Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 3 additions & 4 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,5 @@
# Custom labels for the org's self-hosted runner farm (tootie-ci-runner-1..4),
# so actionlint (run by the Workflow and dependency policy check) accepts
# runs-on entries like [self-hosted, unraid].
self-hosted-runner:
labels:
- unraid
- ci-pool-typescript
- ci-pool-ops
- residential-egress
174 changes: 64 additions & 110 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,132 +5,86 @@ on:
push:
branches: [main]

permissions: {}
permissions:
contents: read

concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
contract:
uses: dinglebear-ai/workflows/.github/workflows/fleet-contract.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d
with:
profile: node
implementation-ref: 66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d

policy:
name: Workflow and dependency policy
runs-on: ubuntu-latest
permissions:
contents: read
uses: dinglebear-ai/workflows/.github/workflows/fast-ops.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d
with:
shell-globs: "ops/*.sh"
policy-command: >-
ops/check-action-pins.sh &&
ops/check-production-topology.sh &&
node scripts/sync-agent-skill.mjs --check &&
ops/check-skill-sync.sh

gradle-wrapper:
name: Gradle wrapper
runs-on: [self-hosted, ci-pool-ops]
timeout-minutes: 5
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Require immutable action references
run: ops/check-action-pins.sh
- name: Validate workflow syntax
uses: docker://rhysd/actionlint@sha256:ef8299f97635c4c30e2298f48f30763ab782a4ad2c95b744649439a039421e36 # 1.7.10
- name: Validate Gradle wrapper
uses: gradle/actions/wrapper-validation@3f131e8634966bd73d06cc69884922b02e6faf92 # v6.2.0
- name: Validate deployment topology
run: ops/check-production-topology.sh
- name: Validate operations shell
run: shellcheck ops/*.sh
- name: Validate generated skill documentation
run: node scripts/sync-agent-skill.mjs --check && ops/check-skill-sync.sh
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
with:
persist-credentials: false
- uses: gradle/actions/wrapper-validation@3f131e8634966bd73d06cc69884922b02e6faf92 # v6

osv:
dependencies:
name: OSV dependency scan
runs-on: ubuntu-latest
runs-on: [self-hosted, ci-pool-typescript]
timeout-minutes: 10
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- uses: google/osv-scanner-action/osv-scanner-action@9a498708959aeaef5ef730655706c5a1df1edbc2 # v2.3.8
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
with:
persist-credentials: false
- uses: google/osv-scanner-action/osv-scanner-action@9a498708959aeaef5ef730655706c5a1df1edbc2 # v2
with:
scan-args: |-
--lockfile=pnpm-lock.yaml
scan-args: --lockfile=pnpm-lock.yaml

web:
name: Web, registry, and standalone
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4
with:
version: 10.33.2
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
cache: pnpm
- name: Cache Next.js build
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: .next/cache
key: nextjs-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml', 'next.config.*', 'proxy.ts') }}
restore-keys: nextjs-${{ runner.os }}-
- run: pnpm install --frozen-lockfile
- run: pnpm run lint
- run: pnpm run audit:composition
- run: pnpm exec tsc --noEmit
- run: pnpm run test:unit
- run: pnpm run test:coverage
- name: Build the tested revision
env:
AURORA_BUILD_SHA: ${{ github.sha }}
run: pnpm run build
- name: Enforce production client JavaScript budgets
run: pnpm run performance:check
- name: Install Playwright Chromium, Firefox, and WebKit
run: pnpm exec playwright install --with-deps chromium firefox webkit
- name: Cross-browser, mobile, and strict Storybook accessibility contracts
run: pnpm run test:e2e
- run: pnpm run refs:check
- run: pnpm run audit:standalone
- name: Smoke production security and cache headers
env:
AURORA_BUILD_SHA: ${{ github.sha }}
run: ops/smoke-production.sh
- run: pnpm run registry:check
- run: pnpm run registry:validate
- run: pnpm run registry:graph
- run: pnpm run registry:smoke
- run: pnpm run gallery:check
- run: pnpm run catalog:check
- run: pnpm run tokens:generate
- name: Generated artifacts are committed
run: git diff --exit-code
uses: dinglebear-ai/workflows/.github/workflows/fast-pnpm.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d
with:
node-version: "24"
pnpm-version: "10.33.2"
audit-command: pnpm audit --audit-level high
lint-command: pnpm run lint
typecheck-command: pnpm exec tsc --noEmit
test-command: pnpm run test:coverage
contract-command: >-
pnpm run audit:composition &&
pnpm run refs:check &&
pnpm run audit:standalone &&
pnpm run registry:check &&
pnpm run registry:validate &&
pnpm run registry:graph &&
pnpm run registry:smoke &&
pnpm run gallery:check &&
pnpm run catalog:check &&
pnpm run tokens:generate &&
git diff --exit-code
timeout-minutes: 25

android:
name: Android app and library variants
runs-on: ubuntu-latest
permissions:
contents: read
gate:
name: CI
if: always()
needs: [contract, policy, gradle-wrapper, dependencies, web]
runs-on: [self-hosted, ci-pool-ops]
timeout-minutes: 2
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4
with:
version: 10.33.2
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
cache: pnpm
- uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4
with:
distribution: temurin
java-version: "21"
- name: Cache Gradle wrapper and caches
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
~/.gradle/wrapper
~/.gradle/caches
key: gradle-${{ runner.os }}-${{ hashFiles('android/**/*.gradle*', 'android/gradle/wrapper/gradle-wrapper.properties') }}
restore-keys: gradle-${{ runner.os }}-
- run: pnpm install --frozen-lockfile
- name: Gate all app/library variants, release lint/package, wrapper, and Roborazzi goldens
run: ./gradlew androidCheck --no-daemon
working-directory: android
- name: Run Android managed-device instrumentation smoke
run: |
if [[ -e /dev/kvm ]]; then sudo chmod 666 /dev/kvm; fi
./gradlew androidManagedDeviceCheck --no-daemon
working-directory: android
- name: Smoke external composite-build consumption
run: ops/smoke-android-composite.sh
- name: Require every fast lane
env:
RESULTS: ${{ join(needs.*.result, ' ') }}
run: test "$RESULTS" = "success success success success success"
156 changes: 76 additions & 80 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
@@ -1,92 +1,88 @@
name: Publish image
name: Release artifacts

on:
workflow_run:
workflows: ["CI"]
types: [completed]
branches: [main]
release:
types: [published]

permissions: {}

concurrency:
group: publish-tested-main
group: aurora-release-${{ github.event.release.tag_name }}
cancel-in-progress: false

jobs:
publish:
name: Publish tested SHA and promote its verified digest
if: >-
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'push' &&
github.event.workflow_run.head_branch == 'main'
runs-on: ubuntu-latest
web:
permissions:
contents: read
uses: dinglebear-ai/workflows/.github/workflows/hosted-web-release.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d
with:
checkout-ref: ${{ github.event.release.tag_name }}
node-version: "24"
package-cache: pnpm
pnpm-version: "10.33.2"
cache-dependency-path: pnpm-lock.yaml
install-command: pnpm install --frozen-lockfile
coverage-command: pnpm run test:coverage
build-command: >-
AURORA_BUILD_SHA=${{ github.sha }}
pnpm run build
performance-command: pnpm run performance:check
e2e-command: pnpm run test:e2e
artifact-name: aurora-web-${{ github.event.release.tag_name }}
artifact-path: .next/standalone
diagnostic-path: |
playwright-report/
test-results/
timeout-minutes: 60

android:
permissions:
contents: read
uses: dinglebear-ai/workflows/.github/workflows/hosted-android-release.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d
with:
checkout-ref: ${{ github.event.release.tag_name }}
java-version: "21"
working-directory: android
setup-command: >-
corepack enable &&
corepack prepare pnpm@10.33.2 --activate &&
pnpm --dir .. install --frozen-lockfile
release-command: ./gradlew androidCheck --no-daemon
device-command: |
if [[ -e /dev/kvm ]]; then sudo chmod 666 /dev/kvm; fi
./gradlew androidManagedDeviceCheck --no-daemon
../ops/smoke-android-composite.sh
artifact-name: aurora-android-${{ github.event.release.tag_name }}
artifact-path: android/**/build/outputs/**
report-path: android/**/build/reports/**
timeout-minutes: 90

container:
permissions:
contents: read
packages: write
env:
# Derived, not hard-coded: this was left pointing at ghcr.io/jmagar/aurora
# after the repository moved to dinglebear-ai, and GITHUB_TOKEN cannot push
# to a package in another account's namespace.
IMAGE: ghcr.io/${{ github.repository }}
TESTED_SHA: ${{ github.event.workflow_run.head_sha }}
steps:
- name: Check out the exact tested revision
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
ref: ${{ github.event.workflow_run.head_sha }}
persist-credentials: false
- name: Prove checkout identity
run: test "$(git rev-parse HEAD)" = "$TESTED_SHA"
- name: Log in to GHCR
uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4.4.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Set up Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
- name: Build and push immutable SHA tag with provenance and SBOM attestations
id: build
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
target: runner
push: true
tags: ${{ env.IMAGE }}:sha-${{ env.TESTED_SHA }}
labels: |
org.opencontainers.image.source=https://github.com/${{ github.repository }}
org.opencontainers.image.revision=${{ env.TESTED_SHA }}
build-args: AURORA_BUILD_SHA=${{ env.TESTED_SHA }}
provenance: false
sbom: false
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Record tested image identity
env:
DIGEST: ${{ steps.build.outputs.digest }}
run: |
test -n "$DIGEST"
printf '%s\n' "$IMAGE@$DIGEST" > image-ref.txt
printf '%s\n' "$TESTED_SHA" > source-sha.txt
- name: Scan the exact digest before promotion
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
with:
image-ref: ${{ env.IMAGE }}@${{ steps.build.outputs.digest }}
version: v0.72.0
format: table
severity: CRITICAL,HIGH
ignore-unfixed: true
exit-code: "1"
- name: Promote only the scanned digest to latest
env:
DIGEST: ${{ steps.build.outputs.digest }}
run: docker buildx imagetools create --tag "$IMAGE:latest" "$IMAGE@$DIGEST"
- name: Upload promotion evidence
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: aurora-image-${{ env.TESTED_SHA }}
path: |
image-ref.txt
source-sha.txt
if-no-files-found: error
retention-days: 90
attestations: write
id-token: write
uses: dinglebear-ai/workflows/.github/workflows/hosted-container-release.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d
with:
checkout-ref: ${{ github.event.release.tag_name }}
image: ghcr.io/${{ github.repository }}
release-tag: ${{ github.event.release.tag_name }}
build-args: AURORA_BUILD_SHA=${{ github.sha }}
smoke-command: |
set -euo pipefail
name="aurora-release-smoke-${GITHUB_RUN_ID}"
trap 'docker rm -f "$name" >/dev/null 2>&1 || true' EXIT
docker run -d --name "$name" -p 127.0.0.1::3000 "$IMAGE_REF" >/dev/null
port="$(docker port "$name" 3000/tcp | awk -F: '{print $NF}')"
for _ in {1..45}; do
curl --fail --silent "http://127.0.0.1:${port}/" >/dev/null && exit 0
sleep 2
done
docker logs "$name"
exit 1
cache-scope: aurora-release
timeout-minutes: 60
secrets:
REGISTRY_USERNAME: ${{ github.actor }}
REGISTRY_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Loading
Loading