Repository navigation
bump npm runtime package series to v0.4 #589
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: amber | |
| on: | |
| push: | |
| branches: | |
| - main | |
| pull_request: | |
| branches: | |
| - main | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| rust-checks: | |
| name: Rust Checks | |
| runs-on: ubuntu-latest | |
| env: | |
| SCCACHE_GHA_ENABLED: "true" | |
| RUSTC_WRAPPER: "sccache" | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: mozilla-actions/sccache-action@v0.0.9 | |
| - name: Validate README CLI Docker tag | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| runtime_tag="$( | |
| cargo run -q -p amber-images --bin version_tags -- docker/images.json | | |
| jq -re '.images[] | select(.name == "amber-cli") | .runtime_tag' | |
| )" | |
| image_ref="ghcr.io/rdi-foundation/amber-cli:${runtime_tag}" | |
| readme_refs="$(grep -oE 'ghcr\.io/rdi-foundation/amber-cli:[A-Za-z0-9._-]+' README.md || true)" | |
| if [ -z "$readme_refs" ]; then | |
| echo "::error::README.md does not reference the amber-cli Docker image." | |
| exit 1 | |
| fi | |
| unexpected_refs="$(printf '%s\n' "$readme_refs" | grep -Fvx "$image_ref" || true)" | |
| if [ -n "$unexpected_refs" ]; then | |
| echo "::error::README.md must use ${image_ref} for every amber-cli Docker example." | |
| printf '%s\n' "$unexpected_refs" | |
| exit 1 | |
| fi | |
| - run: cargo fmt --all -- --check | |
| - run: cargo clippy --workspace --all-features --all-targets -- -D warnings -D clippy::dbg_macro | |
| rust-tests: | |
| name: Rust Tests | |
| runs-on: ubuntu-latest | |
| env: | |
| SCCACHE_GHA_ENABLED: "true" | |
| RUSTC_WRAPPER: "sccache" | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: mozilla-actions/sccache-action@v0.0.9 | |
| - name: Relax AppArmor user namespace restrictions when present | |
| run: | | |
| set -euo pipefail | |
| if sysctl kernel.apparmor_restrict_unprivileged_unconfined >/dev/null 2>&1; then | |
| sudo sysctl -w kernel.apparmor_restrict_unprivileged_unconfined=0 | |
| fi | |
| if sysctl kernel.apparmor_restrict_unprivileged_userns >/dev/null 2>&1; then | |
| sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 | |
| fi | |
| - name: Ensure direct runtime sandbox packages are available | |
| run: | | |
| set -euo pipefail | |
| sudo apt-get update | |
| sudo apt-get install -y bubblewrap slirp4netns | |
| bwrap --version | |
| slirp4netns --version | |
| - run: cargo test --workspace --all-features | |
| direct-tests: | |
| name: Direct Smoke Tests | |
| runs-on: ubuntu-latest | |
| env: | |
| SCCACHE_GHA_ENABLED: "true" | |
| RUSTC_WRAPPER: "sccache" | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: mozilla-actions/sccache-action@v0.0.9 | |
| - name: Relax AppArmor user namespace restrictions when present | |
| run: | | |
| set -euo pipefail | |
| # Ubuntu 24.04 enables AppArmor restrictions for unprivileged user | |
| # namespaces. Bubblewrap relies on those namespaces on the hosted | |
| # runner, so disable the restriction in this ephemeral CI VM. | |
| if sysctl kernel.apparmor_restrict_unprivileged_unconfined >/dev/null 2>&1; then | |
| sudo sysctl -w kernel.apparmor_restrict_unprivileged_unconfined=0 | |
| fi | |
| if sysctl kernel.apparmor_restrict_unprivileged_userns >/dev/null 2>&1; then | |
| sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 | |
| fi | |
| - name: Ensure bubblewrap is available and usable | |
| run: | | |
| set -euo pipefail | |
| probe_bwrap() { | |
| bwrap \ | |
| --die-with-parent \ | |
| --new-session \ | |
| --unshare-pid \ | |
| --unshare-ipc \ | |
| --unshare-net \ | |
| --unshare-uts \ | |
| --ro-bind / / \ | |
| --proc /proc \ | |
| --dev /dev \ | |
| --tmpfs /tmp \ | |
| --tmpfs /run \ | |
| -- /usr/bin/true >/dev/null 2>&1 | |
| } | |
| probe_bwrap_verbose() { | |
| bwrap \ | |
| --die-with-parent \ | |
| --new-session \ | |
| --unshare-pid \ | |
| --unshare-ipc \ | |
| --unshare-net \ | |
| --unshare-uts \ | |
| --ro-bind / / \ | |
| --proc /proc \ | |
| --dev /dev \ | |
| --tmpfs /tmp \ | |
| --tmpfs /run \ | |
| -- /usr/bin/true | |
| } | |
| if ! command -v bwrap >/dev/null 2>&1 || ! probe_bwrap; then | |
| sudo apt-get update | |
| sudo apt-get install -y --reinstall bubblewrap | |
| fi | |
| if ! probe_bwrap; then | |
| echo "bubblewrap is installed but unusable on this runner" >&2 | |
| bwrap --version || true | |
| ls -l "$(command -v bwrap)" || true | |
| sysctl kernel.apparmor_restrict_unprivileged_unconfined || true | |
| sysctl kernel.apparmor_restrict_unprivileged_userns || true | |
| probe_bwrap_verbose || true | |
| exit 1 | |
| fi | |
| - name: Ensure slirp4netns is available | |
| run: | | |
| set -euo pipefail | |
| if ! command -v slirp4netns >/dev/null 2>&1; then | |
| sudo apt-get update | |
| sudo apt-get install -y slirp4netns | |
| fi | |
| slirp4netns --version | |
| - name: Run direct smoke test | |
| run: cargo test -p amber-cli --all-features direct_smoke_ -- --ignored --test-threads=1 | |
| vm-linux-tests: | |
| name: VM Smoke Tests (Linux) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 75 | |
| env: | |
| SCCACHE_GHA_ENABLED: "true" | |
| RUSTC_WRAPPER: "sccache" | |
| AMBER_VM_FORCE_TCG: "1" | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: mozilla-actions/sccache-action@v0.0.9 | |
| - name: Configure VM smoke image path | |
| run: | | |
| set -euo pipefail | |
| echo "AMBER_VM_SMOKE_BASE_IMAGE=${RUNNER_TEMP}/ubuntu-24.04-minimal-cloudimg-amd64.img" >> "$GITHUB_ENV" | |
| - name: Ensure VM runtime packages are available | |
| run: | | |
| set -euo pipefail | |
| sudo apt-get update | |
| sudo apt-get install -y qemu-system-x86 qemu-utils xorriso | |
| - name: Fetch Ubuntu minimal cloud image | |
| run: | | |
| set -euo pipefail | |
| image_url="https://cloud-images.ubuntu.com/minimal/releases/noble/release-20240709/ubuntu-24.04-minimal-cloudimg-amd64.img" | |
| if [ ! -f "$AMBER_VM_SMOKE_BASE_IMAGE" ]; then | |
| curl --fail --show-error --silent --location \ | |
| --retry 5 \ | |
| --retry-all-errors \ | |
| --output "$AMBER_VM_SMOKE_BASE_IMAGE" \ | |
| "$image_url" | |
| fi | |
| qemu-img info "$AMBER_VM_SMOKE_BASE_IMAGE" | |
| - name: Run Linux VM smoke test | |
| run: cargo test -p amber-cli --test vm_smoke -- --ignored --nocapture --test-threads=1 | |
| kvm-smoke-tests: | |
| name: KVM Smoke Tests | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| env: | |
| SCCACHE_GHA_ENABLED: "true" | |
| RUSTC_WRAPPER: "sccache" | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: mozilla-actions/sccache-action@v0.0.9 | |
| - name: Run KVM smoke test | |
| run: cargo test -p amber-cli --test kvm_smoke -- --ignored --nocapture --test-threads=1 | |
| kubernetes-tests: | |
| name: Kubernetes Reporter Tests | |
| runs-on: ubuntu-latest | |
| if: github.event_name == 'pull_request' | |
| needs: docker-build | |
| permissions: | |
| contents: read | |
| packages: read | |
| env: | |
| SCCACHE_GHA_ENABLED: "true" | |
| RUSTC_WRAPPER: "sccache" | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: mozilla-actions/sccache-action@v0.0.9 | |
| - name: Ensure KinD is available | |
| run: | | |
| if ! command -v kind >/dev/null 2>&1; then | |
| curl -fsSL -o /tmp/kind https://kind.sigs.k8s.io/dl/v0.22.0/kind-linux-amd64 | |
| chmod +x /tmp/kind | |
| sudo mv /tmp/kind /usr/local/bin/kind | |
| fi | |
| - name: Ensure kubectl is available | |
| run: | | |
| if ! command -v kubectl >/dev/null 2>&1; then | |
| curl -fsSL -o /tmp/kubectl "https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl" | |
| chmod +x /tmp/kubectl | |
| sudo mv /tmp/kubectl /usr/local/bin/kubectl | |
| fi | |
| - name: Create shared KinD cluster | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| cluster_name="amber-ci-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}" | |
| kubeconfig="${RUNNER_TEMP}/amber-kind-kubeconfig" | |
| kind create cluster --name "$cluster_name" --kubeconfig "$kubeconfig" --wait 120s | |
| echo "AMBER_TEST_KIND_CLUSTER_NAME=${cluster_name}" >> "$GITHUB_ENV" | |
| echo "AMBER_TEST_KIND_KUBECONFIG=${kubeconfig}" >> "$GITHUB_ENV" | |
| - name: Compute image registries | |
| id: registry | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| owner_lc="$(printf '%s' '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')" | |
| ci_registry="ghcr.io/${owner_lc}" | |
| code_registry="$(jq -r '.registry' docker/images.json)" | |
| if [ -z "$code_registry" ] || [ "$code_registry" = "null" ]; then | |
| echo "docker/images.json registry is missing" >&2 | |
| exit 1 | |
| fi | |
| code_registry="${code_registry%/}" | |
| echo "CI_IMAGE_REGISTRY=${ci_registry}" >> "$GITHUB_ENV" | |
| echo "CODE_IMAGE_REGISTRY=${code_registry}" >> "$GITHUB_ENV" | |
| - uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Pull and retag images for tests | |
| shell: bash | |
| run: | | |
| SOURCE_IMAGE_REGISTRY="$CI_IMAGE_REGISTRY" \ | |
| TARGET_IMAGE_REGISTRY="$CODE_IMAGE_REGISTRY" \ | |
| SOURCE_IMAGE_TAG="$GITHUB_SHA" \ | |
| ./.github/scripts/prepare_prebuilt_images.sh | |
| - name: Run Kubernetes smoke tests (prebuilt images) | |
| env: | |
| AMBER_TEST_USE_PREBUILT_IMAGES: "1" | |
| run: | | |
| cargo test -p amber-compiler --all-features kubernetes_smoke_config_roundtrip -- --ignored --test-threads=1 | |
| cargo test -p amber-compiler --all-features kubernetes_smoke_external_slot_routes_to_outside_service -- --ignored --test-threads=1 | |
| cargo test -p amber-compiler --all-features kubernetes_smoke_export_routes_to_host -- --ignored --test-threads=1 | |
| - name: Delete shared KinD cluster | |
| if: always() | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| if [ -n "${AMBER_TEST_KIND_CLUSTER_NAME:-}" ]; then | |
| kind delete cluster --name "${AMBER_TEST_KIND_CLUSTER_NAME}" --kubeconfig "${AMBER_TEST_KIND_KUBECONFIG}" | |
| fi | |
| mixed-site-tests: | |
| name: Mixed-Site Live Tests (${{ matrix.shard_name }}) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: ${{ matrix.timeout_minutes }} | |
| needs: docker-build | |
| if: ${{ !cancelled() && (github.event_name != 'pull_request' || needs.docker-build.result == 'success') }} | |
| permissions: | |
| contents: read | |
| packages: read | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - shard_name: mixed-run | |
| timeout_minutes: 120 | |
| needs_direct: true | |
| needs_kind: true | |
| needs_qemu: true | |
| needs_prebuilt_images: true | |
| test_filters: | | |
| mixed_run_ | |
| - shard_name: framework-fast | |
| timeout_minutes: 15 | |
| needs_direct: false | |
| needs_kind: false | |
| needs_qemu: false | |
| needs_prebuilt_images: false | |
| test_filters: | | |
| framework_component_create_to_unoffered_site_fails_deterministically_live | |
| - shard_name: framework-direct | |
| timeout_minutes: 45 | |
| needs_direct: true | |
| needs_kind: false | |
| needs_qemu: false | |
| needs_prebuilt_images: false | |
| test_filters: | | |
| framework_component_direct_create_destroy_live | |
| framework_component_bounded_template_frozen_source_replay_live | |
| framework_component_destroy_of_provider_keeps_consumer_live | |
| - shard_name: dynamic-capabilities | |
| timeout_minutes: 60 | |
| needs_direct: true | |
| needs_kind: false | |
| needs_qemu: false | |
| needs_prebuilt_images: false | |
| test_filters: | | |
| dynamic_capabilities_ | |
| - shard_name: framework-docker | |
| timeout_minutes: 60 | |
| needs_direct: false | |
| needs_kind: false | |
| needs_qemu: false | |
| needs_prebuilt_images: true | |
| test_filters: | | |
| framework_component_concurrent_create_serialization_live | |
| framework_component_root_external_binding_live | |
| framework_component_nonweak_publication_barrier_live | |
| - shard_name: framework-compose-direct | |
| timeout_minutes: 90 | |
| needs_direct: true | |
| needs_kind: false | |
| needs_qemu: false | |
| needs_prebuilt_images: true | |
| test_filters: | | |
| framework_component_delegated_realm_cross_site_live | |
| framework_component_compose_parent_standby_direct_live | |
| framework_component_direct_parent_compose_child_live | |
| framework_component_dynamic_children_teardown_with_run_live | |
| - shard_name: framework-kind-vm | |
| timeout_minutes: 120 | |
| needs_direct: true | |
| needs_kind: true | |
| needs_qemu: true | |
| needs_prebuilt_images: true | |
| test_filters: | | |
| framework_component_kind_root_export_live | |
| framework_component_cross_backend_matrix_live | |
| env: | |
| SCCACHE_GHA_ENABLED: "true" | |
| RUSTC_WRAPPER: "sccache" | |
| AMBER_VM_FORCE_TCG: "1" | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: mozilla-actions/sccache-action@v0.0.9 | |
| - name: Configure mixed-site VM image path | |
| if: matrix.needs_qemu | |
| run: | | |
| set -euo pipefail | |
| case "$(uname -m)" in | |
| x86_64) | |
| echo "AMBER_MIXED_RUN_BASE_IMAGE=${RUNNER_TEMP}/ubuntu-24.04-minimal-cloudimg-amd64.img" >> "$GITHUB_ENV" | |
| echo "AMBER_MIXED_RUN_QEMU_PACKAGES=qemu-system-x86 qemu-utils xorriso" >> "$GITHUB_ENV" | |
| echo "AMBER_MIXED_RUN_IMAGE_URL=https://cloud-images.ubuntu.com/minimal/releases/noble/release-20240709/ubuntu-24.04-minimal-cloudimg-amd64.img" >> "$GITHUB_ENV" | |
| ;; | |
| aarch64|arm64) | |
| echo "AMBER_MIXED_RUN_BASE_IMAGE=${RUNNER_TEMP}/ubuntu-24.04-minimal-cloudimg-arm64.img" >> "$GITHUB_ENV" | |
| echo "AMBER_MIXED_RUN_QEMU_PACKAGES=qemu-system-arm qemu-utils qemu-efi-aarch64 xorriso" >> "$GITHUB_ENV" | |
| echo "AMBER_MIXED_RUN_IMAGE_URL=https://cloud-images.ubuntu.com/minimal/releases/noble/release-20240709/ubuntu-24.04-minimal-cloudimg-arm64.img" >> "$GITHUB_ENV" | |
| ;; | |
| *) | |
| echo "unsupported mixed-site runner architecture: $(uname -m)" >&2 | |
| exit 1 | |
| ;; | |
| esac | |
| - name: Relax AppArmor user namespace restrictions when present | |
| if: matrix.needs_direct | |
| run: | | |
| set -euo pipefail | |
| if sysctl kernel.apparmor_restrict_unprivileged_unconfined >/dev/null 2>&1; then | |
| sudo sysctl -w kernel.apparmor_restrict_unprivileged_unconfined=0 | |
| fi | |
| if sysctl kernel.apparmor_restrict_unprivileged_userns >/dev/null 2>&1; then | |
| sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 | |
| fi | |
| - name: Ensure bubblewrap is available and usable | |
| if: matrix.needs_direct | |
| run: | | |
| set -euo pipefail | |
| probe_bwrap() { | |
| bwrap \ | |
| --die-with-parent \ | |
| --new-session \ | |
| --unshare-pid \ | |
| --unshare-ipc \ | |
| --unshare-net \ | |
| --unshare-uts \ | |
| --ro-bind / / \ | |
| --proc /proc \ | |
| --dev /dev \ | |
| --tmpfs /tmp \ | |
| --tmpfs /run \ | |
| -- /usr/bin/true >/dev/null 2>&1 | |
| } | |
| probe_bwrap_verbose() { | |
| bwrap \ | |
| --die-with-parent \ | |
| --new-session \ | |
| --unshare-pid \ | |
| --unshare-ipc \ | |
| --unshare-net \ | |
| --unshare-uts \ | |
| --ro-bind / / \ | |
| --proc /proc \ | |
| --dev /dev \ | |
| --tmpfs /tmp \ | |
| --tmpfs /run \ | |
| -- /usr/bin/true | |
| } | |
| if ! command -v bwrap >/dev/null 2>&1 || ! probe_bwrap; then | |
| sudo apt-get update | |
| sudo apt-get install -y --reinstall bubblewrap | |
| fi | |
| if ! probe_bwrap; then | |
| echo "bubblewrap is installed but unusable on this runner" >&2 | |
| bwrap --version || true | |
| ls -l "$(command -v bwrap)" || true | |
| sysctl kernel.apparmor_restrict_unprivileged_unconfined || true | |
| sysctl kernel.apparmor_restrict_unprivileged_userns || true | |
| probe_bwrap_verbose || true | |
| exit 1 | |
| fi | |
| - name: Ensure slirp4netns is available | |
| if: matrix.needs_direct | |
| run: | | |
| set -euo pipefail | |
| if ! command -v slirp4netns >/dev/null 2>&1; then | |
| sudo apt-get update | |
| sudo apt-get install -y slirp4netns | |
| fi | |
| slirp4netns --version | |
| - name: Ensure mixed-site VM runtime packages are available | |
| if: matrix.needs_qemu | |
| run: | | |
| set -euo pipefail | |
| sudo apt-get update | |
| sudo apt-get install -y ${AMBER_MIXED_RUN_QEMU_PACKAGES} | |
| - name: Fetch Ubuntu minimal cloud image | |
| if: matrix.needs_qemu | |
| run: | | |
| set -euo pipefail | |
| if [ ! -f "$AMBER_MIXED_RUN_BASE_IMAGE" ]; then | |
| curl --fail --show-error --silent --location \ | |
| --retry 5 \ | |
| --retry-all-errors \ | |
| --output "$AMBER_MIXED_RUN_BASE_IMAGE" \ | |
| "$AMBER_MIXED_RUN_IMAGE_URL" | |
| fi | |
| qemu-img info "$AMBER_MIXED_RUN_BASE_IMAGE" | |
| - name: Ensure KinD is available | |
| if: matrix.needs_kind | |
| run: | | |
| if ! command -v kind >/dev/null 2>&1; then | |
| curl -fsSL -o /tmp/kind https://kind.sigs.k8s.io/dl/v0.22.0/kind-linux-amd64 | |
| chmod +x /tmp/kind | |
| sudo mv /tmp/kind /usr/local/bin/kind | |
| fi | |
| - name: Ensure kubectl is available | |
| if: matrix.needs_kind | |
| run: | | |
| if ! command -v kubectl >/dev/null 2>&1; then | |
| curl -fsSL -o /tmp/kubectl "https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl" | |
| chmod +x /tmp/kubectl | |
| sudo mv /tmp/kubectl /usr/local/bin/kubectl | |
| fi | |
| - name: Create shared KinD cluster | |
| if: matrix.needs_kind | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| cluster_name="amber-mixed-ci-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}-${{ matrix.shard_name }}" | |
| kubeconfig="${RUNNER_TEMP}/amber-mixed-kind-kubeconfig" | |
| kind create cluster --name "$cluster_name" --kubeconfig "$kubeconfig" --wait 120s | |
| echo "AMBER_TEST_KIND_CLUSTER_NAME=${cluster_name}" >> "$GITHUB_ENV" | |
| echo "AMBER_TEST_KIND_KUBECONFIG=${kubeconfig}" >> "$GITHUB_ENV" | |
| - name: Compute image registries | |
| if: github.event_name == 'pull_request' && matrix.needs_prebuilt_images | |
| id: registry | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| owner_lc="$(printf '%s' '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')" | |
| ci_registry="ghcr.io/${owner_lc}" | |
| code_registry="$(jq -r '.registry' docker/images.json)" | |
| if [ -z "$code_registry" ] || [ "$code_registry" = "null" ]; then | |
| echo "docker/images.json registry is missing" >&2 | |
| exit 1 | |
| fi | |
| code_registry="${code_registry%/}" | |
| echo "CI_IMAGE_REGISTRY=${ci_registry}" >> "$GITHUB_ENV" | |
| echo "CODE_IMAGE_REGISTRY=${code_registry}" >> "$GITHUB_ENV" | |
| - name: Compute semver tag metadata | |
| if: github.event_name == 'pull_request' && matrix.needs_prebuilt_images | |
| id: version_tags | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| json="$(cargo run -q -p amber-images --bin version_tags -- docker/images.json)" | |
| { | |
| echo "json<<EOF" | |
| echo "$json" | |
| echo "EOF" | |
| } >> "$GITHUB_OUTPUT" | |
| - uses: docker/login-action@v3 | |
| if: github.event_name == 'pull_request' && matrix.needs_prebuilt_images | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Pull and retag images for live test shard | |
| if: github.event_name == 'pull_request' && matrix.needs_prebuilt_images | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| version_tags_json='${{ steps.version_tags.outputs.json }}' | |
| while IFS= read -r spec; do | |
| [ -z "$spec" ] && continue | |
| name="$(jq -r '.name' <<< "$spec")" | |
| version="$(jq -r '.version' <<< "$spec")" | |
| runtime_tag="$(jq -r '.runtime_tag' <<< "$spec")" | |
| src="${CI_IMAGE_REGISTRY}/${name}:${GITHUB_SHA}" | |
| docker pull "$src" | |
| docker tag "$src" "${CODE_IMAGE_REGISTRY}/${name}:${version}" | |
| if [ "$runtime_tag" != "$version" ]; then | |
| docker tag "$src" "${CODE_IMAGE_REGISTRY}/${name}:${runtime_tag}" | |
| fi | |
| if [ "$name" = "amber-helper" ]; then | |
| docker tag "$src" "amber-helper:e2e" | |
| fi | |
| done < <(jq -c '.images[]' <<< "$version_tags_json") | |
| - name: Run live test shard | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| if [ "${{ github.event_name }}" = "pull_request" ] && [ "${{ matrix.needs_prebuilt_images }}" = "true" ]; then | |
| export AMBER_TEST_USE_PREBUILT_IMAGES=1 | |
| fi | |
| while IFS= read -r test_filter; do | |
| [ -n "$test_filter" ] || continue | |
| cargo test -p amber-cli --test mixed_run "$test_filter" -- --ignored --nocapture --test-threads=1 | |
| done <<'EOF' | |
| ${{ matrix.test_filters }} | |
| EOF | |
| - name: Delete shared KinD cluster | |
| if: always() && matrix.needs_kind | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| if [ -n "${AMBER_TEST_KIND_CLUSTER_NAME:-}" ]; then | |
| kind delete cluster --name "${AMBER_TEST_KIND_CLUSTER_NAME}" --kubeconfig "${AMBER_TEST_KIND_KUBECONFIG}" | |
| fi | |
| image-matrix: | |
| name: Image Matrix | |
| runs-on: ubuntu-latest | |
| outputs: | |
| build_matrix: ${{ steps.matrix.outputs.build_matrix }} | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - name: Build image matrix | |
| id: matrix | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| matrix=$(jq -c '{ | |
| include: [ | |
| .images[] as $img | | |
| { | |
| image: $img.name, | |
| context: $img.context, | |
| file: $img.dockerfile, | |
| arch: "amd64", | |
| runner: "ubuntu-latest" | |
| } | |
| ] | |
| }' docker/images.json) | |
| echo "build_matrix=$matrix" >> "$GITHUB_OUTPUT" | |
| docker-build: | |
| name: Build Docker Images (${{ matrix.image }} ${{ matrix.arch }}) | |
| runs-on: ${{ matrix.runner }} | |
| if: github.event_name == 'pull_request' | |
| needs: image-matrix | |
| permissions: | |
| contents: read | |
| packages: write | |
| strategy: | |
| fail-fast: false | |
| matrix: ${{ fromJSON(needs.image-matrix.outputs.build_matrix) }} | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - name: Compute image registry | |
| id: registry | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| owner_lc="$(printf '%s' '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')" | |
| image_registry="ghcr.io/${owner_lc}" | |
| echo "image_registry=${image_registry}" >> "$GITHUB_OUTPUT" | |
| echo "IMAGE_REGISTRY=${image_registry}" >> "$GITHUB_ENV" | |
| - uses: docker/setup-buildx-action@v3 | |
| - uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Build and push | |
| uses: docker/build-push-action@v5 | |
| with: | |
| context: ${{ matrix.context }} | |
| file: ${{ matrix.file }} | |
| build-args: | | |
| BUILD_MODE=release | |
| platforms: linux/${{ matrix.arch }} | |
| push: true | |
| labels: | | |
| org.opencontainers.image.revision=${{ github.sha }} | |
| tags: ${{ steps.registry.outputs.image_registry }}/${{ matrix.image }}:${{ github.sha }} | |
| cache-from: | | |
| type=gha,scope=refs/heads/main-${{ matrix.image }}-${{ matrix.arch }} | |
| type=gha,scope=${{ matrix.image }}-pr-${{ github.event.pull_request.number }}-${{ matrix.arch }} | |
| cache-to: type=gha,mode=max,scope=${{ matrix.image }}-pr-${{ github.event.pull_request.number }}-${{ matrix.arch }} | |
| docker-tests: | |
| name: Docker Smoke Tests (prebuilt images) | |
| runs-on: ubuntu-latest | |
| if: github.event_name == 'pull_request' | |
| needs: docker-build | |
| permissions: | |
| contents: read | |
| packages: read | |
| env: | |
| SCCACHE_GHA_ENABLED: "true" | |
| RUSTC_WRAPPER: "sccache" | |
| AMBER_TEST_USE_PREBUILT_IMAGES: "1" | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: mozilla-actions/sccache-action@v0.0.9 | |
| - name: Compute image registries | |
| id: registry | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| owner_lc="$(printf '%s' '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')" | |
| ci_registry="ghcr.io/${owner_lc}" | |
| code_registry="$(jq -r '.registry' docker/images.json)" | |
| if [ -z "$code_registry" ] || [ "$code_registry" = "null" ]; then | |
| echo "docker/images.json registry is missing" >&2 | |
| exit 1 | |
| fi | |
| code_registry="${code_registry%/}" | |
| echo "CI_IMAGE_REGISTRY=${ci_registry}" >> "$GITHUB_ENV" | |
| echo "CODE_IMAGE_REGISTRY=${code_registry}" >> "$GITHUB_ENV" | |
| - name: Compute semver tag metadata | |
| id: version_tags | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| json="$(cargo run -q -p amber-images --bin version_tags -- docker/images.json)" | |
| { | |
| echo "json<<EOF" | |
| echo "$json" | |
| echo "EOF" | |
| } >> "$GITHUB_OUTPUT" | |
| - uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Pull and retag images for tests | |
| shell: bash | |
| env: | |
| VERSION_TAGS_JSON: ${{ steps.version_tags.outputs.json }} | |
| run: | | |
| SOURCE_IMAGE_REGISTRY="$CI_IMAGE_REGISTRY" \ | |
| TARGET_IMAGE_REGISTRY="$CODE_IMAGE_REGISTRY" \ | |
| SOURCE_IMAGE_TAG="$GITHUB_SHA" \ | |
| ./.github/scripts/prepare_prebuilt_images.sh | |
| - name: Run docker compose smoke tests | |
| run: | | |
| cargo test -p amber-compiler --all-features docker_smoke_ocap_blocks_unbound_callers -- --ignored --test-threads=1 | |
| cargo test -p amber-compiler --all-features docker_smoke_config_forwarding_runtime_validation -- --ignored --test-threads=1 | |
| cargo test -p amber-compiler --all-features docker_smoke_external_slot_routes_to_outside_service -- --ignored --test-threads=1 | |
| - name: Run helper docker smoke test | |
| run: cargo test -p amber-helper --all-features helper_image_executes_run_plan_in_scratch -- --ignored --test-threads=1 |