From 90a7148165e9cbd5271d4b539993ab2493aa2534 Mon Sep 17 00:00:00 2001 From: emi Date: Thu, 23 Jul 2026 00:59:03 +0000 Subject: [PATCH] CI: run the test suite inside the built image (#4) --- .forgejo/workflows/build.yml | 24 +++++++++++++++++++++--- .forgejo/workflows/deploy.yml | 5 ++--- 2 files changed, 23 insertions(+), 6 deletions(-) diff --git a/.forgejo/workflows/build.yml b/.forgejo/workflows/build.yml index 6701686..64989cd 100644 --- a/.forgejo/workflows/build.yml +++ b/.forgejo/workflows/build.yml @@ -9,9 +9,9 @@ name: Build check # the runner's shared capacity=2 contention) without ever settling into a # reliably green check. The image DOES boot correctly standalone -- # independently verified by hand: `docker run` + real alembic migrations + -# `/healthz` returning 200 + a real `/api/v2/place` 200. Full pytest-suite -# migration is separate, deferred follow-up work too, same category as -# thermograph-copy's deferred vendoring. +# `/healthz` returning 200 + a real `/api/v2/place` 200. The full pytest +# suite DOES run here now -- inside the built image (see the test step below), +# which sidesteps those runner quirks entirely. on: # Reusable (uses: ./.forgejo/workflows/build.yml) by pr-build.yml and @@ -38,3 +38,21 @@ jobs: - name: Build run: docker build -t thermograph-backend:ci . + + # The suite is hermetic (sqlite/tmpdir; no network), and the image already + # contains tests/ + every runtime dep (COPY . /app/), so run pytest INSIDE + # the image we just built: the exact interpreter/deps that ship, none of + # the runner-environment quirks that sank the old host-side boot check. + # requirements-dev.txt only layers pytest on top, so the install is tiny. + # -u 0: the image's default user can't write to site-packages. + # --entrypoint sh: the image's entrypoint is alembic-migrate + uvicorn; + # without the override the test command is swallowed as entrypoint args + # and the container just boots the server forever. unset THERMOGRAPH_BASE: + # the image bakes the prod root-mount (/), which moves every route off the + # /thermograph prefix the tests are written against -- requests would fall + # through to the frontend-proxy catch-all and fail with ConnectError. + - name: Run tests in the built image + run: | + docker run --rm -u 0 --entrypoint sh thermograph-backend:ci \ + -c "unset THERMOGRAPH_BASE; pip install -q --no-cache-dir pytest==8.4.1 && python -m pytest tests -q" + diff --git a/.forgejo/workflows/deploy.yml b/.forgejo/workflows/deploy.yml index 217734f..8af668b 100644 --- a/.forgejo/workflows/deploy.yml +++ b/.forgejo/workflows/deploy.yml @@ -7,9 +7,8 @@ name: Deploy backend to beta VPS # versa. thermograph-infra/deploy/deploy.sh persists each service's live tag # host-side, so a single-service roll never disturbs the other. # -# The SSH_HOST/USER/KEY/PORT secrets point at beta. Prod is NOT deployed by a -# workflow -- it's deployed with `terraform apply` on the `release` branch, so -# there is deliberately no release-triggered workflow. appleboy/ssh-action is +# The SSH_HOST/USER/KEY/PORT secrets point at beta. Prod deploys the same way +# from deploy-prod.yml (release branch, PROD_SSH_* secrets). appleboy/ssh-action is # referenced by full GitHub URL because it isn't mirrored in Forgejo's default # action registry. #