name: Build check (reusable) # `docker build` + in-image test check for ONE app domain, reused via # `uses:` by pr-build.yml and the deploy-dev workflows -- the monorepo port of # each app repo's build.yml. Still deliberately NOT a live boot+healthz check: # that was tried in the split repos and repeatedly hit this runner's own # environment quirks (bridge-IP reachability, non-unique $$, squatted host # ports) without ever going reliably green. Image boot is verified by hand # instead (docker run + alembic + /healthz 200 + a real /api/v2/place 200). # # Monorepo port: the domain (backend|frontend) arrives as a workflow_call # input, and the build CONTEXT is that domain's subdirectory -- so each # Dockerfile sees exactly the tree it saw when its domain was a repo root, # byte-for-byte the same build as the split era. on: workflow_call: inputs: domain: description: "App domain to build: backend | frontend" required: true type: string jobs: build: runs-on: docker steps: - uses: actions/checkout@v4 - name: Install Docker CLI run: | apt-get update -qq apt-get install -y -qq docker.io - name: Build run: docker build -t thermograph-${{ inputs.domain }}:ci ${{ inputs.domain }}/ # Run the hermetic test tier INSIDE the image we just built (the backend # image ships tests/ + every runtime dep via COPY . /app/): the exact # interpreter/deps that ship, none of the runner-environment quirks that # sank the old host-side boot check. Backend only: the frontend image is # a Go binary with no interpreter or toolchain to test with -- its vet + # test suite runs in frontend/Dockerfile's builder stage instead, so the # Build step above already fails when the Go tests do; its integration # tier (needs a live backend container) stays a local `make`/scripts # concern, see frontend/scripts/backend-for-tests.sh. # requirements-dev only layers pytest on top, so the install is tiny. # -u 0: the image's default user can't write to site-packages. # --entrypoint sh: backend's entrypoint is alembic-migrate + uvicorn -- # without the override the test command is swallowed as entrypoint args # and the container just boots the server forever. unset # THERMOGRAPH_BASE: the image bakes the prod root-mount (/), which moves # every route off the /thermograph prefix the tests are written against. - name: Run tests in the built image (backend only) if: inputs.domain == 'backend' run: | docker run --rm -u 0 --entrypoint sh thermograph-backend:ci \ -c "unset THERMOGRAPH_BASE; pip install -q --no-cache-dir pytest==8.4.1 && python -m pytest tests -q"