Initial commit
This commit is contained in:
@@ -0,0 +1,49 @@
|
||||
---
|
||||
name: Ansible Lint
|
||||
on: # yamllint disable-line rule:truthy
|
||||
pull_request:
|
||||
merge_group:
|
||||
branches:
|
||||
- main
|
||||
types:
|
||||
- checks_requested
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
env:
|
||||
LSR_ROLE2COLL_NAMESPACE: fedora
|
||||
LSR_ROLE2COLL_NAME: linux_system_roles
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
ansible_lint:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Update pip, git
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
sudo apt update
|
||||
sudo apt install -y git
|
||||
|
||||
- name: Checkout repo
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Install tox, tox-lsr
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
pip3 install "git+https://github.com/linux-system-roles/tox-lsr@3.4.0"
|
||||
|
||||
- name: Convert role to collection format
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
TOXENV=collection lsr_ci_runtox
|
||||
coll_dir=".tox/ansible_collections/$LSR_ROLE2COLL_NAMESPACE/$LSR_ROLE2COLL_NAME"
|
||||
# ansible-lint action requires a .git directory???
|
||||
# https://github.com/ansible/ansible-lint/blob/main/action.yml#L45
|
||||
mkdir -p "$coll_dir/.git"
|
||||
|
||||
- name: Run ansible-lint
|
||||
uses: ansible/ansible-lint@v24
|
||||
with:
|
||||
working_directory: ${{ github.workspace }}/.tox/ansible_collections/${{ env.LSR_ROLE2COLL_NAMESPACE }}/${{ env.LSR_ROLE2COLL_NAME }}
|
||||
@@ -0,0 +1,38 @@
|
||||
---
|
||||
name: Check for ansible_managed variable use in comments
|
||||
on: # yamllint disable-line rule:truthy
|
||||
pull_request:
|
||||
merge_group:
|
||||
branches:
|
||||
- main
|
||||
types:
|
||||
- checks_requested
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
ansible_managed_var_comment:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Update pip, git
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
python3 -m pip install --upgrade pip
|
||||
sudo apt update
|
||||
sudo apt install -y git
|
||||
|
||||
- name: Checkout repo
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Install tox, tox-lsr
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
pip3 install "git+https://github.com/linux-system-roles/tox-lsr@3.4.0"
|
||||
|
||||
- name: Run ansible-plugin-scan
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
TOXENV=ansible-managed-var-comment lsr_ci_runtox
|
||||
@@ -0,0 +1,38 @@
|
||||
---
|
||||
name: Ansible Plugin Scan
|
||||
on: # yamllint disable-line rule:truthy
|
||||
pull_request:
|
||||
merge_group:
|
||||
branches:
|
||||
- main
|
||||
types:
|
||||
- checks_requested
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
ansible_plugin_scan:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Update pip, git
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
python3 -m pip install --upgrade pip
|
||||
sudo apt update
|
||||
sudo apt install -y git
|
||||
|
||||
- name: Checkout repo
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Install tox, tox-lsr
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
pip3 install "git+https://github.com/linux-system-roles/tox-lsr@3.4.0"
|
||||
|
||||
- name: Run ansible-plugin-scan
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
TOXENV=ansible-plugin-scan lsr_ci_runtox
|
||||
@@ -0,0 +1,48 @@
|
||||
---
|
||||
name: Ansible Test
|
||||
on: # yamllint disable-line rule:truthy
|
||||
pull_request:
|
||||
merge_group:
|
||||
branches:
|
||||
- main
|
||||
types:
|
||||
- checks_requested
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
env:
|
||||
LSR_ROLE2COLL_NAMESPACE: fedora
|
||||
LSR_ROLE2COLL_NAME: linux_system_roles
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
ansible_test:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Update pip, git
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
python3 -m pip install --upgrade pip
|
||||
sudo apt update
|
||||
sudo apt install -y git
|
||||
|
||||
- name: Checkout repo
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Install tox, tox-lsr
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
pip3 install "git+https://github.com/linux-system-roles/tox-lsr@3.4.0"
|
||||
|
||||
- name: Convert role to collection format
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
TOXENV=collection lsr_ci_runtox
|
||||
|
||||
- name: Run ansible-test
|
||||
uses: ansible-community/ansible-test-gh-action@release/v1
|
||||
with:
|
||||
testing-type: sanity # wokeignore:rule=sanity
|
||||
ansible-core-version: stable-2.17
|
||||
collection-src-directory: ${{ github.workspace }}/.tox/ansible_collections/${{ env.LSR_ROLE2COLL_NAMESPACE }}/${{ env.LSR_ROLE2COLL_NAME }}
|
||||
@@ -0,0 +1,104 @@
|
||||
---
|
||||
# yamllint disable rule:line-length
|
||||
name: Convert README.md to HTML and push to docs branch
|
||||
on: # yamllint disable-line rule:truthy
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- README.md
|
||||
release:
|
||||
types:
|
||||
- published
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
build_docs:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- name: Update pip, git
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
sudo apt update
|
||||
sudo apt install -y git
|
||||
|
||||
- name: Check out code
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
- name: Ensure the docs branch
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
branch=docs
|
||||
existed_in_remote=$(git ls-remote --heads origin $branch)
|
||||
|
||||
if [ -z "${existed_in_remote}" ]; then
|
||||
echo "Creating $branch branch"
|
||||
git config --global user.name "${{ github.actor }}"
|
||||
git config --global user.email "${{ github.actor }}@users.noreply.github.com"
|
||||
git checkout --orphan $branch
|
||||
git reset --hard
|
||||
git commit --allow-empty -m "Initializing $branch branch"
|
||||
git push origin $branch
|
||||
echo "Created $branch branch"
|
||||
else
|
||||
echo "Branch $branch already exists"
|
||||
fi
|
||||
|
||||
- name: Checkout the docs branch
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: docs
|
||||
|
||||
- name: Fetch README.md and .pandoc_template.html5 template from the workflow branch
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
sparse-checkout: |
|
||||
README.md
|
||||
.pandoc_template.html5
|
||||
sparse-checkout-cone-mode: false
|
||||
path: ref_branch
|
||||
- name: Set RELEASE_VERSION based on whether run on release or on push
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
if [ ${{ github.event_name }} = release ]; then
|
||||
echo "RELEASE_VERSION=${{ github.event.release.tag_name }}" >> $GITHUB_ENV
|
||||
elif [ ${{ github.event_name }} = push ]; then
|
||||
echo "RELEASE_VERSION=latest" >> $GITHUB_ENV
|
||||
else
|
||||
echo Unsupported event
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Ensure that version and docs directories exist
|
||||
run: mkdir -p ${{ env.RELEASE_VERSION }} docs
|
||||
|
||||
- name: Remove badges from README.md prior to converting to HTML
|
||||
run: sed -i '1,8 {/^\[\!.*actions\/workflows/d}' ref_branch/README.md
|
||||
|
||||
- name: Convert README.md to HTML and save to the version directory
|
||||
uses: docker://pandoc/core:latest
|
||||
with:
|
||||
args: >-
|
||||
--from gfm --to html5 --toc --shift-heading-level-by=-1
|
||||
--template ref_branch/.pandoc_template.html5
|
||||
--output ${{ env.RELEASE_VERSION }}/README.html ref_branch/README.md
|
||||
|
||||
- name: Copy latest README.html to docs/index.html for GitHub pages
|
||||
if: env.RELEASE_VERSION == 'latest'
|
||||
run: cp ${{ env.RELEASE_VERSION }}/README.html docs/index.html
|
||||
|
||||
- name: Commit changes
|
||||
run: |
|
||||
git config --global user.name "${{ github.actor }}"
|
||||
git config --global user.email "${{ github.actor }}@users.noreply.github.com"
|
||||
git add ${{ env.RELEASE_VERSION }}/README.html docs/index.html
|
||||
git commit -m "Update README.html for ${{ env.RELEASE_VERSION }}"
|
||||
|
||||
- name: Push changes
|
||||
uses: ad-m/github-push-action@master
|
||||
with:
|
||||
github_token: ${{ secrets.GITHUB_TOKEN }}
|
||||
branch: docs
|
||||
@@ -0,0 +1,91 @@
|
||||
---
|
||||
# yamllint disable rule:line-length
|
||||
name: Tag, release, and publish role based on CHANGELOG.md push
|
||||
on: # yamllint disable-line rule:truthy
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- CHANGELOG.md
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
tag_release_publish:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- name: Update pip, git
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
sudo apt update
|
||||
sudo apt install -y git
|
||||
|
||||
- name: checkout PR
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Get tag and message from the latest CHANGELOG.md commit
|
||||
id: tag
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
print=false
|
||||
while read -r line; do
|
||||
if [[ "$line" =~ ^\[([0-9]+\.[0-9]+\.[0-9]+)\]\ -\ [0-9-]+ ]]; then
|
||||
if [ "$print" = false ]; then
|
||||
_tagname="${BASH_REMATCH[1]}"
|
||||
echo "$line"
|
||||
print=true
|
||||
else
|
||||
break
|
||||
fi
|
||||
elif [ "$print" = true ]; then
|
||||
echo "$line"
|
||||
fi
|
||||
done < CHANGELOG.md > ./.tagmsg.txt
|
||||
git fetch --all --tags
|
||||
for t in $( git tag -l ); do
|
||||
if [ "$t" = "$_tagname" ]; then
|
||||
echo INFO: tag "$t" already exists
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
# Get name of the branch that the change was pushed to
|
||||
_branch="${GITHUB_REF_NAME:-}"
|
||||
if [ "$_branch" = master ] || [ "$_branch" = main ]; then
|
||||
echo Using branch name ["$_branch"] as push branch
|
||||
else
|
||||
echo WARNING: GITHUB_REF_NAME ["$_branch"] is not main or master
|
||||
_branch=$( git branch -r | grep -o 'origin/HEAD -> origin/.*$' | \
|
||||
awk -F'/' '{print $3}' || : )
|
||||
fi
|
||||
if [ -z "$_branch" ]; then
|
||||
_branch=$( git branch --points-at HEAD --no-color --format='%(refname:short)' )
|
||||
fi
|
||||
if [ -z "$_branch" ]; then
|
||||
echo ERROR: unable to determine push branch
|
||||
git branch -a
|
||||
exit 1
|
||||
fi
|
||||
echo "tagname=$_tagname" >> "$GITHUB_OUTPUT"
|
||||
echo "branch=$_branch" >> "$GITHUB_OUTPUT"
|
||||
- name: Create tag
|
||||
uses: mathieudutour/github-tag-action@v6.2
|
||||
with:
|
||||
github_token: ${{ secrets.GITHUB_TOKEN }}
|
||||
custom_tag: ${{ steps.tag.outputs.tagname }}
|
||||
tag_prefix: ''
|
||||
|
||||
- name: Create Release
|
||||
id: create_release
|
||||
uses: ncipollo/release-action@v1
|
||||
with:
|
||||
tag: ${{ steps.tag.outputs.tagname }}
|
||||
name: Version ${{ steps.tag.outputs.tagname }}
|
||||
bodyFile: ./.tagmsg.txt
|
||||
makeLatest: true
|
||||
|
||||
- name: Publish role to Galaxy
|
||||
uses: robertdebock/galaxy-action@1.2.1
|
||||
with:
|
||||
galaxy_api_key: ${{ secrets.galaxy_api_key }}
|
||||
git_branch: ${{ steps.tag.outputs.branch }}
|
||||
@@ -0,0 +1,38 @@
|
||||
---
|
||||
# yamllint disable rule:line-length
|
||||
name: Markdown Lint
|
||||
on: # yamllint disable-line rule:truthy
|
||||
pull_request:
|
||||
merge_group:
|
||||
branches:
|
||||
- main
|
||||
types:
|
||||
- checks_requested
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
markdownlint:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Update pip, git
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
sudo apt update
|
||||
sudo apt install -y git
|
||||
|
||||
- name: Check out code
|
||||
uses: actions/checkout@v4
|
||||
|
||||
# CHANGELOG.md is generated automatically from PR titles and descriptions
|
||||
# It might have issues but they are not critical
|
||||
- name: Lint all markdown files except for CHANGELOG.md
|
||||
uses: docker://avtodev/markdown-lint:master
|
||||
with:
|
||||
args: >-
|
||||
--ignore=CHANGELOG.md
|
||||
**/*.md
|
||||
config: .markdownlint.yaml
|
||||
@@ -0,0 +1,32 @@
|
||||
---
|
||||
name: PR Title Lint
|
||||
on: # yamllint disable-line rule:truthy
|
||||
pull_request:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- reopened
|
||||
- edited
|
||||
merge_group:
|
||||
branches:
|
||||
- main
|
||||
types:
|
||||
- checks_requested
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
commit-checks:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Install conventional-commit linter
|
||||
run: npm install @commitlint/config-conventional @commitlint/cli
|
||||
|
||||
- name: Run commitlint on PR title
|
||||
env:
|
||||
PR_TITLE: ${{ github.event.pull_request.title }}
|
||||
# Echo from env variable to avoid bash errors with extra characters
|
||||
run: echo "$PR_TITLE" | npx commitlint --verbose
|
||||
@@ -0,0 +1,34 @@
|
||||
---
|
||||
name: ShellCheck
|
||||
on: # yamllint disable-line rule:truthy
|
||||
pull_request:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
env:
|
||||
# some scripts source tox-lsr scripts - suppress that check
|
||||
SHELLCHECK_OPTS: -e SC1091
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
shellcheck:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Update git
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
sudo apt update
|
||||
sudo apt install -y git
|
||||
|
||||
- name: Checkout repo
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Run ShellCheck
|
||||
id: shellcheck_id
|
||||
uses: ludeeus/action-shellcheck@master
|
||||
|
||||
- name: Show file paths scanned
|
||||
run: |
|
||||
echo Files scanned:
|
||||
echo "${{ steps.shellcheck_id.outputs.files }}"
|
||||
@@ -0,0 +1,46 @@
|
||||
---
|
||||
# yamllint disable rule:line-length
|
||||
name: Test converting README.md to README.html
|
||||
on: # yamllint disable-line rule:truthy
|
||||
pull_request:
|
||||
merge_group:
|
||||
branches:
|
||||
- main
|
||||
types:
|
||||
- checks_requested
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
test_converting_readme:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- name: Update pip, git
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
sudo apt update
|
||||
sudo apt install -y git
|
||||
|
||||
- name: Check out code
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Remove badges from README.md prior to converting to HTML
|
||||
run: sed -i '1,8 {/^\[\!.*actions\/workflows/d}' README.md
|
||||
|
||||
- name: Convert README.md to HTML
|
||||
uses: docker://pandoc/core:latest
|
||||
with:
|
||||
args: >-
|
||||
--from gfm --to html5 --toc --shift-heading-level-by=-1
|
||||
--template .pandoc_template.html5
|
||||
--output README.html README.md
|
||||
|
||||
- name: Upload README.html as an artifact
|
||||
uses: actions/upload-artifact@master
|
||||
with:
|
||||
name: README.html
|
||||
path: README.html
|
||||
@@ -0,0 +1,194 @@
|
||||
---
|
||||
name: Run integration tests in Testing Farm
|
||||
on:
|
||||
issue_comment:
|
||||
types:
|
||||
- created
|
||||
permissions:
|
||||
contents: read
|
||||
# This is required for the ability to create/update the Pull request status
|
||||
statuses: write
|
||||
jobs:
|
||||
prepare_vars:
|
||||
name: Get info from role and PR to determine if and how to test
|
||||
# The concurrency key is used to prevent multiple workflows from running at the same time
|
||||
concurrency:
|
||||
# group name contains reponame-pr_num to allow simualteneous runs in different PRs
|
||||
group: testing-farm-${{ github.event.repository.name }}-${{ github.event.issue.number }}
|
||||
cancel-in-progress: true
|
||||
# Let's schedule tests only on user request. NOT automatically.
|
||||
# Only repository owner or member can schedule tests
|
||||
if: |
|
||||
github.event.issue.pull_request
|
||||
&& contains(github.event.comment.body, '[citest]')
|
||||
&& (contains(fromJson('["OWNER", "MEMBER", "COLLABORATOR", "CONTRIBUTOR"]'), github.event.comment.author_association)
|
||||
|| contains('systemroller', github.event.comment.user.login))
|
||||
runs-on: ubuntu-latest
|
||||
outputs:
|
||||
supported_platforms: ${{ steps.supported_platforms.outputs.supported_platforms }}
|
||||
head_sha: ${{ steps.head_sha.outputs.head_sha }}
|
||||
memory: ${{ steps.memory.outputs.memory }}
|
||||
steps:
|
||||
- name: Dump github context
|
||||
run: echo "$GITHUB_CONTEXT"
|
||||
shell: bash
|
||||
env:
|
||||
GITHUB_CONTEXT: ${{ toJson(github) }}
|
||||
|
||||
- name: Checkout repo
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Get head sha of the PR
|
||||
id: head_sha
|
||||
run: |
|
||||
head_sha=$(gh api "repos/$REPO/pulls/$PR_NO" --jq '.head.sha')
|
||||
echo "head_sha=$head_sha" >> $GITHUB_OUTPUT
|
||||
env:
|
||||
REPO: ${{ github.repository }}
|
||||
PR_NO: ${{ github.event.issue.number }}
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Checkout PR
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ steps.head_sha.outputs.head_sha }}
|
||||
|
||||
- name: Get memory
|
||||
id: memory
|
||||
run: |
|
||||
if [ -d tests/provision.fmf ]; then
|
||||
memory=$(grep -rPo ' m: \K(.*)' tests/provision.fmf)
|
||||
fi
|
||||
if [ -n "$memory" ]; then
|
||||
echo "memory=$memory" >> $GITHUB_OUTPUT
|
||||
else
|
||||
echo "memory=2048" >> $GITHUB_OUTPUT
|
||||
fi
|
||||
|
||||
- name: Get supported platforms
|
||||
id: supported_platforms
|
||||
run: |
|
||||
supported_platforms=""
|
||||
meta_main=meta/main.yml
|
||||
# All Fedora are supported, add latest Fedora versions to supported_platforms
|
||||
if yq '.galaxy_info.galaxy_tags[]' "$meta_main" | grep -qi fedora$; then
|
||||
supported_platforms+=" Fedora-39"
|
||||
supported_platforms+=" Fedora-40"
|
||||
fi
|
||||
# Specific Fedora versions supported
|
||||
if yq '.galaxy_info.galaxy_tags[]' "$meta_main" | grep -qiP 'fedora\d+$'; then
|
||||
for fedora_ver in $(yq '.galaxy_info.galaxy_tags[]' "$meta_main" | grep -iPo 'fedora\K(\d+$)'); do
|
||||
supported_platforms+=" Fedora-$fedora_ver"
|
||||
done
|
||||
fi
|
||||
if yq '.galaxy_info.galaxy_tags[]' "$meta_main" | grep -qi el7; then
|
||||
supported_platforms+=" CentOS-7-latest"
|
||||
fi
|
||||
for ver in 8 9 10; do
|
||||
if yq '.galaxy_info.galaxy_tags[]' "$meta_main" | grep -qi el"$ver"; then
|
||||
supported_platforms+=" CentOS-Stream-$ver"
|
||||
fi
|
||||
done
|
||||
echo "supported_platforms=$supported_platforms" >> $GITHUB_OUTPUT
|
||||
|
||||
testing-farm:
|
||||
name: ${{ matrix.platform }}/ansible-${{ matrix.ansible_version }}
|
||||
needs: prepare_vars
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- platform: Fedora-39
|
||||
ansible_version: 2.17
|
||||
- platform: Fedora-40
|
||||
ansible_version: 2.17
|
||||
- platform: CentOS-7-latest
|
||||
ansible_version: 2.9
|
||||
- platform: CentOS-Stream-8
|
||||
ansible_version: 2.9
|
||||
# On CentOS-Stream-8, latest supported Ansible is 2.16
|
||||
- platform: CentOS-Stream-8
|
||||
ansible_version: 2.16
|
||||
- platform: CentOS-Stream-9
|
||||
ansible_version: 2.17
|
||||
- platform: CentOS-Stream-10
|
||||
ansible_version: 2.17
|
||||
runs-on: ubuntu-latest
|
||||
env:
|
||||
ARTIFACTS_DIR_NAME: "tf_${{ github.event.repository.name }}-${{ github.event.issue.number }}_\
|
||||
${{ matrix.platform }}-${{ matrix.ansible_version }}_\
|
||||
${{ needs.prepare_vars.outputs.datetime }}/artifacts"
|
||||
ARTIFACT_TARGET_DIR: /srv/pub/alt/${{ vars.LINUXSYSTEMROLES_USER }}/logs
|
||||
steps:
|
||||
- name: Set variables with DATETIME and artifact location
|
||||
id: set_vars
|
||||
run: |
|
||||
printf -v DATETIME '%(%Y%m%d-%H%M%S)T' -1
|
||||
ARTIFACTS_DIR_NAME="tf_${{ github.event.repository.name }}-${{ github.event.issue.number }}_\
|
||||
${{ matrix.platform }}-${{ matrix.ansible_version }}_$DATETIME/artifacts"
|
||||
ARTIFACTS_TARGET_DIR=/srv/pub/alt/${{ vars.LINUXSYSTEMROLES_USER }}/logs
|
||||
ARTIFACTS_DIR=$ARTIFACTS_TARGET_DIR/$ARTIFACTS_DIR_NAME
|
||||
ARTIFACTS_URL=https://dl.fedoraproject.org/pub/alt/${{ vars.LINUXSYSTEMROLES_USER }}/logs/$ARTIFACTS_DIR_NAME
|
||||
echo "DATETIME=$DATETIME" >> $GITHUB_OUTPUT
|
||||
echo "ARTIFACTS_DIR=$ARTIFACTS_DIR" >> $GITHUB_OUTPUT
|
||||
echo "ARTIFACTS_URL=$ARTIFACTS_URL" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Set commit status as pending
|
||||
if: contains(needs.prepare_vars.outputs.supported_platforms, matrix.platform)
|
||||
uses: myrotvorets/set-commit-status-action@master
|
||||
with:
|
||||
sha: ${{ needs.prepare_vars.outputs.head_sha }}
|
||||
status: pending
|
||||
context: ${{ matrix.platform }}|ansible-${{ matrix.ansible_version }}
|
||||
description: Test started
|
||||
targetUrl: ""
|
||||
|
||||
- name: Set commit status as success with a description that platform is skipped
|
||||
if: "!contains(needs.prepare_vars.outputs.supported_platforms, matrix.platform)"
|
||||
uses: myrotvorets/set-commit-status-action@master
|
||||
with:
|
||||
sha: ${{ needs.prepare_vars.outputs.head_sha }}
|
||||
status: success
|
||||
context: ${{ matrix.platform }}|ansible-${{ matrix.ansible_version }}
|
||||
description: The role does not support this platform. Skipping.
|
||||
targetUrl: ""
|
||||
|
||||
- name: Run test in testing farm
|
||||
uses: sclorg/testing-farm-as-github-action@v3
|
||||
if: contains(needs.prepare_vars.outputs.supported_platforms, matrix.platform)
|
||||
with:
|
||||
git_url: https://github.com/linux-system-roles/tft-tests
|
||||
git_ref: main
|
||||
pipeline_settings: '{ "type": "tmt-multihost" }'
|
||||
environment_settings: '{ "provisioning": { "tags": { "BusinessUnit": "system_roles" } } }'
|
||||
# Keeping ARTIFACTS_URL at the bottom makes the link in logs clickable
|
||||
variables: "ANSIBLE_VER=${{ matrix.ansible_version }};\
|
||||
REPO_NAME=${{ github.event.repository.name }};\
|
||||
GITHUB_ORG=${{ github.repository_owner }};\
|
||||
PR_NUM=${{ github.event.issue.number }};\
|
||||
ARTIFACTS_DIR=${{ steps.set_vars.outputs.ARTIFACTS_DIR }};\
|
||||
TEST_LOCAL_CHANGES=false;\
|
||||
LINUXSYSTEMROLES_USER=${{ vars.LINUXSYSTEMROLES_USER }};\
|
||||
ARTIFACTS_URL=${{ steps.set_vars.outputs.ARTIFACTS_URL }}"
|
||||
# Note that LINUXSYSTEMROLES_SSH_KEY must be single-line, TF doesn't read multi-line variables fine.
|
||||
secrets: "LINUXSYSTEMROLES_DOMAIN=${{ secrets.LINUXSYSTEMROLES_DOMAIN }};\
|
||||
LINUXSYSTEMROLES_SSH_KEY=${{ secrets.LINUXSYSTEMROLES_SSH_KEY }}"
|
||||
compose: ${{ matrix.platform }}
|
||||
# There are two blockers for using public ranch:
|
||||
# 1. multihost is not supported in public https://github.com/teemtee/tmt/issues/2620
|
||||
# 2. Security issue that leaks long secrets - Jira TFT-2698
|
||||
tf_scope: private
|
||||
api_key: ${{ secrets.TF_API_KEY_RH }}
|
||||
update_pull_request_status: false
|
||||
tmt_hardware: '{ "memory": ">= ${{ needs.prepare_vars.outputs.memory }} MB" }'
|
||||
tmt_plan_filter: "tag:general,template"
|
||||
|
||||
- name: Set final commit status
|
||||
uses: myrotvorets/set-commit-status-action@master
|
||||
if: always() && contains(needs.prepare_vars.outputs.supported_platforms, matrix.platform)
|
||||
with:
|
||||
sha: ${{ needs.prepare_vars.outputs.head_sha }}
|
||||
status: ${{ job.status }}
|
||||
context: ${{ matrix.platform }}|ansible-${{ matrix.ansible_version }}
|
||||
description: Test finished
|
||||
targetUrl: ${{ steps.set_vars.outputs.ARTIFACTS_URL }}
|
||||
@@ -0,0 +1,43 @@
|
||||
---
|
||||
name: Re-run failed testing farm tests
|
||||
on:
|
||||
issue_comment:
|
||||
types:
|
||||
- created
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
citest_bad_rerun:
|
||||
if: |
|
||||
github.event.issue.pull_request
|
||||
&& contains(fromJson('["[citest_bad]", "[citest-bad]", "[citest bad]"]'), github.event.comment.body)
|
||||
&& contains(fromJson('["OWNER", "MEMBER", "COLLABORATOR", "CONTRIBUTOR"]'), github.event.comment.author_association)
|
||||
permissions:
|
||||
actions: write # for re-running failed jobs: https://docs.github.com/en/rest/actions/workflow-runs?apiVersion=2022-11-28#re-run-a-job-from-a-workflow-run
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Wait 10s until tft.yml workflow is created and skipped because new comment don't match [citest]
|
||||
run: sleep 10s
|
||||
|
||||
- name: Re-run failed jobs for this PR
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
REPO: ${{ github.repository }}
|
||||
PR_TITLE: ${{ github.event.issue.title }}
|
||||
run: |
|
||||
PENDING_RUN=$(gh api "repos/$REPO/actions/workflows/tft.yml/runs?event=issue_comment" \
|
||||
| jq -r "[.workflow_runs[] | select( .display_title == \"$PR_TITLE\") | \
|
||||
select(.status == \"pending\" or .status == \"queued\" or .status == \"in_progress\") | .id][0]")
|
||||
# if pending run don't exist, take the last run with failure state
|
||||
if [ "$PENDING_RUN" != "null" ]; then
|
||||
echo "The workflow $PENDING_RUN is still running, wait for it to finish to re-run"
|
||||
exit 1
|
||||
fi
|
||||
RUN_ID=$(gh api "repos/$REPO/actions/workflows/tft.yml/runs?event=issue_comment" \
|
||||
| jq -r "[.workflow_runs[] | select( .display_title == \"$PR_TITLE\" ) | select( .conclusion == \"failure\" ) | .id][0]")
|
||||
if [ "$RUN_ID" = "null" ]; then
|
||||
echo "Failed workflow not found, exitting"
|
||||
exit 1
|
||||
fi
|
||||
echo "Re-running workflow $RUN_ID"
|
||||
gh api --method POST repos/$REPO/actions/runs/$RUN_ID/rerun-failed-jobs
|
||||
@@ -0,0 +1,84 @@
|
||||
---
|
||||
# yamllint disable rule:line-length
|
||||
name: Weekly CI trigger
|
||||
on: # yamllint disable-line rule:truthy
|
||||
workflow_dispatch:
|
||||
schedule:
|
||||
- cron: 0 0 * * 6
|
||||
env:
|
||||
BRANCH_NAME: weekly-ci
|
||||
COMMIT_MESSAGE: "ci: This PR is to trigger periodic CI testing"
|
||||
BODY_MESSAGE: >-
|
||||
This PR is for the purpose of triggering periodic CI testing.
|
||||
We don't currently have a way to trigger CI without a PR,
|
||||
so this PR serves that purpose.
|
||||
COMMENT: "[citest]"
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
weekly_ci:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
issues: write
|
||||
pull-requests: write
|
||||
contents: write
|
||||
steps:
|
||||
- name: Update pip, git
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
sudo apt update
|
||||
sudo apt install -y git
|
||||
|
||||
- name: Checkout latest code
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
- name: Create or rebase commit, add dump_packages callback
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
|
||||
git config --global user.name "github-actions[bot]"
|
||||
git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com"
|
||||
git checkout ${{ env.BRANCH_NAME }} || git checkout -b ${{ env.BRANCH_NAME }}
|
||||
git rebase main
|
||||
if [ ! -d tests/callback_plugins ]; then
|
||||
mkdir -p tests/callback_plugins
|
||||
fi
|
||||
curl -L -s -o tests/callback_plugins/dump_packages.py https://raw.githubusercontent.com/linux-system-roles/auto-maintenance/main/callback_plugins/dump_packages.py
|
||||
git add tests/callback_plugins
|
||||
git commit --allow-empty -m "${{ env.COMMIT_MESSAGE }}"
|
||||
git push -f --set-upstream origin ${{ env.BRANCH_NAME }}
|
||||
|
||||
- name: Create and comment pull request
|
||||
uses: actions/github-script@v7
|
||||
with:
|
||||
github-token: ${{ secrets.GH_PUSH_TOKEN }}
|
||||
script: |
|
||||
const head = [context.repo.owner, ":", "${{ env.BRANCH_NAME }}"].join("");
|
||||
const response = await github.rest.pulls.list({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
head: head,
|
||||
base: context.ref,
|
||||
state: "open"
|
||||
});
|
||||
let pr_number = '';
|
||||
if (response.data.length === 0) {
|
||||
pr_number = (await github.rest.pulls.create({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
title: "${{ env.COMMIT_MESSAGE }}",
|
||||
body: "${{ env.BODY_MESSAGE }}",
|
||||
head: "${{ env.BRANCH_NAME }}",
|
||||
base: context.ref,
|
||||
draft: true
|
||||
})).data.number;
|
||||
} else {
|
||||
pr_number = response.data[0].number;
|
||||
}
|
||||
github.rest.issues.createComment({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
issue_number: pr_number,
|
||||
body: "${{ env.COMMENT }}",
|
||||
});
|
||||
@@ -0,0 +1,20 @@
|
||||
---
|
||||
# yamllint disable rule:line-length
|
||||
name: Woke
|
||||
on: # yamllint disable-line rule:truthy
|
||||
- pull_request
|
||||
jobs:
|
||||
woke:
|
||||
name: Detect non-inclusive language
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Run lsr-woke-action
|
||||
# Originally, uses: get-woke/woke-action@v0
|
||||
uses: linux-system-roles/lsr-woke-action@main
|
||||
with:
|
||||
woke-args: "-c https://raw.githubusercontent.com/linux-system-roles/tox-lsr/main/src/tox_lsr/config_files/woke.yml --count-only-error-for-failure"
|
||||
# Cause the check to fail on any broke rules
|
||||
fail-on-error: true
|
||||
Reference in New Issue
Block a user