Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 6 additions & 35 deletions .github/workflows/deploy-backend.yml
Original file line number Diff line number Diff line change
Expand Up @@ -287,9 +287,6 @@ jobs:
with:
suite: functional
api_base_url: ${{ vars.DEV_API_BASE_URL }}
# Provider functional is flaky against dev, so it runs report-only in
# provider-functional-report instead of gating the deploy.
skip_provider: true
secrets:
HOME_URL_DEV: ${{ secrets.HOME_URL_DEV }}
TEST_EMAIL_1: ${{ secrets.TEST_EMAIL_1 }}
Expand All @@ -298,36 +295,12 @@ jobs:
TEST_PASSWORD_2: ${{ secrets.TEST_PASSWORD_2 }}
KEYCLOAK_CLIENT_SECRET: ${{ secrets.KEYCLOAK_CLIENT_SECRET }}

provider-functional-report:
name: Provider Functional (report-only)
needs: smoke-tests
# Report-only: rollback and finalize do not list this job in needs, so
# its result never rolls back or blocks a dev deploy. Promote it to a
# gate once the provider suite is stable against dev.
if: github.ref_name != 'main'
uses: CivicDataLab/CivicDataSpace-test/.github/workflows/run-smoke.yml@CI
with:
suite: functional
only_provider: true
api_base_url: ${{ vars.DEV_API_BASE_URL }}
secrets:
HOME_URL_DEV: ${{ secrets.HOME_URL_DEV }}
TEST_EMAIL_1: ${{ secrets.TEST_EMAIL_1 }}
TEST_PASSWORD_1: ${{ secrets.TEST_PASSWORD_1 }}
TEST_EMAIL_2: ${{ secrets.TEST_EMAIL_2 }}
TEST_PASSWORD_2: ${{ secrets.TEST_PASSWORD_2 }}
# org_add_permission needs a token to check canAdd; without this every
# org-create test skips on both workers and the report is hollow.
KEYCLOAK_CLIENT_SECRET: ${{ secrets.KEYCLOAK_CLIENT_SECRET }}

rollback-on-smoke-failure:
name: Rollback (smoke tests failed)
# `deploy` must be in needs: for needs.deploy.result to resolve here.
# provider-functional-report is listed so this waits for every test to
# finish, but its result is deliberately not checked (report-only).
needs: [deploy, smoke-tests, functional-tests, provider-functional-report]
# Explicit gating results, not failure(): failure() would also count the
# report-only provider job. !cancelled() keeps cancellation a no-op.
needs: [deploy, smoke-tests, functional-tests]
# Explicit results rather than failure(), so that a skipped functional stage
# on main never reads as a failure. !cancelled() keeps cancellation a no-op.
if: >-
${{ !cancelled() && needs.deploy.result == 'success' &&
(needs.smoke-tests.result == 'failure' || needs.functional-tests.result == 'failure') }}
Expand Down Expand Up @@ -377,11 +350,9 @@ jobs:

finalize-deploy:
name: Finalize Deploy
# provider-functional-report is listed so this waits for every test to
# finish, but its result is deliberately not checked (report-only).
needs: [deploy, smoke-tests, functional-tests, provider-functional-report]
# Explicit gating results, not success()/!failure(): on main the functional
# jobs are skipped by design, and the provider job must not block.
needs: [deploy, smoke-tests, functional-tests]
# Explicit results, not success()/!failure(): on main the functional stage
# is skipped by design.
if: >-
${{ !cancelled() && needs.deploy.result == 'success' &&
needs.smoke-tests.result == 'success' &&
Expand Down
39 changes: 16 additions & 23 deletions .github/workflows/pr-gate.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,8 @@
# Full test suite against dev for every PR into main. Required by branch
# protection on main, so a PR merges (and prod deploys) only once it's green.
# dev already runs the PR's code (it was merged to dev first); deployed_sha
# makes the suite fail if dev is running anything else.
# Releases come from dev, so the suite checks that dev is running dev's head:
# not the PR head, which is a different commit whenever a release is built as
# a merge to resolve conflicts.
name: PR Gate

on:
Expand All @@ -22,37 +23,29 @@ jobs:
name: Django Tests
uses: ./.github/workflows/django-tests.yml

dev-head:
name: Resolve dev head
runs-on: ubuntu-latest
outputs:
sha: ${{ steps.dev.outputs.sha }}
steps:
- id: dev
env:
GH_TOKEN: ${{ github.token }}
run: echo "sha=$(gh api repos/${{ github.repository }}/commits/dev --jq .sha)" >> "$GITHUB_OUTPUT"

full-suite:
name: Full Suite (dev)
needs: dev-head
uses: CivicDataLab/CivicDataSpace-test/.github/workflows/run-smoke.yml@CI
with:
suite: full
# Provider is flaky against dev: it reports in provider-report below, which
# branch protection does not require.
skip_provider: true
api_base_url: ${{ vars.DEV_API_BASE_URL }}
deployed_sha: ${{ github.event.pull_request.head.sha }}
secrets:
HOME_URL_DEV: ${{ secrets.HOME_URL_DEV }}
TEST_EMAIL_1: ${{ secrets.TEST_EMAIL_1 }}
TEST_PASSWORD_1: ${{ secrets.TEST_PASSWORD_1 }}
TEST_EMAIL_2: ${{ secrets.TEST_EMAIL_2 }}
TEST_PASSWORD_2: ${{ secrets.TEST_PASSWORD_2 }}
KEYCLOAK_CLIENT_SECRET: ${{ secrets.KEYCLOAK_CLIENT_SECRET }}

provider-report:
name: Provider Full Suite (report-only)
uses: CivicDataLab/CivicDataSpace-test/.github/workflows/run-smoke.yml@CI
with:
suite: full
only_provider: true
api_base_url: ${{ vars.DEV_API_BASE_URL }}
deployed_sha: ${{ needs.dev-head.outputs.sha }}
secrets:
HOME_URL_DEV: ${{ secrets.HOME_URL_DEV }}
TEST_EMAIL_1: ${{ secrets.TEST_EMAIL_1 }}
TEST_PASSWORD_1: ${{ secrets.TEST_PASSWORD_1 }}
TEST_EMAIL_2: ${{ secrets.TEST_EMAIL_2 }}
TEST_PASSWORD_2: ${{ secrets.TEST_PASSWORD_2 }}
# org_add_permission needs a token to check canAdd; without this every
# org-create test skips on both workers and the report is hollow.
KEYCLOAK_CLIENT_SECRET: ${{ secrets.KEYCLOAK_CLIENT_SECRET }}
Loading