ci: run the auth tests on a schedule, and badge them - #26
Merged
Merged
Conversation
There was no way to badge the Keycloak tests. They run as a job inside the deploy workflow via workflow_call, and a reusable workflow's runs are recorded against the CALLER - so keycloak-tests.yml has no run history of its own to point a badge at. A shields badge for it renders "repo or workflow not found". Adding a schedule fixes that, but the reason to do it is not the badge. The post-deploy tests only prove the theme was healthy at the moment it shipped. auth.civicdatalab.in can break with no deploy involved: a client or realm setting changed in the admin console, a certificate expiring, Google rotating an identity-provider credential, the box filling its disk. None of that touches this repository, so nothing would notice until the next theme change - which could be weeks, on a server every product authenticates through. Runs every 6 hours: often enough to catch a break the same working day, rare enough not to become noise. Deploys nothing; read-only against the live server. Passes api_base_url so the health assertion runs rather than skipping. The badge will read "no status" until the first scheduled run.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds the tests badge — and the workflow that makes it mean something.
Why a badge was not possible before
The Keycloak tests run as a job inside the deploy workflow via
workflow_call, and a reusable workflow's runs are recorded against the caller. Sokeycloak-tests.ymlhas no run history of its own. A shields badge pointed at it renders:The real reason to add this
Not the badge. The post-deploy tests only prove the theme was healthy at the moment it shipped.
auth.civicdatalab.incan break with no deploy involved:None of that touches this repository, so nothing would notice until the next theme change — potentially weeks, on the server every CivicDataLab product authenticates through.
What it does
Runs the same checks every 6 hours — often enough to catch a break the same working day, rare enough not to be noise. Deploys nothing, read-only against the live server, and passes
api_base_urlso the health assertion runs rather than skipping.Also manually runnable via
workflow_dispatch, which works here because the file lands on the default branch.Badge
It will read
no statusuntil the first scheduled run, then reflect real state.Verified separately
#24's
paths-ignoreis confirmed working: merging #25 (docs-only) rancibut no deploy, while #24 (workflow change) ran both.