Files
familysync/.gitea/workflows/runner-probe.yml
T
Lucas Berger 0b148b96f8
CI / fast-checks (pull_request) Successful in 48s
CI / api (pull_request) Successful in 57s
chore(08-01): probe to manual-only (workflow_dispatch)
Stops the throwaway probe re-running on every push and contending with
ci.yml on the single runner. Fork answers already captured in 08-01-SUMMARY.
2026-06-11 14:29:38 -04:00

229 lines
12 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
name: runner-probe
# Probe-only workflow — answers all runner unknowns before real CI is designed.
# Runs ONLY on the feature branch; never on main.
# All steps that may fail on this runner use continue-on-error: true or || true
# so the probe REPORTS findings instead of red-failing on an expected unknown.
# Do NOT reference any secret in this workflow (T-08-01).
#
# Checks performed: P-01 through P-11 + P-13
# P-12 (docker login) is deferred to Plan 04 (publish) — DO NOT add it here.
# Probe served its purpose (run #2 recorded the fork answers in 08-01-SUMMARY).
# Switched to manual-only so it no longer re-runs on every push and competes
# with ci.yml on the single runner. Throwaway — remove before merge to main.
on:
workflow_dispatch:
jobs:
probe:
name: runner-probe
# Runner advertises ubuntu-latest/ubuntu-24.04/ubuntu-22.04 (no 'self-hosted' label).
# Probe confirmed `runs-on: self-hosted` matched no runner and the job stayed queued.
runs-on: ubuntu-latest
# P-05: Service container — probe whether it spawns and on which hostname.
# Uses healthcheck.sh --connect --innodb_initialized.
# Note: healthcheck.sh is used because the binary from older clients was
# removed from mariadb:11 (Pitfall 11).
services:
mariadb:
image: mariadb:11
env:
MARIADB_ROOT_PASSWORD: root
MARIADB_DATABASE: familysync
MARIADB_USER: familysync
MARIADB_PASSWORD: testpass
options: >-
--health-cmd="healthcheck.sh --connect --innodb_initialized"
--health-interval=10s
--health-timeout=5s
--health-retries=10
--health-start-period=30s
steps:
# ─── P-07: actions/checkout ──────────────────────────────────────────────
# Must be first real step. Reaching subsequent steps proves it resolves.
- name: P-07 checkout (actions/checkout@v4)
uses: actions/checkout@v4
# ─── P-08: actions/setup-node ────────────────────────────────────────────
- name: P-08 setup-node (actions/setup-node@v4 — pin Node 22)
uses: actions/setup-node@v4
with:
node-version: '22'
# ─── P-01: Node.js version ───────────────────────────────────────────────
- name: P-01 Node.js version
run: |
echo "=== P-01: Node.js version ==="
node --version
echo "Expected: v22.x"
# ─── P-02: pnpm availability ─────────────────────────────────────────────
- name: P-02 pnpm availability
run: |
echo "=== P-02: pnpm availability ==="
pnpm --version 2>/dev/null || (
echo "pnpm not found — attempting corepack activation"
corepack enable pnpm
pnpm --version
)
echo "Expected: pnpm 11.x (from packageManager field in package.json)"
# ─── P-03: Runner mode — THE critical fork ───────────────────────────────
# Docker-executor mode: job runs inside a Docker container
# → services: works; DB_HOST=mariadb
# Host-executor mode: job runs directly on the Unraid host
# → services: not supported; must use docker run -d fallback
- name: P-03 runner mode detection (Docker vs host — critical fork)
run: |
echo "=== P-03: Runner mode (critical fork) ==="
echo "--- /proc/1/cgroup (first 5 lines) ---"
cat /proc/1/cgroup 2>/dev/null | head -5 || echo "(not readable)"
echo "--- hostname ---"
hostname
echo "--- /.dockerenv presence ---"
ls -la /.dockerenv 2>&1
echo "--- Conclusion ---"
if [ -f /.dockerenv ]; then
echo "RUNNER MODE: Docker-executor (job is running inside a Docker container)"
echo " → services: will work; MariaDB hostname = service label name (mariadb)"
echo " → DB_HOST=mariadb in downstream jobs"
else
echo "RUNNER MODE: host-executor (job is running directly on the host)"
echo " → services: NOT supported (nektos/act#2711)"
echo " → Downstream jobs must use: docker run -d mariadb:11 + explicit readiness loop"
echo " → DB_HOST=127.0.0.1 with -p 3306:3306 in docker run"
fi
# ─── P-04: Docker socket access ──────────────────────────────────────────
- name: P-04 Docker socket access
continue-on-error: true
run: |
echo "=== P-04: Docker socket access ==="
docker info 2>&1 | head -20
echo "--- docker ps (first few lines) ---"
docker ps 2>&1 | head
# ─── P-05: Service container spawn check ─────────────────────────────────
- name: P-05 service container spawn (mariadb:11 visible in docker ps?)
continue-on-error: true
run: |
echo "=== P-05: Service container spawn ==="
docker ps 2>&1 | grep -i maria \
&& echo "RESULT: MariaDB service container IS visible in docker ps (Docker-executor mode confirmed)" \
|| echo "RESULT: no mariadb container visible in docker ps (likely host-executor mode — services: not supported)"
# ─── P-06: MariaDB reachability — try BOTH hostnames ─────────────────────
# Does NOT fail the job: records which hostname resolves.
- name: P-06 MariaDB reachability (hostname=mariadb — Docker mode)
continue-on-error: true
run: |
echo "=== P-06a: MariaDB via hostname 'mariadb' (Docker-executor mode) ==="
mysql -h mariadb -P 3306 -u familysync -ptestpass -e "SELECT 1" 2>&1 | head \
&& echo "P-06a RESULT: mariadb hostname RESOLVES — Docker mode" \
|| echo "P-06a RESULT: mariadb hostname DOES NOT resolve (expected if host-executor mode)"
- name: P-06 MariaDB reachability (hostname=127.0.0.1 — host mode)
continue-on-error: true
run: |
echo "=== P-06b: MariaDB via 127.0.0.1 (host-executor mode fallback) ==="
mysql -h 127.0.0.1 -P 3306 -u familysync -ptestpass -e "SELECT 1" 2>&1 | head \
&& echo "P-06b RESULT: 127.0.0.1 RESOLVES — host mode" \
|| echo "P-06b RESULT: 127.0.0.1 does not resolve (expected if Docker-executor mode uses 'mariadb' hostname)"
# ─── P-09: actions/cache ─────────────────────────────────────────────────
# Known issue: cache server runs in runner container; job container on different
# network may cause socket hang-up. continue-on-error so probe reports finding.
- name: P-09 cache action (actions/cache@v4 — may time out in Docker mode)
uses: actions/cache@v4
continue-on-error: true
with:
path: /tmp/probe-cache-test
key: runner-probe-cache-test-${{ github.sha }}
- name: P-09 cache result
run: |
echo "=== P-09: Cache action result ==="
echo "If the previous 'cache' step completed without hanging, cache IS usable."
echo "If it timed out or errored, fall back to no-cache in downstream jobs."
# ─── P-10: Playwright WebKit system deps ────────────────────────────────
# Confirms WebKit system deps install without sudo/apt failure (Assumption A10).
# Runs from apps/pwa where @playwright/test is installed.
- name: P-10 Playwright WebKit + Chromium system deps
continue-on-error: true
working-directory: apps/pwa
run: |
echo "=== P-10: Playwright browser system deps (webkit + chromium) ==="
npx playwright install --with-deps webkit chromium 2>&1 | tail -30
echo "--- Exit code: $? ---"
echo "If the above shows installed without 'sudo' or 'apt' errors, WebKit deps are OK."
# ─── P-11: gitea-upload-artifact fork ───────────────────────────────────
# The official upload-artifact action is broken on Gitea (detected as GHES, aborts).
# Use ChristopherHX/gitea-upload-artifact@v4 — the confirmed Gitea fix (RESEARCH T-08-SC).
- name: P-11 write dummy artifact for upload test
run: |
echo "=== P-11: Upload artifact test ==="
mkdir -p /tmp/probe-artifact
echo "runner-probe artifact: sha=${GITHUB_SHA}" > /tmp/probe-artifact/probe.txt
cat /tmp/probe-artifact/probe.txt
- name: P-11 artifact upload (ChristopherHX/gitea-upload-artifact@v4)
uses: https://github.com/ChristopherHX/gitea-upload-artifact@v4
continue-on-error: true
with:
name: runner-probe-artifact
path: /tmp/probe-artifact/
retention-days: 3
# ─── P-13: GITHUB_SHA short SHA expression ───────────────────────────────
- name: P-13 short SHA expression (D-04 tag validation)
run: |
echo "=== P-13: GITHUB_SHA short SHA ==="
echo "GITHUB_SHA full = ${GITHUB_SHA}"
echo "short sha = ${GITHUB_SHA:0:7}"
echo "Expected: a 7-character hex string — confirms D-04 tag expression works"
if [ "${#GITHUB_SHA}" -ge 7 ]; then
echo "P-13 RESULT: OK — GITHUB_SHA is available and bash substring works"
else
echo "P-13 RESULT: WARN — GITHUB_SHA is shorter than expected or empty"
fi
# ─── SUMMARY: one-line verdict per fork ──────────────────────────────────
# Plans 0204 consume these answers to pick the correct implementation path.
- name: SUMMARY — fork verdicts (record answers for SUMMARY.md)
run: |
echo "========================================================"
echo " RUNNER PROBE SUMMARY — FORK ANSWERS"
echo "========================================================"
echo ""
echo "P-03 Runner mode:"
if [ -f /.dockerenv ]; then
echo " DOCKER-EXECUTOR — job runs in a container"
echo " → services: works; DB_HOST=mariadb"
else
echo " HOST-EXECUTOR — job runs directly on host"
echo " → services: NOT supported; use docker run -d + DB_HOST=127.0.0.1"
fi
echo ""
echo "P-05/P-06 MariaDB service container:"
MARIA_CONTAINER=$(docker ps 2>/dev/null | grep -i maria | head -1 || true)
if [ -n "$MARIA_CONTAINER" ]; then
echo " Service container IS visible — hostname 'mariadb' should resolve"
else
echo " Service container NOT visible — use docker run -d fallback"
fi
echo ""
echo "P-09 Cache: see 'cache' step result above (continue-on-error — pass = usable)"
echo "P-10 WebKit deps: see 'playwright install' step above (continue-on-error)"
echo "P-11 Upload artifact: see 'gitea-upload-artifact' step above (continue-on-error)"
echo ""
echo "P-13 Short SHA: ${GITHUB_SHA:0:7}"
echo ""
echo " SECURITY CHECK: this probe references NO secrets (T-08-01 compliant)"
echo " P-12 (docker login/push) is deferred to Plan 04 — NOT in this probe."
echo "========================================================"