Run #7 harness failed: global-setup polled :5173/health (Vite proxy → :3000) and never got 200. The API connected to the DB and :3000/health was green during the separate 'Wait for API' step, but the bare-backgrounded node process was reaped at the step boundary and was dead by the time the e2e step ran (after the multi-minute browser install). Confirmed locally the API does not self-crash (alive + healthy for 75s in-shell). Install browsers first, then start the API and run Playwright in a SINGLE step so the API stays a child of the test shell for the whole run; capture the test exit code and kill the API after. No harness files touched.
275 lines
10 KiB
YAML
275 lines
10 KiB
YAML
name: CI
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
push:
|
|
branches: [main]
|
|
|
|
env:
|
|
MILESTONE: v1.1
|
|
|
|
jobs:
|
|
fast-checks:
|
|
runs-on: ubuntu-latest
|
|
if: github.event_name == 'pull_request'
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '22'
|
|
|
|
- name: Enable pnpm
|
|
run: corepack enable pnpm
|
|
|
|
# actions/cache@v4 is intentionally omitted — probe (D-PROBE-04) showed it
|
|
# times out on this runner (socket hang-up between runner container and job
|
|
# container cache server). pnpm install without cache takes ~30s; acceptable.
|
|
|
|
- name: Install dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
# lint is currently a no-op: no package defines a `lint` script and ESLint is
|
|
# not installed. `pnpm -r lint` prints ERR_PNPM_RECURSIVE_RUN_NO_SCRIPT but
|
|
# exits 0, so this step passes. Wiring lint is out of this phase's scope.
|
|
- name: Lint
|
|
run: pnpm lint
|
|
|
|
- name: Typecheck
|
|
run: pnpm typecheck
|
|
|
|
- name: PWA unit tests
|
|
run: pnpm --filter @familysync/pwa test
|
|
|
|
api:
|
|
runs-on: ubuntu-latest
|
|
if: github.event_name == 'pull_request'
|
|
# Runs in PARALLEL with fast-checks (D-03) — no needs: dependency.
|
|
services:
|
|
mariadb:
|
|
image: mariadb:11
|
|
env:
|
|
MARIADB_ROOT_PASSWORD: root
|
|
MARIADB_DATABASE: familysync
|
|
MARIADB_USER: familysync
|
|
MARIADB_PASSWORD: testpass
|
|
options: >-
|
|
--health-cmd="healthcheck.sh --connect --innodb_initialized"
|
|
--health-interval=10s
|
|
--health-timeout=5s
|
|
--health-retries=10
|
|
--health-start-period=30s
|
|
# Throwaway creds scoped to the ephemeral service container — never production secrets (T-08-03).
|
|
env:
|
|
DB_HOST: mariadb
|
|
DB_PORT: 3306
|
|
DB_USER: familysync
|
|
DB_PASSWORD: testpass
|
|
DB_NAME: familysync
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '22'
|
|
|
|
- name: Enable pnpm
|
|
run: corepack enable pnpm
|
|
|
|
# actions/cache@v4 intentionally omitted — same reasoning as fast-checks job (D-PROBE-04).
|
|
|
|
- name: Install dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
# Pitfall 11: service container healthy != MariaDB accepting connections.
|
|
# No mysql CLI in the runner image (D-PROBE-03); poll via the already-installed
|
|
# mysql2 driver using an inline Node script. 90s deadline covers cold-start InnoDB init.
|
|
- name: Wait for MariaDB to accept connections
|
|
# No mysql CLI in the runner image (D-PROBE-03). Poll via the mysql2 driver
|
|
# already installed in apps/pwa (devDependency). --input-type=commonjs forces
|
|
# CJS mode even though apps/pwa has "type":"module" in its package.json.
|
|
run: |
|
|
node --input-type=commonjs - <<'EOF'
|
|
const mysql = require('mysql2/promise');
|
|
const deadline = Date.now() + 90_000;
|
|
(async () => {
|
|
while (true) {
|
|
try {
|
|
const conn = await mysql.createConnection({
|
|
host: process.env.DB_HOST,
|
|
port: Number(process.env.DB_PORT ?? 3306),
|
|
user: process.env.DB_USER,
|
|
password: process.env.DB_PASSWORD,
|
|
database: process.env.DB_NAME,
|
|
});
|
|
await conn.query('SELECT 1');
|
|
await conn.end();
|
|
console.log('MariaDB ready');
|
|
process.exit(0);
|
|
} catch (err) {
|
|
if (Date.now() >= deadline) {
|
|
console.error('MariaDB did not become ready within 90s:', err.message);
|
|
process.exit(1);
|
|
}
|
|
await new Promise(r => setTimeout(r, 3000));
|
|
}
|
|
}
|
|
})();
|
|
EOF
|
|
working-directory: apps/pwa
|
|
|
|
# Apply schema migrations. Uses drizzle-kit migrate (applies committed SQL files).
|
|
# Never use drizzle push — unsafe on MariaDB (emits destructive TRUNCATE diff, T-08-04).
|
|
- name: Run DB migrations
|
|
run: pnpm --filter @familysync/api db:migrate
|
|
|
|
# Full DB-backed API test suite (all tests in apps/api/tests/ require a real MariaDB).
|
|
- name: Run API tests
|
|
run: pnpm --filter @familysync/api test
|
|
|
|
harness:
|
|
runs-on: ubuntu-latest
|
|
if: github.event_name == 'pull_request'
|
|
# Runs in PARALLEL with fast-checks + api (D-03) — no needs: dependency.
|
|
services:
|
|
mariadb:
|
|
image: mariadb:11
|
|
env:
|
|
MARIADB_ROOT_PASSWORD: root
|
|
MARIADB_DATABASE: familysync
|
|
MARIADB_USER: familysync
|
|
MARIADB_PASSWORD: testpass
|
|
options: >-
|
|
--health-cmd="healthcheck.sh --connect --innodb_initialized"
|
|
--health-interval=10s
|
|
--health-timeout=5s
|
|
--health-retries=10
|
|
--health-start-period=30s
|
|
# Throwaway creds scoped to the ephemeral service container — never production secrets (T-08-06).
|
|
env:
|
|
DB_HOST: mariadb
|
|
DB_PORT: 3306
|
|
DB_USER: familysync
|
|
DB_PASSWORD: testpass
|
|
DB_NAME: familysync
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '22'
|
|
|
|
- name: Enable pnpm
|
|
run: corepack enable pnpm
|
|
|
|
# actions/cache@v4 intentionally omitted — same reasoning as fast-checks job (D-PROBE-04).
|
|
|
|
- name: Install dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
# Pitfall 11: service container healthy != MariaDB accepting connections.
|
|
# No mysql CLI in the runner image (D-PROBE-03); poll via the mysql2 driver
|
|
# already installed in apps/pwa (devDependency). --input-type=commonjs forces
|
|
# CJS mode even though apps/pwa has "type":"module" in its package.json.
|
|
- name: Wait for MariaDB to accept connections
|
|
run: |
|
|
node --input-type=commonjs - <<'EOF'
|
|
const mysql = require('mysql2/promise');
|
|
const deadline = Date.now() + 90_000;
|
|
(async () => {
|
|
while (true) {
|
|
try {
|
|
const conn = await mysql.createConnection({
|
|
host: process.env.DB_HOST,
|
|
port: Number(process.env.DB_PORT ?? 3306),
|
|
user: process.env.DB_USER,
|
|
password: process.env.DB_PASSWORD,
|
|
database: process.env.DB_NAME,
|
|
});
|
|
await conn.query('SELECT 1');
|
|
await conn.end();
|
|
console.log('MariaDB ready');
|
|
process.exit(0);
|
|
} catch (err) {
|
|
if (Date.now() >= deadline) {
|
|
console.error('MariaDB did not become ready within 90s:', err.message);
|
|
process.exit(1);
|
|
}
|
|
await new Promise(r => setTimeout(r, 3000));
|
|
}
|
|
}
|
|
})();
|
|
EOF
|
|
working-directory: apps/pwa
|
|
|
|
# Apply schema migrations. Uses drizzle-kit migrate (applies committed SQL files).
|
|
# Never use drizzle push — unsafe on MariaDB (emits destructive TRUNCATE diff, T-08-07).
|
|
- name: Run DB migrations
|
|
run: pnpm --filter @familysync/api db:migrate
|
|
|
|
# Build the API before starting it — dist/ is gitignored and does not exist in CI (Pitfall 4).
|
|
- name: Build API
|
|
run: pnpm --filter @familysync/api build
|
|
|
|
# Install Playwright browsers with system deps BEFORE starting the API, so the long
|
|
# browser download does not run during the API's lifetime.
|
|
# Must run from apps/pwa/ where @playwright/test is installed (D-PROBE-05 confirmed exit 0).
|
|
# Do NOT cache browser binaries — Playwright explicitly recommends against it in CI.
|
|
- name: Install Playwright browsers
|
|
run: npx playwright install --with-deps webkit chromium
|
|
working-directory: apps/pwa
|
|
|
|
# Start the API AND run the harness in ONE step. A bare `node &` started in an EARLIER
|
|
# step is reaped at the step boundary: CI run #7 proved :3000 was healthy during a
|
|
# separate "wait" step but dead by the time global-setup polled :5173/health → :3000
|
|
# (after the multi-minute browser install). Keeping the API a child of THIS step's shell
|
|
# guarantees it stays alive for the entire Playwright run.
|
|
# DEV_AUTH_BYPASS=true + NODE_ENV=development are set both inline and in env: — global-setup.ts
|
|
# refuses NODE_ENV=production and the API devBypass.ts checks development. DB_* come from env:.
|
|
# CI=true makes Playwright start Vite :5173 itself (reuseExistingServer=false), use
|
|
# retries:2/workers:1, and apply reporter:'github' — which --reporter=list,html overrides
|
|
# because Gitea does not render github annotations (Pitfall 5 / D-06). Both projects run.
|
|
- name: Run harness (start API + Playwright iphone + pixel)
|
|
env:
|
|
CI: 'true'
|
|
PLAYWRIGHT_BASE_URL: http://localhost:5173
|
|
DEV_AUTH_BYPASS: 'true'
|
|
NODE_ENV: development
|
|
DB_HOST: mariadb
|
|
DB_PORT: 3306
|
|
DB_USER: familysync
|
|
DB_PASSWORD: testpass
|
|
DB_NAME: familysync
|
|
run: |
|
|
NODE_ENV=development DEV_AUTH_BYPASS=true node apps/api/dist/index.js &
|
|
API_PID=$!
|
|
echo "API PID: $API_PID"
|
|
|
|
# Wait for the API :3000/health before launching Playwright (D-02 / T-08-08).
|
|
deadline=$((SECONDS + 60))
|
|
until curl -sf http://localhost:3000/health > /dev/null 2>&1; do
|
|
if ! kill -0 "$API_PID" 2>/dev/null; then echo "API process exited before becoming ready"; exit 1; fi
|
|
if [ $SECONDS -ge $deadline ]; then echo "API did not become ready within 60s"; kill "$API_PID" 2>/dev/null || true; exit 1; fi
|
|
sleep 2
|
|
done
|
|
echo "API ready at :3000"
|
|
|
|
# Run the Phase 7 harness across both profiles; preserve its exit code, always kill the API.
|
|
set +e
|
|
pnpm test:e2e -- --reporter=list,html
|
|
rc=$?
|
|
kill "$API_PID" 2>/dev/null || true
|
|
exit $rc
|
|
|
|
# Upload traces/screenshots/videos on failure for debugging (D-06).
|
|
# MUST use ChristopherHX/gitea-upload-artifact@v4 — the standard upload-artifact action
|
|
# detects Gitea as GHES and aborts (Pitfall 6 / D-PROBE-06).
|
|
- name: Upload Playwright test artifacts
|
|
if: failure()
|
|
uses: https://github.com/ChristopherHX/gitea-upload-artifact@v4
|
|
with:
|
|
name: playwright-traces-${{ github.run_id }}
|
|
path: apps/pwa/test-results/
|
|
retention-days: 14
|