init complex runners #15
Workflow file for this run
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
--- | ||
# desc: build container images, perform static tests then push | ||
# this workflow will only use current as tag container tag reference, dedicated workflow exists for releasing versionned image | ||
name: build-images | ||
on: | ||
push: | ||
pull_request_target: | ||
jobs: | ||
lint: | ||
name: pre-commit | ||
runs-on: ubuntu-latest | ||
steps: | ||
- uses: actions/checkout@v3 | ||
- uses: actions/setup-python@v3 | ||
- uses: pre-commit/[email protected] | ||
build-image: | ||
runs-on: ubuntu-latest | ||
if: ${{ github.event_name == 'push' }} | ||
outputs: | ||
full_image_name: ${{ steps.compute-image-name-step.outputs.full_image_name }} | ||
# TODO: later, we should be able to build multiple versions of keycloak | ||
# strategy: | ||
# matrix: | ||
# keycloak_version: [keycloak-22, keycloak-23] | ||
steps: | ||
- name: Checkout | ||
uses: actions/checkout@v4 | ||
- name: Install if required common software tooling | ||
uses: camunda/infra-global-github-actions/common-tooling@main | ||
with: | ||
java-enabled: false | ||
yarn-enabled: false | ||
- name: Build image using Camunda docker build | ||
id: build-image-step | ||
uses: camunda/infra-global-github-actions/build-docker-image@feature/container-build-multiarch | ||
with: | ||
registry_host: ${{ vars.CONTAINER_REGISTRY }} | ||
registry_username: ${{ vars.DOCKERHUB_USERNAME }} | ||
registry_password: ${{ secrets.DOCKERHUB_TOKEN }} | ||
force_push: true | ||
image_name: ${{ vars.CONTAINER_IMAGE_NAME }} | ||
build_context: . | ||
build_platforms: linux/amd64,linux/arm64 | ||
- name: Compute target built image fully qualified name from metadata | ||
id: compute-image-name-step | ||
run: | | ||
image_metadata='${{ steps.build-image-step.outputs.image_metadata }}' | ||
image_name=$(echo "${image_metadata}" | tr -d '\n' | jq -r '."image.name"') | ||
digest=$(echo "${image_metadata}" | tr -d '\n' | jq -r '."containerimage.digest"') | ||
full_image_name="${image_name}@${digest}" | ||
echo "full_image_name=${full_image_name}" >> $GITHUB_OUTPUT | ||
echo "$full_image_name" | ||
test-base-image: | ||
runs-on: ubuntu-latest | ||
needs: | ||
- build-image | ||
steps: | ||
- name: Checkout | ||
uses: actions/checkout@v4 | ||
- name: Install if required common software tooling | ||
uses: camunda/infra-global-github-actions/common-tooling@main | ||
with: | ||
java-enabled: false | ||
yarn-enabled: false | ||
- name: Login to the registry | ||
uses: docker/login-action@v3 | ||
with: | ||
registry: ${{ vars.CONTAINER_REGISTRY }} | ||
username: ${{ vars.DOCKERHUB_USERNAME }} | ||
password: ${{ secrets.DOCKERHUB_TOKEN }} | ||
- name: KeyCloak Show-Config | ||
run: | | ||
docker run ${{ needs.build-image.outputs.full_image_name }} show-config >> docker.log | ||
echo "config=$(cat docker.log | tr '\n' ' ')" >> "$GITHUB_ENV" | ||
- name: Assert Config | ||
env: | ||
CONFIG: ${{ env.config }} | ||
run: python3 ./.github/scripts/build-check/main.py | ||
test-postgres-integ: | ||
strategy: | ||
matrix: | ||
runner_desc: | ||
- {runner: ubuntu-22.04, postgres_replicas: 1, postgres_database: keycloak, postgres_username: keycloak, postgres_password: password, keycloak_db_driver: software.amazon.jdbc.Driver, keycloak_db_host: "postgres", keycloak_db_port: "5432" } | ||
- {runner: aws-core-2-default, postgres_replicas: 0, postgres_database: keycloak, postgres_username: keycloak, postgres_password: password, keycloak_db_driver: software.amazon.jdbc.Driver, keycloak_db_host: "camunda-ci-eks-aurora-postgresql-${{ matrix.postgres_version }}.cluster-clnwzia8ptad.eu-central-1.rds.amazonaws.com", keycloak_db_port: "5432" } | ||
Check failure on line 98 in .github/workflows/build-images.yml GitHub Actions / build-imagesInvalid workflow file
|
||
- {runner: aws-arm-core-2-default, postgres_replicas: 0, postgres_database: keycloak, postgres_username: keycloak, postgres_password: password, keycloak_db_driver: software.amazon.jdbc.Driver, keycloak_db_host: "camunda-ci-eks-aurora-postgresql-${{ matrix.postgres_version }}.cluster-clnwzia8ptad.eu-central-1.rds.amazonaws.com", keycloak_db_port: "5432" } | ||
- {runner: gcp-core-2-default, postgres_replicas: 0, postgres_database: keycloak, postgres_username: keycloak, postgres_password: password, keycloak_db_driver: software.amazon.jdbc.Driver, keycloak_db_host: "${{ matrix.postgres_version }}", keycloak_db_port: "5432" } | ||
postgres_version: [15] # reference: https://www.keycloak.org/server/db | ||
runs-on: ${{ matrix.runner_desc.runner }} | ||
needs: | ||
- build-image | ||
steps: | ||
- name: Checkout | ||
uses: actions/checkout@v4 | ||
- name: Install if required common software tooling | ||
uses: camunda/infra-global-github-actions/common-tooling@main | ||
with: | ||
java-enabled: false | ||
yarn-enabled: false | ||
- name: Declare test recipe variables | ||
run: | | ||
test_db_name="db-${{ matrix.runner_desc.runner }}-${{ github.sha }}" | ||
echo "test_db_name=${test_db_name}" >> $GITHUB_ENV | ||
echo "test_db_name=$test_db_name" | ||
test_db_url="jdbc:aws-wrapper:postgresql://${{ matrix.runner_desc.keycloak_db_host }}:${{ matrix.runner_desc.keycloak_db_port }}/${test_db_name}" | ||
echo "test_db_url=${test_db_url}" >> $GITHUB_ENV | ||
echo "test_db_url=$test_db_url" | ||
- name: Login to the registry | ||
uses: docker/login-action@v3 | ||
with: | ||
registry: ${{ vars.CONTAINER_REGISTRY }} | ||
username: ${{ vars.DOCKERHUB_USERNAME }} | ||
password: ${{ secrets.DOCKERHUB_TOKEN }} | ||
- name: Tear up Aurora PG (aws only) | ||
if: startsWith(matrix.runner_desc.runner, 'aws') | ||
run: ./.helpers/actions/create-aurora-database.sh | ||
env: | ||
PGDATABASE: "${{ env.test_db_name }}" | ||
PGHOST: ${{ matrix.runner_desc.keycloak_db_host }} | ||
PGPORT: ${{ matrix.runner_desc.keycloak_db_port }} | ||
PGPASSWORD: ${{ steps.secrets.outputs.AURORA_POSTGRESQL_PASSWORD }} | ||
PGUSER: ${{ steps.secrets.outputs.AURORA_POSTGRESQL_USERNAME }} | ||
PGUSER_IRSA: web-modeler-irsa # TODO: TDB | ||
# TODO: database name and generation should be unique and destroyed at the end | ||
- name: Start Test Environment | ||
uses: ./.github/actions/compose | ||
with: | ||
compose_file: ${{ github.workspace }}/docker-compose.yml | ||
project_name: keycloak | ||
env: | ||
POSTGRES_DB: "${{ matrix.runner_desc.postgres_database }}" | ||
POSTGRES_USER: "${{ matrix.runner_desc.postgres_username }}" | ||
POSTGRES_PASSWORD: "${{ matrix.runner_desc.postgres_password }}" | ||
KC_DB_USERNAME: "${{ matrix.runner_desc.postgres_username }}" | ||
KC_DB_PASSWORD: "${{ matrix.runner_desc.postgres_password }}" | ||
KC_DB_DRIVER: "${{ matrix.runner_desc.keycloak_db_driver }}" | ||
KC_DB_URL: "${{ matrix.runner_desc.keycloak_db_url }}" | ||
COMPOSE_POSTGRES_IMAGE: "postgres:${{ matrix.postgres_version }}" | ||
COMPOSE_POSTGRES_DEPLOY_REPLICAS: "${{ matrix.runner_desc.postgres_replicas }}" | ||
COMPOSE_KEYCLOAK_IMAGE: ${{ needs.build-image.outputs.full_image_name }} | ||
- name: Install dependencies | ||
run: | | ||
python -m pip install --upgrade pip | ||
pip install -r ./.github/scripts/integration/requirements.txt | ||
- name: Test Environment | ||
run: python3 ./.github/scripts/integration/main.py | ||
- name: Tear down Aurora PG (aws only) | ||
if: startsWith(matrix.runner_desc.runner, 'aws') || always() | ||
run: ./.helpers/actions/delete-aurora-database.sh | ||
env: | ||
PGDATABASE: "${{ env.test_db_name }}" | ||
PGHOST: ${{ matrix.runner_desc.keycloak_db_host }} | ||
PGPORT: ${{ matrix.runner_desc.keycloak_db_port }} | ||
PGPASSWORD: ${{ steps.secrets.outputs.AURORA_POSTGRESQL_PASSWORD }} | ||
PGUSER: ${{ steps.secrets.outputs.AURORA_POSTGRESQL_USERNAME }} | ||
# TODO: add tests (static framework tbd) then push | ||
# TODO : cleanup images after test | ||
# TODO: implement | ||
# publish-image: | ||
# release: |