL_1 }} - TEST_PASSWORD_1: ${{ secrets.TEST_PASSWORD_1 }} - TEST_EMAIL_2: ${{ secrets.TEST_EMAIL_2 }} - TEST_PASSWORD_2: ${{ secrets.TEST_PASSWORD_2 }} - # org_add_permission needs a token to check canAdd; without this every - # org-create test skips on both workers and the report is hollow. - KEYCLOAK_CLIENT_SECRET: ${{ secrets.KEYCLOAK_CLIENT_SECRET }} - rollback-on-smoke-failure: name: Rollback (smoke tests failed) # `deploy` must be in needs: for needs.deploy.result to resolve here. - # provider-functional-report is listed so this waits for every test to - # finish, but its result is deliberately not checked (report-only). - needs: [deploy, smoke-tests, functional-tests, provider-functional-report] - # Explicit gating results, not failure(): failure() would also count the - # report-only provider job. !cancelled() keeps cancellation a no-op. + needs: [deploy, smoke-tests, functional-tests] + # Explicit results rather than failure(), so that a skipped functional stage + # on main never reads as a failure. !cancelled() keeps cancellation a no-op. if: >- ${{ !cancelled() && needs.deploy.result == 'success' && (needs.smoke-tests.result == 'failure' || needs.functional-tests.result == 'failure') }} @@ -377,11 +350,9 @@ jobs: finalize-deploy: name: Finalize Deploy - # provider-functional-report is listed so this waits for every test to - # finish, but its result is deliberately not checked (report-only). - needs: [deploy, smoke-tests, functional-tests, provider-functional-report] - # Explicit gating results, not success()/!failure(): on main the functional - # jobs are skipped by design, and the provider job must not block. + needs: [deploy, smoke-tests, functional-tests] + # Explicit results, not success()/!failure(): on main the functional stage + # is skipped by design. if: >- ${{ !cancelled() && needs.deploy.result == 'success' && needs.smoke-tests.result == 'success' && diff --git a/.github/workflows/pr-gate.yml b/.github/workflows/pr-gate.yml index 3a804c1..5a9f6ce 100644 --- a/.github/workflows/pr-gate.yml +++ b/.github/workflows/pr-gate.yml @@ -1,7 +1,8 @@ # Full test suite against dev for every PR into main. Required by branch # protection on main, so a PR merges (and prod deploys) only once it's green. -# dev already runs the PR's code (it was merged to dev first); deployed_sha -# makes the suite fail if dev is running anything else. +# Releases come from dev, so the suite checks that dev is running dev's head: +# not the PR head, which is a different commit whenever a release is built as +# a merge to resolve conflicts. name: PR Gate on: @@ -22,37 +23,29 @@ jobs: name: Django Tests uses: ./.github/workflows/django-tests.yml + dev-head: + name: Resolve dev head + runs-on: ubuntu-latest + outputs: + sha: ${{ steps.dev.outputs.sha }} + steps: + - id: dev + env: + GH_TOKEN: ${{ github.token }} + run: echo "sha=$(gh api repos/${{ github.repository }}/commits/dev --jq .sha)" >> "$GITHUB_OUTPUT" + full-suite: name: Full Suite (dev) + needs: dev-head uses: CivicDataLab/CivicDataSpace-test/.github/workflows/run-smoke.yml@CI with: suite: full - # Provider is flaky against dev: it reports in provider-report below, which - # branch protection does not require. - skip_provider: true - api_base_url: ${{ vars.DEV_API_BASE_URL }} - deployed_sha: ${{ github.event.pull_request.head.sha }} - secrets: - HOME_URL_DEV: ${{ secrets.HOME_URL_DEV }} - TEST_EMAIL_1: ${{ secrets.TEST_EMAIL_1 }} - TEST_PASSWORD_1: ${{ secrets.TEST_PASSWORD_1 }} - TEST_EMAIL_2: ${{ secrets.TEST_EMAIL_2 }} - TEST_PASSWORD_2: ${{ secrets.TEST_PASSWORD_2 }} - KEYCLOAK_CLIENT_SECRET: ${{ secrets.KEYCLOAK_CLIENT_SECRET }} - - provider-report: - name: Provider Full Suite (report-only) - uses: CivicDataLab/CivicDataSpace-test/.github/workflows/run-smoke.yml@CI - with: - suite: full - only_provider: true api_base_url: ${{ vars.DEV_API_BASE_URL }} + deployed_sha: ${{ needs.dev-head.outputs.sha }} secrets: HOME_URL_DEV: ${{ secrets.HOME_URL_DEV }} TEST_EMAIL_1: ${{ secrets.TEST_EMAIL_1 }} TEST_PASSWORD_1: ${{ secrets.TEST_PASSWORD_1 }} TEST_EMAIL_2: ${{ secrets.TEST_EMAIL_2 }} TEST_PASSWORD_2: ${{ secrets.TEST_PASSWORD_2 }} - # org_add_permission needs a token to check canAdd; without this every - # org-create test skips on both workers and the report is hollow. KEYCLOAK_CLIENT_SECRET: ${{ secrets.KEYCLOAK_CLIENT_SECRET }}