feat(agent): conversation audience + owner-private scope enforcement #625
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: api-pr-ci | |
| on: | |
| pull_request: | |
| paths: | |
| - "services/api/**" | |
| - ".github/workflows/api-pr-ci.yml" | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: api-pr-ci-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: true | |
| env: | |
| GO_VERSION: "1.26" | |
| jobs: | |
| # --------------------------------------------------------------------------- | |
| # 1. Lint — fast feedback, no services needed | |
| # --------------------------------------------------------------------------- | |
| lint: | |
| name: Lint | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| defaults: | |
| run: | |
| working-directory: services/api | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v5 | |
| with: | |
| fetch-depth: 1 | |
| - name: Setup Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ env.GO_VERSION }} | |
| cache-dependency-path: services/api/go.sum | |
| - name: Install golangci-lint | |
| run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@latest | |
| - name: Run golangci-lint | |
| run: golangci-lint run --timeout=5m | |
| # --------------------------------------------------------------------------- | |
| # 2. Build — verify the binary compiles | |
| # --------------------------------------------------------------------------- | |
| build: | |
| name: Build | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| defaults: | |
| run: | |
| working-directory: services/api | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v5 | |
| with: | |
| fetch-depth: 1 | |
| - name: Setup Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ env.GO_VERSION }} | |
| cache-dependency-path: services/api/go.sum | |
| - name: Build binary | |
| run: make build | |
| # --------------------------------------------------------------------------- | |
| # 3. Unit & integration tests — in-memory fakes, no external services needed | |
| # --------------------------------------------------------------------------- | |
| test: | |
| name: Unit & integration tests | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| defaults: | |
| run: | |
| working-directory: services/api | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v5 | |
| with: | |
| fetch-depth: 1 | |
| - name: Setup Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ env.GO_VERSION }} | |
| cache-dependency-path: services/api/go.sum | |
| - name: Run tests (race detector) | |
| run: go test -race -timeout 60s -coverprofile=coverage.out $(go list ./... | grep -v '/test/e2e') | |
| - name: Upload coverage report | |
| uses: actions/upload-artifact@v6 | |
| with: | |
| name: coverage-report | |
| path: services/api/coverage.out | |
| retention-days: 7 | |
| # --------------------------------------------------------------------------- | |
| # 4. E2E tests — full HTTP flow via testcontainers-go (manages own containers) | |
| # --------------------------------------------------------------------------- | |
| test-e2e: | |
| name: E2E tests | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| needs: [build] | |
| defaults: | |
| run: | |
| working-directory: services/api | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v5 | |
| with: | |
| fetch-depth: 1 | |
| - name: Setup Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ env.GO_VERSION }} | |
| cache-dependency-path: services/api/go.sum | |
| - name: Run E2E tests | |
| # Every test gets its own Postgres database and, for automation | |
| # tests, its own Redis consumer group/leader-lock key (see | |
| # worker.AutomationConsumer.WithConsumerGroup / | |
| # CronScheduler.WithLeaderKey) — so the whole package is safe to run | |
| # with -parallel, cutting wall-clock time roughly 4-5x versus fully | |
| # sequential. 450s still leaves headroom over the ~100-110s this | |
| # takes locally, plus the 60-90s testcontainer/migration startup on | |
| # cold CI runners. | |
| env: | |
| PACA_E2E: "1" | |
| run: go test -v -timeout 450s -parallel 8 ./test/e2e/... |