fix(nginx): SP の属性の受け付け判定を、real_ip で書き換える前の接続元で行う #864
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # UIテスト。 | |
| # | |
| # 本体イメージ(web/worker) と Elasticsearch、nginx(Shibboleth 込み)は | |
| # ci-images.yml が用意したビルド済みイメージを pull して使う。タグは依存関係 | |
| # ファイルのハッシュなので、依存を触らない PR ではビルドが 0 回になる。 | |
| # ソースの変更は . を /code に bind mount しているので反映される。 | |
| # | |
| # UIテストは動いている WEKO 一式が要るので、install.sh によるインスタンス | |
| # 初期化 (populate-instance / デモSQL / assets build / collect) はそのまま行う。 | |
| # WEKO_SKIP_BUILD=1 でイメージのビルド部分だけを飛ばしている。 | |
| name: UI Tests | |
| on: | |
| push: | |
| branches: [ '**' ] | |
| pull_request: | |
| branches: [ '**' ] | |
| workflow_dispatch: | |
| inputs: | |
| force_rebuild: | |
| description: CI イメージを作り直す(依存を変えずに差し替えたいとき) | |
| type: boolean | |
| default: false | |
| jobs: | |
| images: | |
| uses: ./.github/workflows/ci-images.yml | |
| permissions: | |
| contents: read | |
| packages: write | |
| with: | |
| force_rebuild: ${{ inputs.force_rebuild || false }} | |
| ui-tests: | |
| needs: images | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 60 | |
| permissions: | |
| contents: read | |
| packages: read | |
| env: | |
| COMPOSE_FILE: docker-compose2.yml:docker-compose.ci.yml | |
| WEKO_IMAGE: ${{ needs.images.outputs.web }} | |
| WEKO_ES_IMAGE: ${{ needs.images.outputs.es }} | |
| WEKO_NGINX_IMAGE: ${{ needs.images.outputs.nginx }} | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Set up Python | |
| uses: actions/setup-python@v4 | |
| with: | |
| python-version: '3.9' | |
| - name: Install system dependencies | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y fonts-noto-cjk fonts-noto-color-emoji | |
| - name: Log in to GHCR | |
| continue-on-error: true | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Pull prebuilt images | |
| id: pull | |
| continue-on-error: true | |
| run: | | |
| docker pull -q "$WEKO_IMAGE" | |
| docker pull -q "$WEKO_ES_IMAGE" | |
| docker pull -q "$WEKO_NGINX_IMAGE" | |
| # fork PR など pull できない場合のみ、ビルドキャッシュからローカルビルドする。 | |
| - name: Set up Docker Buildx | |
| if: steps.pull.outcome == 'failure' | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Build WEKO image (fallback) | |
| if: steps.pull.outcome == 'failure' | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: . | |
| file: Dockerfile | |
| tags: ${{ env.WEKO_IMAGE }} | |
| load: true | |
| cache-from: type=gha,scope=weko-web | |
| - name: Build Elasticsearch image (fallback) | |
| if: steps.pull.outcome == 'failure' | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: . | |
| file: elasticsearch/Dockerfile | |
| tags: ${{ env.WEKO_ES_IMAGE }} | |
| load: true | |
| cache-from: type=gha,scope=weko-es | |
| - name: Build nginx image (fallback) | |
| if: steps.pull.outcome == 'failure' | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: ./nginx | |
| file: ./nginx/Dockerfile | |
| tags: ${{ env.WEKO_NGINX_IMAGE }} | |
| load: true | |
| cache-from: type=gha,scope=weko-nginx | |
| # イメージは用意済みなので、install.sh はインスタンス初期化だけ行う。 | |
| # inbox だけは移動するブランチを clone するため、ここで compose がビルドする。 | |
| - name: Start WEKO containers | |
| run: | | |
| chmod +x install.sh | |
| ./install.sh | |
| env: | |
| WEKO_SKIP_BUILD: 1 | |
| DOCKER_BUILDKIT: 1 | |
| COMPOSE_DOCKER_CLI_BUILD: 1 | |
| - name: Wait for services to be ready | |
| run: | | |
| echo "Waiting for WEKO services to start..." | |
| start_time=$(date +%s) | |
| max_attempts=60 | |
| attempt=0 | |
| while [ $attempt -lt $max_attempts ]; do | |
| attempt=$((attempt + 1)) | |
| current_time=$(date +%s) | |
| elapsed=$((current_time - start_time)) | |
| echo "Attempt $attempt/$max_attempts (${elapsed}s elapsed): Checking WEKO availability..." | |
| # Check if we can connect to the service | |
| if curl -f -s --insecure https://localhost/ > /dev/null 2>&1; then | |
| echo "✓ WEKO is ready! (took ${elapsed}s)" | |
| exit 0 | |
| else | |
| # Get HTTP response code for debugging | |
| http_code=$(curl -s -o /dev/null -w "%{http_code}" --insecure https://localhost/ 2>/dev/null || echo "connection_failed") | |
| echo " ✗ HTTP response: $http_code" | |
| fi | |
| if [ $attempt -lt $max_attempts ]; then | |
| echo " → Retrying in 5 seconds..." | |
| sleep 5 | |
| fi | |
| done | |
| echo "" | |
| echo "❌ WEKO failed to start within 300 seconds" | |
| echo "Final HTTP response: $(curl -s -o /dev/null -w "%{http_code}" --insecure https://localhost/ 2>/dev/null || echo "connection_failed")" | |
| echo "" | |
| echo "Container status:" | |
| docker compose ps | |
| exit 1 | |
| - name: Install UI test dependencies | |
| run: | | |
| cd ui-tests | |
| pip install -r requirements.txt | |
| playwright install chromium | |
| - name: Run UI tests | |
| run: | | |
| cd ui-tests | |
| mkdir -p reports test-results/videos | |
| pytest --browser chromium --html=reports/report.html --self-contained-html | |
| env: | |
| WEKO_BASE_URL: https://localhost | |
| WEKO_TEST_EMAIL: wekosoftware@nii.ac.jp | |
| WEKO_TEST_PASSWORD: uspass123 | |
| - name: Upload test results | |
| uses: actions/upload-artifact@v4 | |
| if: always() | |
| with: | |
| name: ui-test-results | |
| path: | | |
| ui-tests/reports/ | |
| ui-tests/test-results/ | |
| retention-days: 30 | |
| - name: Upload container logs | |
| uses: actions/upload-artifact@v4 | |
| if: failure() | |
| with: | |
| name: container-logs | |
| path: | | |
| docker-compose2.yml | |
| retention-days: 7 | |
| - name: Get container logs on failure | |
| if: failure() | |
| run: | | |
| echo "=== Docker Compose Services ===" | |
| docker compose ps | |
| echo "=== Web Container Logs ===" | |
| docker compose logs web | |
| echo "=== Worker Container Logs ===" | |
| docker compose logs worker | |
| echo "=== PostgreSQL Container Logs ===" | |
| docker compose logs postgresql | |
| echo "=== Elasticsearch Container Logs ===" | |
| docker compose logs elasticsearch | |
| - name: Cleanup containers | |
| if: always() | |
| run: | | |
| docker compose down -v | |
| docker system prune -f |