Skip to content

init complex runners #15

init complex runners

init complex runners #15

Workflow file for this run

---
# desc: build container images, perform static tests then push
# this workflow will only use current as tag container tag reference, dedicated workflow exists for releasing versionned image
name: build-images
on:
push:
pull_request_target:
jobs:
lint:
name: pre-commit
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/setup-python@v3
- uses: pre-commit/[email protected]
build-image:
runs-on: ubuntu-latest
if: ${{ github.event_name == 'push' }}
outputs:
full_image_name: ${{ steps.compute-image-name-step.outputs.full_image_name }}
# TODO: later, we should be able to build multiple versions of keycloak
# strategy:
# matrix:
# keycloak_version: [keycloak-22, keycloak-23]
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install if required common software tooling
uses: camunda/infra-global-github-actions/common-tooling@main
with:
java-enabled: false
yarn-enabled: false
- name: Build image using Camunda docker build
id: build-image-step
uses: camunda/infra-global-github-actions/build-docker-image@feature/container-build-multiarch
with:
registry_host: ${{ vars.CONTAINER_REGISTRY }}
registry_username: ${{ vars.DOCKERHUB_USERNAME }}
registry_password: ${{ secrets.DOCKERHUB_TOKEN }}
force_push: true
image_name: ${{ vars.CONTAINER_IMAGE_NAME }}
build_context: .
build_platforms: linux/amd64,linux/arm64
- name: Compute target built image fully qualified name from metadata
id: compute-image-name-step
run: |
image_metadata='${{ steps.build-image-step.outputs.image_metadata }}'
image_name=$(echo "${image_metadata}" | tr -d '\n' | jq -r '."image.name"')
digest=$(echo "${image_metadata}" | tr -d '\n' | jq -r '."containerimage.digest"')
full_image_name="${image_name}@${digest}"
echo "full_image_name=${full_image_name}" >> $GITHUB_OUTPUT
echo "$full_image_name"
test-base-image:
runs-on: ubuntu-latest
needs:
- build-image
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install if required common software tooling
uses: camunda/infra-global-github-actions/common-tooling@main
with:
java-enabled: false
yarn-enabled: false
- name: Login to the registry
uses: docker/login-action@v3
with:
registry: ${{ vars.CONTAINER_REGISTRY }}
username: ${{ vars.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: KeyCloak Show-Config
run: |
docker run ${{ needs.build-image.outputs.full_image_name }} show-config >> docker.log
echo "config=$(cat docker.log | tr '\n' ' ')" >> "$GITHUB_ENV"
- name: Assert Config
env:
CONFIG: ${{ env.config }}
run: python3 ./.github/scripts/build-check/main.py
test-postgres-integ:
strategy:
matrix:
runner_desc:
- {runner: ubuntu-22.04, postgres_replicas: 1, postgres_database: keycloak, postgres_username: keycloak, postgres_password: password, keycloak_db_driver: software.amazon.jdbc.Driver, keycloak_db_host: "postgres", keycloak_db_port: "5432" }
- {runner: aws-core-2-default, postgres_replicas: 0, postgres_database: keycloak, postgres_username: keycloak, postgres_password: password, keycloak_db_driver: software.amazon.jdbc.Driver, keycloak_db_host: "camunda-ci-eks-aurora-postgresql-${{ matrix.postgres_version }}.cluster-clnwzia8ptad.eu-central-1.rds.amazonaws.com", keycloak_db_port: "5432" }

Check failure on line 98 in .github/workflows/build-images.yml

View workflow run for this annotation

GitHub Actions / build-images

Invalid workflow file

The workflow is not valid. .github/workflows/build-images.yml (Line: 98, Col: 218): Unrecognized named-value: 'matrix'. Located at position 1 within expression: matrix.postgres_version .github/workflows/build-images.yml (Line: 99, Col: 222): Unrecognized named-value: 'matrix'. Located at position 1 within expression: matrix.postgres_version
- {runner: aws-arm-core-2-default, postgres_replicas: 0, postgres_database: keycloak, postgres_username: keycloak, postgres_password: password, keycloak_db_driver: software.amazon.jdbc.Driver, keycloak_db_host: "camunda-ci-eks-aurora-postgresql-${{ matrix.postgres_version }}.cluster-clnwzia8ptad.eu-central-1.rds.amazonaws.com", keycloak_db_port: "5432" }
- {runner: gcp-core-2-default, postgres_replicas: 0, postgres_database: keycloak, postgres_username: keycloak, postgres_password: password, keycloak_db_driver: software.amazon.jdbc.Driver, keycloak_db_host: "${{ matrix.postgres_version }}", keycloak_db_port: "5432" }
postgres_version: [15] # reference: https://www.keycloak.org/server/db
runs-on: ${{ matrix.runner_desc.runner }}
needs:
- build-image
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install if required common software tooling
uses: camunda/infra-global-github-actions/common-tooling@main
with:
java-enabled: false
yarn-enabled: false
- name: Declare test recipe variables
run: |
test_db_name="db-${{ matrix.runner_desc.runner }}-${{ github.sha }}"
echo "test_db_name=${test_db_name}" >> $GITHUB_ENV
echo "test_db_name=$test_db_name"
test_db_url="jdbc:aws-wrapper:postgresql://${{ matrix.runner_desc.keycloak_db_host }}:${{ matrix.runner_desc.keycloak_db_port }}/${test_db_name}"
echo "test_db_url=${test_db_url}" >> $GITHUB_ENV
echo "test_db_url=$test_db_url"
- name: Login to the registry
uses: docker/login-action@v3
with:
registry: ${{ vars.CONTAINER_REGISTRY }}
username: ${{ vars.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Tear up Aurora PG (aws only)
if: startsWith(matrix.runner_desc.runner, 'aws')
run: ./.helpers/actions/create-aurora-database.sh
env:
PGDATABASE: "${{ env.test_db_name }}"
PGHOST: ${{ matrix.runner_desc.keycloak_db_host }}
PGPORT: ${{ matrix.runner_desc.keycloak_db_port }}
PGPASSWORD: ${{ steps.secrets.outputs.AURORA_POSTGRESQL_PASSWORD }}
PGUSER: ${{ steps.secrets.outputs.AURORA_POSTGRESQL_USERNAME }}
PGUSER_IRSA: web-modeler-irsa # TODO: TDB
# TODO: database name and generation should be unique and destroyed at the end
- name: Start Test Environment
uses: ./.github/actions/compose
with:
compose_file: ${{ github.workspace }}/docker-compose.yml
project_name: keycloak
env:
POSTGRES_DB: "${{ matrix.runner_desc.postgres_database }}"
POSTGRES_USER: "${{ matrix.runner_desc.postgres_username }}"
POSTGRES_PASSWORD: "${{ matrix.runner_desc.postgres_password }}"
KC_DB_USERNAME: "${{ matrix.runner_desc.postgres_username }}"
KC_DB_PASSWORD: "${{ matrix.runner_desc.postgres_password }}"
KC_DB_DRIVER: "${{ matrix.runner_desc.keycloak_db_driver }}"
KC_DB_URL: "${{ matrix.runner_desc.keycloak_db_url }}"
COMPOSE_POSTGRES_IMAGE: "postgres:${{ matrix.postgres_version }}"
COMPOSE_POSTGRES_DEPLOY_REPLICAS: "${{ matrix.runner_desc.postgres_replicas }}"
COMPOSE_KEYCLOAK_IMAGE: ${{ needs.build-image.outputs.full_image_name }}
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -r ./.github/scripts/integration/requirements.txt
- name: Test Environment
run: python3 ./.github/scripts/integration/main.py
- name: Tear down Aurora PG (aws only)
if: startsWith(matrix.runner_desc.runner, 'aws') || always()
run: ./.helpers/actions/delete-aurora-database.sh
env:
PGDATABASE: "${{ env.test_db_name }}"
PGHOST: ${{ matrix.runner_desc.keycloak_db_host }}
PGPORT: ${{ matrix.runner_desc.keycloak_db_port }}
PGPASSWORD: ${{ steps.secrets.outputs.AURORA_POSTGRESQL_PASSWORD }}
PGUSER: ${{ steps.secrets.outputs.AURORA_POSTGRESQL_USERNAME }}
# TODO: add tests (static framework tbd) then push
# TODO : cleanup images after test
# TODO: implement
# publish-image:
# release: