Files
ObsiGate/.gitea/workflows/ci.yml
T
bruno 14b8032635
CI / security (push) Successful in 1m37s
CI / lint (push) Successful in 2m18s
CI / test (push) Successful in 4m8s
CI / build (push) Successful in 1m38s
CI / e2e (push) Successful in 14m28s
fix: CI lint — config-ai-keys.test.mjs rejoint l'étape JSDOM (complément BUG-082)
2026-09-27 09:44:18 -04:00

265 lines
10 KiB
YAML

# ObsiGate CI/CD Pipeline
# Runs on every push and pull request to main
name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
# ── Lint ──────────────────────────────────────────────────────────
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Python
uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Install dependencies
run: |
pip install ruff mypy
pip install -r backend/requirements.txt
- name: Ruff (linter)
run: ruff check backend/
- name: Mypy (type checker)
run: mypy backend/ --ignore-missing-imports
- name: Frontend validation
run: node tests/frontend/validate-imports.mjs
- name: Frontend unit tests
run: |
node tests/frontend/unit.test.mjs
node tests/frontend/image-viewer.test.mjs
node tests/frontend/pdf-viewer.test.mjs
node tests/frontend/forge-completion.test.mjs
node tests/frontend/config-mobile.test.mjs
node tests/frontend/settings-order-avatar.test.mjs
node tests/frontend/mobile-toolbar.test.mjs
node tests/frontend/pretty.test.mjs
node tests/frontend/media-viewer.test.mjs
node tests/frontend/mfa-settings.test.mjs
- name: Frontend JSDOM tests (PaneManager + Excalidraw + Plugins + AI + SW + Collab + Mobile + Semantic + Desktop + Inline edition + Upload)
run: |
cd tests/frontend
if [ -d node_modules ]; then
node pane-manager.test.mjs
node excalidraw-viewer.test.mjs
node plugins.test.mjs
node ai.test.mjs
node ai-sidebar.test.mjs
node sidebar-filters.test.mjs
node sw.test.mjs
node collab.test.mjs
node mobile-editor.test.mjs
node semantic-search.test.mjs
node desktop.test.mjs
node toolbar-order.test.mjs
node editor-inline.test.mjs
node ai-quick-actions.test.mjs
node upload.test.mjs
node config-ai-keys.test.mjs
else
echo "tests/frontend/node_modules missing - installing jsdom"
npm install --no-audit --no-fund --silent
node pane-manager.test.mjs
node excalidraw-viewer.test.mjs
node plugins.test.mjs
node ai.test.mjs
node ai-sidebar.test.mjs
node sidebar-filters.test.mjs
node sw.test.mjs
node collab.test.mjs
node mobile-editor.test.mjs
node semantic-search.test.mjs
node desktop.test.mjs
node toolbar-order.test.mjs
node editor-inline.test.mjs
node ai-quick-actions.test.mjs
node upload.test.mjs
node config-ai-keys.test.mjs
fi
# ── Tests ─────────────────────────────────────────────────────────
test:
needs: lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Python
uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Install dependencies
run: |
pip install pytest pytest-cov pytest-asyncio httpx
pip install -r backend/requirements.txt
pip install -r backend/requirements-test.txt || echo "test deps install failed (non-blocking — PDF tests will skip)"
- name: Run tests
run: pytest tests/ --cov=backend --cov-report=xml --cov-report=term -q
- name: Upload coverage artifact
uses: actions/upload-artifact@v3
with:
name: coverage-report
path: coverage.xml
retention-days: 30
# ── Security scan ─────────────────────────────────────────────────
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Python
uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Install dependencies
run: |
pip install bandit pip-audit
pip install -r backend/requirements.txt
- name: Bandit (SAST, bloquant — #87)
# B105 est exclu (aligné avec [tool.bandit] de pyproject.toml :
# faux positifs systématiques sur les noms de variables) ; les rares
# vrais positifs restants portent un `# nosec` justifié inline.
run: bandit -r backend/ --skip B101,B105,B110,B310
- name: Pip-audit (consultatif — #87)
# Reste non bloquant tant que les montées de version requises
# (starlette via fastapi, weasyprint) ne sont pas qualifiées :
# upgrade FastAPI = chantier de régression dédié, hors périmètre.
# NOTE runner Gitea Act (BUG-083) : aucun `#` dans le `run:`
# ci-dessous (tronqué au premier `#`, même entre guillemets, ce qui
# cassait la citation de l'echo) — la réf #87 ne vit qu'ici.
run: pip-audit || echo "pip-audit found vulnerabilities (non-blocking)"
# ── Docker build ──────────────────────────────────────────────────
build:
needs: test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Version livrée
# VERSION (racine du dépôt) est copié dans l'image par le Dockerfile :
# plus aucun numéro généré ni codé en dur dans le pipeline.
run: echo "Version livree = $(cat VERSION)"
- name: Configure DNS (workaround flaky 127.0.0.11 resolver)
# GitHub Actions runners occasionally fail to resolve auth.docker.io via
# the embedded Docker DNS (127.0.0.11:53 → "server misbehaving").
# Force the daemon to use public DNS as a fallback.
run: |
sudo mkdir -p /etc/docker
if ! grep -q "dns" /etc/docker/daemon.json 2>/dev/null; then
echo '{"dns": ["8.8.8.8", "1.1.1.1", "9.9.9.9"]}' | sudo tee /etc/docker/daemon.json
sudo systemctl restart docker || sudo service docker restart || true
sleep 3
fi
- name: Build Docker image (retry on transient DNS/network errors)
run: |
for attempt in 1 2 3; do
echo "=== docker build attempt $attempt/3 ==="
if docker build -t obsigate:ci . ; then
echo "✓ Docker build succeeded"
exit 0
fi
echo "✗ Build failed (attempt $attempt)"
if [ $attempt -lt 3 ]; then
sleep $((attempt * 10))
fi
done
echo "✗ Docker build failed after 3 attempts"
exit 1
- name: Verify image
run: docker images obsigate:ci
# ── E2E Tests (Playwright) ─────────────────────────────────────────
e2e:
needs: build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Install Playwright
run: |
npm ci
npx playwright install --with-deps chromium
- name: Npm audit (bloquant — #87, 0 dépendance prod hors Playwright)
run: npm audit --omit=dev
- name: Start ObsiGate
run: |
docker rm -f obsigate-e2e 2>/dev/null || true
docker create --name obsigate-e2e -p 2029:8080 \
-v $(pwd)/test_vault:/vaults/TestVault \
-v $(pwd)/test_dir:/vaults/TestDir \
-e VAULT_1_NAME=TestVault \
-e VAULT_1_PATH=/vaults/TestVault \
-e DIR_1_NAME=TestDir \
-e DIR_1_PATH=/vaults/TestDir \
-e OBSIGATE_AUTH_ENABLED=false \
-e OBSIGATE_ALLOW_INSECURE=true \
obsigate:ci
# Docker-in-docker : le bind mount $(pwd)/... pointe sur un chemin
# du job container, inexistant sur l'hôte → montage vide. Les -v
# créent quand même /vaults/* dans le container ; on y copie les
# fixtures avant le démarrage (l'indexeur scanne au démarrage).
docker cp test_vault/. obsigate-e2e:/vaults/TestVault
docker cp test_dir/. obsigate-e2e:/vaults/TestDir
docker start obsigate-e2e
# Le port publié est joignable via l'IP de la passerelle (localhost
# du job container ne voit pas le port publié sur l'hôte).
GW=$(ip route show default | awk '{print $3}' || echo 172.17.0.1)
echo "Gateway IP: $GW"
# Wait for health check
for i in $(seq 1 30); do
if curl -sf "http://$GW:2029/api/health"; then echo "Health OK"; break; fi
sleep 1
done
curl -sf "http://$GW:2029/api/health" >/dev/null || { echo "App not reachable at $GW:2029"; exit 1; }
# Les fixtures sont copiées via `docker cp` en root → rendre le vault
# inscriptible par l'utilisateur non-root de l'app (UID 1000), sinon
# toute création/édition de fichier renvoie 403 « Vault is read-only ».
docker exec -u 0 obsigate-e2e chmod -R a+rwX /vaults/TestVault /vaults/TestDir || true
- name: Run E2E tests
run: |
GW=$(ip route show default | awk '{print $3}' || echo 172.17.0.1)
echo "Using BASE_URL=http://$GW:2029"
BASE_URL="http://$GW:2029" npx playwright test --project=chromium-desktop --reporter=list
- name: Upload test results
if: always()
uses: actions/upload-artifact@v3
with:
name: playwright-report
path: playwright-report/
retention-days: 7
- name: Cleanup
if: always()
run: docker rm -f obsigate-e2e