Repository navigation
docs(readme): add Glama MCP score badge #851
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| pull_request: | |
| branches: [main, dev] | |
| push: | |
| # `main` is intentionally not listed here -- pushes to main are gated | |
| # through publish-images.yml, which calls this workflow via workflow_call. | |
| # Listing main twice would cause CI to run on every merge commit twice. | |
| branches: [dev] | |
| # Allow other workflows (publish-images, release) to reuse this one as a | |
| # gate via `uses: ./.github/workflows/ci.yml`. | |
| workflow_call: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| env: | |
| CARGO_TERM_COLOR: always | |
| RUSTFLAGS: -Dwarnings | |
| jobs: | |
| # --------------------------------------------------------------------------- | |
| # Rust: format check | |
| # --------------------------------------------------------------------------- | |
| rust-fmt: | |
| name: Rust Format | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - uses: dtolnay/rust-toolchain@stable | |
| with: | |
| components: rustfmt | |
| - run: cargo fmt --all -- --check | |
| # --------------------------------------------------------------------------- | |
| # Rust: clippy lint | |
| # --------------------------------------------------------------------------- | |
| rust-clippy: | |
| name: Rust Clippy | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Install system dependencies | |
| run: sudo apt-get update && sudo apt-get install -y libdbus-1-dev pkg-config | |
| - uses: dtolnay/rust-toolchain@stable | |
| with: | |
| components: clippy | |
| - uses: Swatinem/rust-cache@v2 | |
| - run: cargo clippy --workspace --all-targets -- -D warnings | |
| # --------------------------------------------------------------------------- | |
| # Rust: backend build + test | |
| # Handler + service tests call `connect_test_database` which probes a local | |
| # MongoDB on 27017 (no auth) then 27018 (auth, used by the dev docker-compose | |
| # override) and skips when neither is reachable. The service container below | |
| # satisfies the 27017 probe so those tests actually run instead of silently | |
| # skipping. | |
| # --------------------------------------------------------------------------- | |
| backend-test: | |
| name: Backend Test | |
| runs-on: ubuntu-latest | |
| services: | |
| mongodb: | |
| image: mongo:8.0 | |
| ports: | |
| - 27017:27017 | |
| options: >- | |
| --health-cmd "mongosh --quiet --eval 'db.adminCommand({ ping: 1 })'" | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 5 | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Install system dependencies | |
| run: sudo apt-get update && sudo apt-get install -y libdbus-1-dev pkg-config | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: Swatinem/rust-cache@v2 | |
| with: | |
| key: backend | |
| - uses: taiki-e/install-action@nextest | |
| - name: Build backend | |
| run: cargo build -p nyxid | |
| - name: Run backend tests | |
| run: cargo nextest run -p nyxid --profile ci | |
| - name: Publish test summary | |
| if: always() | |
| uses: test-summary/action@v2 | |
| with: | |
| paths: target/nextest/ci/junit.xml | |
| show: all | |
| # --------------------------------------------------------------------------- | |
| # Rust: CLI / node-agent build + test (no DB required) | |
| # --------------------------------------------------------------------------- | |
| cli-test: | |
| name: CLI Test | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Install system dependencies | |
| run: sudo apt-get update && sudo apt-get install -y libdbus-1-dev pkg-config | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: Swatinem/rust-cache@v2 | |
| with: | |
| key: cli | |
| - uses: taiki-e/install-action@nextest | |
| - name: Build CLI | |
| run: cargo build -p nyxid-cli | |
| - name: Run CLI tests | |
| run: cargo nextest run -p nyxid-cli --profile ci | |
| - name: Publish test summary | |
| if: always() | |
| uses: test-summary/action@v2 | |
| with: | |
| paths: target/nextest/ci/junit.xml | |
| show: all | |
| # --------------------------------------------------------------------------- | |
| # Rust: build with feature flags (KMS providers) | |
| # --------------------------------------------------------------------------- | |
| rust-features: | |
| name: Rust Features (${{ matrix.features }}) | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - features: aws-kms | |
| cache-suffix: aws-kms | |
| - features: gcp-kms | |
| cache-suffix: gcp-kms | |
| - features: aws-kms,gcp-kms | |
| cache-suffix: aws-and-gcp-kms | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Install system dependencies | |
| run: sudo apt-get update && sudo apt-get install -y libdbus-1-dev pkg-config | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: Swatinem/rust-cache@v2 | |
| with: | |
| key: features-${{ matrix.cache-suffix }} | |
| - name: Build with --features ${{ matrix.features }} | |
| run: cargo build -p nyxid --features ${{ matrix.features }} | |
| # --------------------------------------------------------------------------- | |
| # Frontend: lint, type-check, test, build | |
| # --------------------------------------------------------------------------- | |
| frontend: | |
| name: Frontend | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: frontend | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version-file: .node-version | |
| cache: npm | |
| cache-dependency-path: frontend/package-lock.json | |
| - run: npm ci | |
| - run: npm run lint | |
| - run: npm run test | |
| - run: npm run build | |
| # --------------------------------------------------------------------------- | |
| # CLI wizard bundle: source-closure freshness check. | |
| # | |
| # The CLI embeds the React wizard bundle at `cli/src/wizard/assets/index.html` | |
| # via `rust_embed`. We commit the prebuilt artifact so `cargo build -p | |
| # nyxid-cli` doesn't need a Node toolchain. To detect drift, `build:wizard` | |
| # also writes the wizard's full module graph to | |
| # `cli/src/wizard/bundle-meta/index.manifest` and a SHA-256 over every | |
| # source file in that graph (+ package-lock, vite config, node-version) to | |
| # `cli/src/wizard/bundle-meta/index.hash`. | |
| # | |
| # This job recomputes the hash from sources and fails if it no longer | |
| # matches the committed hash — i.e. someone edited wizard source without | |
| # running `npm --prefix frontend run build:wizard`. Because the check is | |
| # source-only, it is immune to byte-level non-determinism between Vite / | |
| # esbuild versions that previously caused spurious failures on unrelated | |
| # PRs. Runs in parallel with `cli-test`; overall pipeline wall-clock is | |
| # unchanged. See CONTRIBUTING.md § CLI Wizard Bundle for the rebuild | |
| # workflow. | |
| # --------------------------------------------------------------------------- | |
| wizard-bundle-freshness: | |
| name: CLI Wizard Bundle Freshness | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Install system dependencies | |
| run: sudo apt-get update && sudo apt-get install -y libdbus-1-dev pkg-config | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: Swatinem/rust-cache@v2 | |
| with: | |
| key: wizard-freshness | |
| - name: Verify wizard bundle freshness | |
| run: cargo test -p nyxid-cli --test wizard_bundle_freshness | |
| # --------------------------------------------------------------------------- | |
| # SDK: build all packages | |
| # --------------------------------------------------------------------------- | |
| sdk: | |
| name: SDK Build | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: sdk | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version-file: .node-version | |
| cache: npm | |
| cache-dependency-path: sdk/package-lock.json | |
| - run: npm ci | |
| - run: npm run build |