Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
129 changes: 16 additions & 113 deletions .github/workflows/build_deploy_dev.yml
Original file line number Diff line number Diff line change
@@ -1,10 +1,8 @@
name: Build and deploy to dev
name: Test pull request

permissions:
contents: read
pull-requests: write
pages: write
id-token: write
pull-requests: read

on:
pull_request:
Expand All @@ -14,7 +12,7 @@ on:
- 'releases/*'

# Cancel any existing runs of this workflow on the same branch/pr
# We always want to build/deploy/test a new commit over an older one
# We always want to test a new commit over an older one
concurrency:
group: ${{ github.workflow_ref }}
cancel-in-progress: true
Expand All @@ -27,7 +25,10 @@ jobs:
outputs:
not-docs: ${{ steps.filter.outputs.not-docs }}
steps:
- uses: dorny/paths-filter@v3
# A pull request that changes only docs, images or Markdown skips the unit
# tests. Every other change runs them, including a version bump, because
# setup.py builds the package from mindsdb/__about__.py.
- uses: dorny/paths-filter@0e4a8c6effa4802afeda77dc8d303f8176d7dfad # v3.0.4
id: filter
with:
predicate-quantifier: "every"
Expand All @@ -36,126 +37,28 @@ jobs:
- '!docs/**'
- '!assets/**'
- '!**/*.md'
- '!.github/workflows/build_deploy_dev.yml'
- '!.github/workflows/test_on_deploy.yml'
- '!mindsdb/__about__.py'

# Start running unit tests early - we want to run them always
# and they don't depend on build or deployment
run_unit_tests:
name: Run Unit Tests
needs: [changes]
if: ${{ needs.changes.outputs.not-docs == 'true' }}
# tests_unit.yml asks for these permissions itself, and a called workflow
# can only keep or lower what the job that calls it grants.
permissions:
contents: read
pull-requests: write
pages: write
id-token: write
uses: ./.github/workflows/tests_unit.yml
secrets: inherit

# Looks for labels like "deploy-to-<env>" attached to a PR so we can deploy to those envs
get-deploy-labels:
if: ${{ !github.event.pull_request.head.repo.fork }}
name: Get Deploy Envs
runs-on: mdb-dev
needs: [changes]
outputs:
deploy-envs: ${{ steps.get-labels.outputs.deploy-envs }}
steps:
- id: get-labels
uses: mindsdb/github-actions/get-deploy-labels@main

# Build our docker images based on our bake file
build:
if: ${{ !github.event.pull_request.head.repo.fork && needs.get-deploy-labels.outputs.deploy-envs != '[]' }}
name: Build Docker Images
runs-on: mdb-dev
needs: [get-deploy-labels]
steps:
- uses: actions/checkout@v4
# Build the bakefile and push
- uses: mindsdb/github-actions/docker-bake@main
with:
git-sha: ${{ github.event.pull_request.head.sha }}
target: cloud-cpu
platforms: linux/amd64
push-cache: false

scan-keycloak:
if: ${{ !github.event.pull_request.head.repo.fork }}
runs-on: mdb-dev
needs: [ build ]
name: Scan cloud-cpu image
steps:
- uses: actions/checkout@v4
- uses: mindsdb/github-actions/snyk-docker-scan@main
with:
image: 168681354662.dkr.ecr.us-east-1.amazonaws.com/mindsdb:${{ github.event.pull_request.head.sha }}-cloud-cpu
snyk-token: ${{ secrets.SNYK_TOKEN }}
dockerfile: docker/mindsdb.Dockerfile

# Push cache layers to docker registry
# This is separate to the build step so we can do other stuff in parallel
build-cache:
if: ${{ !github.event.pull_request.head.repo.fork }}
name: Push Docker Cache
runs-on: mdb-dev
needs: [build]
steps:
- uses: actions/checkout@v4
# Build the bakefile and push
- uses: mindsdb/github-actions/docker-bake@main
with:
git-sha: ${{ github.event.pull_request.head.sha }}
target: cloud-cpu
platforms: linux/amd64
push-cache: true
cache-only: true

# This will run the deployment workflow in the base branch, not in the PR.
# So if you change the deploy workflow in your PR, the changes won't be reflected in this run.
deploy:
if: ${{ !github.event.pull_request.head.repo.fork && needs.get-deploy-labels.outputs.deploy-envs != '[]' }}
name: Deploy
needs: [build, get-deploy-labels]
uses: ./.github/workflows/deploy.yml
with:
deploy-envs: ${{ needs.get-deploy-labels.outputs.deploy-envs }}
image-tag: ${{ github.event.pull_request.head.sha }}
secrets: inherit

# Run integration tests against the deployed environment
run_integration_tests:
if: ${{ !github.event.pull_request.head.repo.fork }}
name: Run Integration Tests
needs: [deploy, get-deploy-labels]
strategy:
fail-fast: false
matrix:
deploy-env: ${{ fromJson(needs.get-deploy-labels.outputs.deploy-envs) }}
concurrency:
group: deploy-${{ matrix.deploy-env }}
cancel-in-progress: false
uses: ./.github/workflows/tests_integration.yml
with:
deploy-env: ${{ matrix.deploy-env }}
secrets: inherit

# This is a collection point for all of the matrix tests above so we can have a single required job
tests_completed:
name: All Tests Succeeded
needs: [run_unit_tests, run_integration_tests, changes, get-deploy-labels]
needs: [run_unit_tests, changes]
runs-on: ubuntu-latest
if: always()
steps:
# A skipped `run_integration_tests` means two different things. With no
# deploy label there was nothing to run them against, which is fine. A
# deploy that failed also leaves them skipped, which is not. Reading
# `!= 'success'` treated both the same, so this job failed on every
# first-party pull request that carried no deploy label and its red said
# nothing. Gate on whether anything was actually deployed instead.
- name: fail if tests failed or didnt run
if: >-
${{ needs.changes.outputs.not-docs == 'true'
&& (needs.run_unit_tests.result != 'success'
|| (needs.get-deploy-labels.outputs.deploy-envs != '[]'
&& !github.event.pull_request.head.repo.fork
&& needs.run_integration_tests.result != 'success')) }}
if: ${{ needs.changes.result != 'success' || (needs.changes.outputs.not-docs == 'true' && needs.run_unit_tests.result != 'success') }}
run: exit 1
- run: echo "Tests ran successfully"
206 changes: 0 additions & 206 deletions .github/workflows/build_deploy_prod.yml

This file was deleted.

Loading
Loading