shoc-backend/.github/workflows/ci.yml
2026-09-28 19:28:25 +00:00

116 lines
3.5 KiB
YAML

name: Backend CI
on:
pull_request:
# The merge queue builds main plus the queued pull requests on a temporary
# branch and only counts checks that ran on the merge_group event.
merge_group:
push:
branches: [main]
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
build-and-test:
name: Build and test
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Checkout
uses: actions/checkout@v7.0.1
- name: Set up .NET
uses: actions/setup-dotnet@v6
with:
dotnet-version: "8.0.x"
- name: Cache NuGet packages
uses: actions/cache@v4.3.0
with:
path: ~/.nuget/packages
key: nuget-${{ runner.os }}-${{ hashFiles('**/*.csproj', '**/*.props') }}
restore-keys: |
nuget-${{ runner.os }}-
- name: Restore
run: dotnet restore SeaHavenIndustries.sln
- name: Build
run: dotnet build SeaHavenIndustries.sln --no-restore --configuration Release
- name: Test
run: dotnet test SeaHavenIndustries.sln --no-build --configuration Release
architecture:
name: architecture
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Checkout
uses: actions/checkout@v7.0.1
with:
fetch-depth: 0
- name: Set up .NET
uses: actions/setup-dotnet@v6
with:
dotnet-version: "8.0.x"
- name: Cache NuGet packages
uses: actions/cache@v4.3.0
with:
path: ~/.nuget/packages
key: nuget-${{ runner.os }}-${{ hashFiles('**/*.csproj', '**/*.props') }}
restore-keys: |
nuget-${{ runner.os }}-
- name: Set up Terraform
uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1
with:
terraform_version: "1.9.8"
terraform_wrapper: false
- name: Repository quality gate
shell: bash
env:
GOVERNANCE_SKIP_BUILD_TEST: "1"
# A merge group carries its own base and head; github.event.before is
# empty on that event.
BASE_REF: ${{ github.event.pull_request.base.sha || github.event.merge_group.base_sha || github.event.before }}
HEAD_REF: ${{ github.event.pull_request.head.sha || github.event.merge_group.head_sha || github.sha }}
run: bash scripts/governance-check.sh
review:
name: review
if: github.event_name != 'push'
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19
ci-complete:
name: ci-complete
if: always()
needs: [build-and-test, architecture, review]
runs-on: ubuntu-latest
steps:
- name: All required jobs passed
shell: bash
env:
BUILD: ${{ needs.build-and-test.result }}
ARCH: ${{ needs.architecture.result }}
REVIEW: ${{ needs.review.result }}
run: |
set -euo pipefail
if [[ "${BUILD}" != "success" || "${ARCH}" != "success" ]]; then
echo "Build and test or architecture did not succeed: build=${BUILD} architecture=${ARCH}"
exit 1
fi
# review is skipped on push to main; it must succeed on pull_request
# and merge_group.
if [[ "${REVIEW}" != "success" && "${REVIEW}" != "skipped" ]]; then
echo "review did not succeed: ${REVIEW}"
exit 1
fi