diff --git a/.github/workflows/auth-tests.yml b/.github/workflows/auth-tests.yml new file mode 100644 index 0000000..c6c204e --- /dev/null +++ b/.github/workflows/auth-tests.yml @@ -0,0 +1,48 @@ +# Keycloak auth checks, run on a schedule rather than only after a deploy. +# +# The post-deploy tests in deploy-keycloak-staging.yml only prove the theme was +# healthy at the moment it shipped. auth.civicdatalab.in can break without any +# deploy happening: a realm or client setting changed in the admin console, a +# certificate expiring, an identity provider (Google) rotating credentials, the +# box running out of disk. None of that touches this repository, so nothing +# would notice until the next theme change - which could be weeks. +# +# This runs the same tests independently, so a break is found in hours rather +# than at the next deploy. It also gives the tests a real run history, which a +# reusable workflow called from a deploy does not have: those runs are recorded +# against the CALLER, so there is nothing to point a status badge at. +# +# Deploys nothing. Read-only against the live server. + +name: Auth tests + +on: + schedule: + # Every 6 hours. Frequent enough that a break is caught the same working + # day, infrequent enough not to be noise. Times are UTC. + - cron: '0 */6 * * *' + workflow_dispatch: + inputs: + keycloak_url: + description: 'Keycloak base URL to test' + type: string + required: false + default: 'https://auth.civicdatalab.in' + +concurrency: + group: auth-tests + cancel-in-progress: true + +jobs: + auth: + name: Auth pages + uses: CivicDataLab/CivicDataSpace-test/.github/workflows/keycloak-tests.yml@CI + with: + keycloak_url: ${{ inputs.keycloak_url || 'https://auth.civicdatalab.in' }} + app_base_url: https://dev.civicdataspace.in + api_base_url: https://dev.api.civicdataspace.in + secrets: + HOME_URL_DEV: ${{ secrets.HOME_URL_DEV }} + # Optional. Present -> the registration tests run too; absent -> they skip, + # because they create real accounts and must be able to delete them. + KEYCLOAK_CLIENT_SECRET: ${{ secrets.KEYCLOAK_CLIENT_SECRET }} diff --git a/README.md b/README.md index a59a113..3dd9af2 100644 --- a/README.md +++ b/README.md @@ -2,6 +2,7 @@ [![deploy](https://img.shields.io/github/actions/workflow/status/CivicDataLab/DataSpaceKeycloakTheme/deploy-keycloak-staging.yml?branch=main&label=deploy&logo=githubactions&logoColor=white)](https://github.com/CivicDataLab/DataSpaceKeycloakTheme/actions/workflows/deploy-keycloak-staging.yml) [![ci](https://img.shields.io/github/actions/workflow/status/CivicDataLab/DataSpaceKeycloakTheme/ci.yaml?branch=main&label=ci&logo=githubactions&logoColor=white)](https://github.com/CivicDataLab/DataSpaceKeycloakTheme/actions/workflows/ci.yaml) +[![auth tests](https://img.shields.io/github/actions/workflow/status/CivicDataLab/DataSpaceKeycloakTheme/auth-tests.yml?branch=main&label=auth%20tests&logo=githubactions&logoColor=white)](https://github.com/CivicDataLab/DataSpaceKeycloakTheme/actions/workflows/auth-tests.yml) [![deploys to](https://img.shields.io/badge/deploys%20to-auth.civicdatalab.in-0A7D33)](https://auth.civicdatalab.in/realms/DataSpace) [![Keycloak](https://img.shields.io/badge/Keycloak-26.7.0-4D4D4D)](https://www.keycloak.org/) [![Keycloakify](https://img.shields.io/badge/Keycloakify-v11-4D4D4D)](https://keycloakify.dev) @@ -51,6 +52,17 @@ PR ──► dev ───────────────────── login page · Google sign-in · privacy links · issuer ``` +### Checked between deploys, too + +`auth-tests.yml` runs the same checks on a schedule (every 6 hours) rather than +only after a deploy. `auth.civicdatalab.in` can break with no deploy involved - +a client setting changed in the admin console, a certificate expiring, Google +rotating an identity-provider credential, the box filling its disk. None of that +touches this repository, so without the schedule nothing would notice until the +next theme change. + +It deploys nothing and is read-only against the live server. + The tests run from [`CivicDataSpace-test`](https://github.com/CivicDataLab/CivicDataSpace-test) after every deploy, because the theme ships independently of the applications —