Skip to content

ci: run the auth tests on a schedule, and badge them - #26

Merged
saqibmanan merged 1 commit into
mainfrom
ci-scheduled-auth-tests
Sep 8, 2026
Merged

saqibmanan merged 1 commit into
mainfrom
ci-scheduled-auth-tests

Conversation

@saqibmanan

Copy link
Copy Markdown
Contributor

Adds the tests badge — and the workflow that makes it mean something.

Why a badge was not possible before

The Keycloak tests run as a job inside the deploy workflow via workflow_call, and a reusable workflow's runs are recorded against the caller. So keycloak-tests.yml has no run history of its own. A shields badge pointed at it renders:

auth tests: repo or workflow not found

The real reason to add this

Not the badge. The post-deploy tests only prove the theme was healthy at the moment it shipped.

auth.civicdatalab.in can break with no deploy involved:

  • a client or realm setting changed in the admin console
  • a certificate expiring
  • Google rotating an identity-provider credential
  • the box filling its disk

None of that touches this repository, so nothing would notice until the next theme change — potentially weeks, on the server every CivicDataLab product authenticates through.

What it does

Runs the same checks every 6 hours — often enough to catch a break the same working day, rare enough not to be noise. Deploys nothing, read-only against the live server, and passes api_base_url so the health assertion runs rather than skipping.

Also manually runnable via workflow_dispatch, which works here because the file lands on the default branch.

Badge

deploy: passing   ci: passing   auth tests: …   deploys to: auth.civicdatalab.in

It will read no status until the first scheduled run, then reflect real state.

Verified separately

#24's paths-ignore is confirmed working: merging #25 (docs-only) ran ci but no deploy, while #24 (workflow change) ran both.

There was no way to badge the Keycloak tests. They run as a job inside
the deploy workflow via workflow_call, and a reusable workflow's runs are
recorded against the CALLER - so keycloak-tests.yml has no run history of
its own to point a badge at. A shields badge for it renders "repo or
workflow not found".

Adding a schedule fixes that, but the reason to do it is not the badge.

The post-deploy tests only prove the theme was healthy at the moment it
shipped. auth.civicdatalab.in can break with no deploy involved: a client
or realm setting changed in the admin console, a certificate expiring,
Google rotating an identity-provider credential, the box filling its
disk. None of that touches this repository, so nothing would notice until
the next theme change - which could be weeks, on a server every product
authenticates through.

Runs every 6 hours: often enough to catch a break the same working day,
rare enough not to become noise. Deploys nothing; read-only against the
live server. Passes api_base_url so the health assertion runs rather than
skipping.

The badge will read "no status" until the first scheduled run.
@saqibmanan
saqibmanan merged commit 80b21d4 into main Sep 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant