Skip to content

DM-47760: Allow internal tokens on the OIDC userinfo route #4132

DM-47760: Allow internal tokens on the OIDC userinfo route

DM-47760: Allow internal tokens on the OIDC userinfo route #4132

Workflow file for this run

name: CI
env:
# Current supported Python version. For applications, there is generally no
# reason to support multiple Python versions, so all actions are run with
# this version. Quote the version to avoid interpretation as a floating
# point number.
PYTHON_VERSION: "3.12"
"on":
merge_group: {}
pull_request: {}
push:
branches-ignore:
# These should always correspond to pull requests, so ignore them for
# the push trigger and let them be triggered by the pull_request
# trigger, avoiding running the workflow twice. This is a minor
# optimization so there's no need to ensure this is comprehensive.
- "dependabot/**"
- "gh-readonly-queue/**"
- "renovate/**"
- "tickets/**"
- "u/**"
tags:
- "*"
jobs:
ui:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@v4
- name: Set up Node
uses: actions/setup-node@v4
with:
node-version-file: .nvmrc
cache: npm
cache-dependency-path: ui/package-lock.json
- name: Read .nvmrc
id: node_version
run: echo NODE_VERSION="$(cat .nvmrc)" >> $GITHUB_OUTPUT
# First try to restore the fully-installed node modules. If that works
# (no changes to the JavaScript layer), skip npm i and restoring the
# cache of downloaded modules. If that fails, restore the cache of the
# downloaded modules and then run npm clean-install.
- name: Cache installed Node modules
uses: actions/cache@v4
id: node-cache
with:
path: ./ui/node_modules
key: node-${{ steps.node_version.outputs.NODE_VERSION }}-${{ hashFiles('**/package-lock.json') }}
# --legacy-peer-deps is currently required because react-aria-modal
# hasn't been updated for the latest React.
- name: Install Node dependencies
run: npm ci --legacy-peer-deps
if: steps.node-cache.outputs.cache-hit != 'true'
working-directory: ./ui
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: ${{ env.PYTHON_VERSION }}
# This has to happen after installing Node modules because we run eslint
# and it wants react to be already installed. We therefore do all the
# linting here instead of during the test job.
- name: Run pre-commit
uses: pre-commit/action@v3.0.1
- name: Build the UI
run: npm run build
working-directory: ./ui
# Cache the built web UI in a build artifact so that it can be used by
# both the test job and the docker job. We only use this artifact
# internally in this workflow, so only keep it for a day, not the full
# 90 day default.
- name: Cache UI artifact
uses: actions/upload-artifact@v4
with:
name: ui
path: ui/public
retention-days: 1
test:
runs-on: ubuntu-latest
needs: [ui]
timeout-minutes: 15
steps:
- uses: actions/checkout@v4
# Reuse the built UI from the ui job.
- name: Restore UI artifact
uses: actions/download-artifact@v4
with:
name: ui
path: ui/public
- name: Update package lists
run: sudo apt-get update
- name: Install extra packages
run: sudo apt install -y libpq-dev libldap2-dev libsasl2-dev
- name: Set up Minikube
uses: medyagh/setup-minikube@v0.0.18
with:
kubernetes-version: "v1.27.3"
- uses: lsst-sqre/run-tox@v1
with:
python-version: ${{ env.PYTHON_VERSION }}
tox-envs: "typing,py-full,coverage-report"
tox-requirements: "requirements/tox.txt"
cache-key-prefix: test
docs:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@v4
with:
# Ensure the documentation gets the right version.
fetch-depth: 0
- name: Filter paths
uses: dorny/paths-filter@v3
id: filter
with:
filters: |
docs:
- "docs/**"
- name: Update package lists
run: sudo apt-get update
- name: Install extra packages
run: sudo apt install -y graphviz libpq-dev libldap2-dev libsasl2-dev
- uses: lsst-sqre/run-tox@v1
with:
python-version: ${{ env.PYTHON_VERSION }}
tox-envs: docs
tox-requirements: "requirements/tox.txt"
cache-key-prefix: docs
# Only attempt documentation uploads for long-lived branches, tagged
# releases, and pull requests from ticket branches. This avoids version
# clutter in the docs and failures when a PR doesn't have access to
# secrets.
- uses: lsst-sqre/ltd-upload@v1
with:
project: gafaelfawr
dir: "docs/_build/html"
username: ${{ secrets.LTD_USERNAME }}
password: ${{ secrets.LTD_PASSWORD }}
if: >
github.event_name != 'merge_group'
&& (github.event_name != 'pull_request'
|| (startsWith(github.head_ref, 'tickets/')
&& steps.filter.outputs.docs == 'true'))
linkcheck:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@v4
- name: Update package lists
run: sudo apt-get update
- name: Install extra packages
run: sudo apt install -y graphviz libpq-dev libldap2-dev libsasl2-dev
- name: Check links
uses: lsst-sqre/run-tox@v1
with:
python-version: ${{ env.PYTHON_VERSION }}
tox-envs: docs-linkcheck
tox-requirements: "requirements/tox.txt"
build:
runs-on: ubuntu-latest
needs: [test]
timeout-minutes: 10
# Only do Docker builds of tagged releases and pull requests from ticket
# branches. This will still trigger on pull requests from untrusted
# repositories whose branch names match our tickets/* branch convention,
# but in this case the build will fail with an error since the secret
# won't be set.
if: >
github.event_name != 'merge_group'
&& (startsWith(github.ref, 'refs/tags/')
|| startsWith(github.head_ref, 'tickets/'))
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
# Reuse the built UI from the ui job.
- name: Restore UI artifact
uses: actions/download-artifact@v4
with:
name: ui
path: ui/public
- uses: lsst-sqre/build-and-push-to-ghcr@v1
id: build
with:
image: ${{ github.repository }}
github_token: ${{ secrets.GITHUB_TOKEN }}