mirror of
https://github.com/suitenumerique/meet.git
synced 2026-10-01 05:55:11 +02:00
The development stacks now run Garage instead of MinIO which is deprecated. Garage is a bit stricter than MinIO: - key IDs and secrets must be at least 8 and 16 characters long - requests must be signed for its region, so every development env now sets AWS_S3_REGION_NAME=local; - cross-origin requests are denied unless the bucket CORS rules allow them, so a one-shot aws-cli container allows the frontend origin to upload files straight to the bucket.
390 lines
12 KiB
YAML
390 lines
12 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
pull_request:
|
|
branches:
|
|
- "*"
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
lint-git:
|
|
runs-on: ubuntu-latest
|
|
if: github.event_name == 'pull_request' # Makes sense only for pull requests
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
with:
|
|
fetch-depth: 0
|
|
- name: show
|
|
run: git log
|
|
- name: Enforce absence of print statements in code
|
|
if: always()
|
|
run: |
|
|
! git diff origin/${{ github.event.pull_request.base.ref }}..HEAD -- . ':(exclude).github/workflows/**' | grep "print("
|
|
- name: Check absence of fixup commits
|
|
if: always()
|
|
run: |
|
|
! git log | grep 'fixup!'
|
|
- name: Install uv
|
|
if: always()
|
|
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7.6.0
|
|
- name: Lint commit messages added to main
|
|
if: always()
|
|
run: uvx --no-build --from gitlint-core==0.19.1 gitlint --commits origin/${{ github.event.pull_request.base.ref }}..HEAD
|
|
|
|
check-changelog:
|
|
runs-on: ubuntu-latest
|
|
if: |
|
|
contains(github.event.pull_request.labels.*.name, 'noChangeLog') == false &&
|
|
github.event_name == 'pull_request'
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
with:
|
|
fetch-depth: 50
|
|
- name: Check that the CHANGELOG has been modified in the current branch
|
|
run: git diff --name-only ${{ github.event.pull_request.base.sha }} ${{ github.event.after }} | grep 'CHANGELOG.md'
|
|
|
|
lint-changelog:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
- name: Check CHANGELOG max line length
|
|
run: |
|
|
max_line_length=$(cat CHANGELOG.md | grep -Ev "^\[.*\]: https://github.com" | wc -L)
|
|
if [ $max_line_length -ge 80 ]; then
|
|
echo "ERROR: CHANGELOG has lines longer than 80 characters."
|
|
exit 1
|
|
fi
|
|
|
|
build-mails:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/mail
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
|
|
- name: Install Node.js
|
|
uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0
|
|
with:
|
|
node-version: "22"
|
|
|
|
- name: Restore the mail templates
|
|
uses: actions/cache@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0
|
|
id: mail-templates
|
|
with:
|
|
path: "src/backend/core/templates/mail"
|
|
key: mail-templates-${{ hashFiles('src/mail/mjml') }}
|
|
|
|
- name: Install yarn
|
|
if: steps.mail-templates.outputs.cache-hit != 'true'
|
|
run: npm install -g --ignore-scripts yarn@1.22.22
|
|
|
|
- name: Install node dependencies
|
|
if: steps.mail-templates.outputs.cache-hit != 'true'
|
|
run: yarn install --frozen-lockfile --ignore-scripts
|
|
|
|
- name: Build mails
|
|
if: steps.mail-templates.outputs.cache-hit != 'true'
|
|
run: yarn build
|
|
|
|
- name: Cache mail templates
|
|
if: steps.mail-templates.outputs.cache-hit != 'true'
|
|
uses: actions/cache@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0
|
|
with:
|
|
path: "src/backend/core/templates/mail"
|
|
key: mail-templates-${{ hashFiles('src/mail/mjml') }}
|
|
|
|
lint-back:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/backend
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
- name: Install Python
|
|
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7.6.0
|
|
- name: Install the project
|
|
run: uv sync --locked --all-extras
|
|
|
|
- name: Check code formatting with ruff
|
|
run: uv run --no-sync --no-build ruff format . --diff
|
|
- name: Lint code with ruff
|
|
run: uv run --no-sync --no-build ruff check .
|
|
- name: Lint code with pylint
|
|
run: uv run --no-sync --no-build pylint meet demo core
|
|
|
|
lint-agents:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/agents
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
- name: Install Python
|
|
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7.6.0
|
|
- name: Install the project
|
|
run: uv sync --locked --all-extras --no-build
|
|
- name: Check code formatting with ruff
|
|
run: uv run --no-sync --no-build ruff format . --diff
|
|
- name: Lint code with ruff
|
|
run: uv run --no-sync --no-build ruff check .
|
|
|
|
lint-summary:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/summary
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
- name: Install Python
|
|
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7.6.0
|
|
- name: Install the project
|
|
run: uv sync --locked --all-extras
|
|
- name: Check code formatting with ruff
|
|
run: uv run --no-sync --no-build ruff format . --diff
|
|
- name: Lint code with ruff
|
|
run: uv run --no-sync --no-build ruff check .
|
|
|
|
test-back:
|
|
runs-on: ubuntu-latest
|
|
needs: build-mails
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/backend
|
|
|
|
services:
|
|
postgres:
|
|
image: postgres:16
|
|
env:
|
|
POSTGRES_DB: meet
|
|
POSTGRES_USER: dinum
|
|
POSTGRES_PASSWORD: pass
|
|
ports:
|
|
- 5432:5432
|
|
# needed because the postgres container does not provide a healthcheck
|
|
options: --health-cmd pg_isready --health-interval 10s --health-timeout 5s --health-retries 5
|
|
redis:
|
|
image: redis:5
|
|
ports:
|
|
- 6379:6379
|
|
# Set health checks to wait until redis has started
|
|
options: >-
|
|
--health-cmd "redis-cli ping"
|
|
--health-interval 10s
|
|
--health-timeout 5s
|
|
--health-retries 5
|
|
|
|
env:
|
|
DJANGO_CONFIGURATION: Test
|
|
DJANGO_SETTINGS_MODULE: meet.settings
|
|
DJANGO_SECRET_KEY: ThisIsAnExampleKeyForTestPurposeOnly
|
|
OIDC_OP_JWKS_ENDPOINT: /endpoint-for-test-purpose-only
|
|
DB_HOST: localhost
|
|
DB_NAME: meet
|
|
DB_USER: dinum
|
|
DB_PASSWORD: pass
|
|
DB_PORT: 5432
|
|
REDIS_URL: redis://localhost:6379/1
|
|
STORAGES_STATICFILES_BACKEND: django.contrib.staticfiles.storage.StaticFilesStorage
|
|
AWS_S3_ENDPOINT_URL: http://localhost:9000
|
|
AWS_S3_ACCESS_KEY_ID: meet-access-key
|
|
AWS_S3_SECRET_ACCESS_KEY: meet-secret-access-key
|
|
AWS_S3_REGION_NAME: local
|
|
OIDC_RS_CLIENT_ID: meet
|
|
OIDC_RS_CLIENT_SECRET: ThisIsAnExampleKeyForDevPurposeOnly
|
|
OIDC_OP_INTROSPECTION_ENDPOINT: https://oidc.example.com/introspect
|
|
OIDC_OP_URL: https://oidc.example.com
|
|
MEDIA_BASE_URL: http://localhost:8083
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
|
|
- name: Create writable /data
|
|
run: |
|
|
sudo mkdir -p /data/media && \
|
|
sudo mkdir -p /data/static
|
|
|
|
- name: Restore the mail templates
|
|
uses: actions/cache@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0
|
|
id: mail-templates
|
|
with:
|
|
path: "src/backend/core/templates/mail"
|
|
key: mail-templates-${{ hashFiles('src/mail/mjml') }}
|
|
|
|
# Creates the access key and the bucket on startup
|
|
- name: Start Garage
|
|
run: |
|
|
docker run -d --name garage \
|
|
-p 9000:9000 \
|
|
-v "${GITHUB_WORKSPACE}/docker/files/etc/garage/garage.toml:/etc/garage.toml:ro" \
|
|
-e "GARAGE_RPC_SECRET=$(openssl rand -hex 32)" \
|
|
-e "GARAGE_DEFAULT_ACCESS_KEY=meet-access-key" \
|
|
-e "GARAGE_DEFAULT_SECRET_KEY=meet-secret-access-key" \
|
|
-e "GARAGE_DEFAULT_BUCKET=meet-media-storage" \
|
|
dxflrs/garage:v2.4.1 \
|
|
/garage server --single-node --default-bucket
|
|
|
|
- name: Wait for Garage to be ready
|
|
run: |
|
|
timeout 30 sh -c 'until docker exec garage /garage health; do sleep 1; done'
|
|
|
|
- name: Install Python
|
|
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7.6.0
|
|
- name: Install the dependencies
|
|
run: uv sync --locked --all-extras
|
|
|
|
- name: Install gettext (required to compile messages)
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y gettext
|
|
|
|
- name: Generate a MO file from strings extracted from the project
|
|
run: uv run --no-sync --no-build python manage.py compilemessages
|
|
|
|
- name: Run tests
|
|
run: uv run --no-sync --no-build pytest -n 2
|
|
|
|
test-summary:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/summary
|
|
|
|
env:
|
|
AUTHORIZED_TENANTS: '[{"id": "test-tenant", "api_key": "test-api-token", "webhook_url": "https://example.com/webhook", "webhook_api_key": "test-webhook-api-key"}]'
|
|
AWS_STORAGE_BUCKET_NAME: "http://meet-media-storage"
|
|
AWS_S3_ENDPOINT_URL: "garage:9000"
|
|
AWS_S3_ACCESS_KEY_ID: "meet-access-key"
|
|
AWS_S3_SECRET_ACCESS_KEY: "meet-secret-access-key"
|
|
WHISPERX_BASE_URL: "https://configure-your-url.com"
|
|
WHISPERX_ASR_MODEL: "large-v2"
|
|
WHISPERX_API_KEY: "test-whisperx-secret"
|
|
WHISPERX_DEFAULT_LANGUAGE: "fr"
|
|
LLM_BASE_URL: "https://configure-your-url.com"
|
|
LLM_API_KEY: "test-llm-secret"
|
|
LLM_MODEL: "test-llm-model"
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
|
|
- name: Install ffmpeg
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y ffmpeg
|
|
|
|
- name: Install Python
|
|
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7.6.0
|
|
|
|
- name: Install the project
|
|
run: uv sync --locked --all-extras
|
|
|
|
- name: Run summary tests
|
|
run: uv run --no-sync --no-build pytest
|
|
|
|
lint-front:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
|
|
- name: Install dependencies
|
|
run: cd src/frontend/ && npm ci --ignore-scripts
|
|
|
|
- name: Check linting
|
|
run: cd src/frontend/ && npm run lint
|
|
|
|
- name: Check format
|
|
run: cd src/frontend/ && npm run check
|
|
|
|
lint-sdk:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/sdk/library
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
|
|
- name: Install dependencies
|
|
run: npm ci --ignore-scripts
|
|
|
|
- name: Check linting
|
|
run: npm run lint
|
|
|
|
- name: Check format
|
|
run: npm run check
|
|
|
|
build-sdk:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
needs: lint-sdk
|
|
defaults:
|
|
run:
|
|
working-directory: src/sdk/library
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
|
|
- name: Install dependencies
|
|
run: npm ci --ignore-scripts
|
|
|
|
- name: Build SDK
|
|
run: npm run build
|