All checks were successful
CICD / Build and Publish CICD Base Image (push) Successful in 6m8s
CICD / Build and Push CICD Image (push) Successful in 23m14s
CICD / Build CICD Image Failure Postmortem (push) Has been skipped
CICD / Backend Tests (push) Successful in 7m10s
CICD / Frontend Tests (push) Successful in 45s
CICD / Backend Doctests (push) Successful in 18s
CICD / Pre-commit Checks (push) Successful in 14m57s
CICD / Source Lanes Failure Postmortem (push) Has been skipped
CICD / CICD Tests Complete (push) Successful in 3s
CICD / Build Backend Base Image (push) Successful in 18s
CICD / Build Integration Tester Image (push) Successful in 1m5s
CICD / Build Backend Main Image (push) Successful in 1m52s
CICD / Build Frontend Base Image (push) Successful in 10m42s
CICD / Build Frontend Main Image (push) Successful in 33s
CICD / Build E2E Tester Image (push) Successful in 32m17s
CICD / Production Images Complete (push) Successful in 5s
CICD / Production Image Failures Postmortem (push) Has been skipped
CICD / Runtime Black-Box Integration Tests (push) Successful in 1m13s
CICD / Integration Tests Failure Postmortem (push) Has been skipped
CICD / End-to-End Tests (push) Successful in 11m23s
CICD / E2E Tests Failure Postmortem (push) Has been skipped
## Summary Hardens CI workflows for self-hosted Gitea runners by stabilizing E2E execution and Renovate behavior across internal/external network paths. Closes #62 ## What Changed ### E2E workflow reliability - Fixed E2E workspace handoff to ensure expected repository contents are present during test execution. - Added stricter preflight checks for required frontend files before running E2E. - Reduced mount/path fragility while preserving runtime image pull and compose flow. ### Renovate workflow hardening - Added internal-first endpoint reachability selection with fallback handling. - Added token preflight checks for repository access. - Added explicit host-rule auth handling for API/git paths. - Added container-level connectivity preflight diagnostics. - Added git URL override aligned with selected endpoint context. - Removed incorrect forced Dogar host-IP pinning that broke HTTPS clone routing. ## Why CI behavior was sensitive to runner networking and Renovate clone/auth interactions. These changes make the workflow deterministic in our runner topology and address recurring CI failures. ## Scope - Workflow logic only (`cicd.yaml`, `renovate.yml`) - No app feature or API behavior changes ## Validation - Workflow YAML validation passed during updates. - Changes were applied and verified iteratively from real failing run diagnostics. Co-authored-by: copilotcoder <copilotcoder@darkhelm.org> Reviewed-on: #73
68 lines
2.5 KiB
Plaintext
68 lines
2.5 KiB
Plaintext
hosts = [
|
|
"kankali.darkhelm.lan",
|
|
"zhokq.darkhelm.lan",
|
|
"urtzul.darkhelm.lan",
|
|
"pi-desktop.darkhelm.lan",
|
|
]
|
|
|
|
mirror_image = "kankali.darkhelm.lan:3001/darkhelm.org/act-ubuntu:act-latest"
|
|
ghcr_runner_image = "ghcr.io/catthehacker/ubuntu:act-latest"
|
|
renovate_image = "ghcr.io/renovatebot/renovate:41"
|
|
python_image = "python:3.14-slim"
|
|
node_image = "node:20-bookworm-slim"
|
|
|
|
# Check both upstream and mirrored tags on each runner host.
|
|
remote_script = """
|
|
def local_state(label, image):
|
|
r = !(docker image inspect @(image) > /dev/null 2> /dev/null)
|
|
print(f"{label}:present" if r.returncode == 0 else f"{label}:missing")
|
|
|
|
local_state("UBUNTU22", "ubuntu:22.04")
|
|
local_state("PYTHON", "__PYTHON_IMAGE__")
|
|
local_state("NODE", "__NODE_IMAGE__")
|
|
local_state("GHCR", "__GHCR_RUNNER_IMAGE__")
|
|
local_state("MIRROR_LOCAL", "__MIRROR_IMAGE__")
|
|
local_state("RENOVATE", "__RENOVATE_IMAGE__")
|
|
|
|
r = !(docker info 2> /dev/null | grep -qi "kankali.darkhelm.lan:3001")
|
|
print("REGISTRY_CONFIG:ok" if r.returncode == 0 else "REGISTRY_CONFIG:missing")
|
|
|
|
def remote_pull(label, image, log_path):
|
|
pull = !(docker pull @(image) > @(log_path) 2>&1)
|
|
if pull.returncode == 0:
|
|
print(f"{label}:pull-ok")
|
|
return
|
|
mismatch = !(grep -qi "http response to https client" @(log_path))
|
|
if mismatch.returncode == 0:
|
|
print(f"{label}:https-mismatch")
|
|
else:
|
|
print(f"{label}:pull-failed")
|
|
|
|
remote_pull("UBUNTU22_REMOTE", "ubuntu:22.04", "/tmp/ubuntu22-pull.log")
|
|
remote_pull("PYTHON_REMOTE", "__PYTHON_IMAGE__", "/tmp/python-pull.log")
|
|
remote_pull("NODE_REMOTE", "__NODE_IMAGE__", "/tmp/node-pull.log")
|
|
remote_pull("GHCR_REMOTE", "__GHCR_RUNNER_IMAGE__", "/tmp/ghcr-runner-pull.log")
|
|
remote_pull("MIRROR_REMOTE", "__MIRROR_IMAGE__", "/tmp/mirror-pull.log")
|
|
remote_pull("RENOVATE_REMOTE", "__RENOVATE_IMAGE__", "/tmp/renovate-pull.log")
|
|
|
|
local_state("UBUNTU22_AFTER_PULL", "ubuntu:22.04")
|
|
local_state("PYTHON_AFTER_PULL", "__PYTHON_IMAGE__")
|
|
local_state("NODE_AFTER_PULL", "__NODE_IMAGE__")
|
|
local_state("GHCR_AFTER_PULL", "__GHCR_RUNNER_IMAGE__")
|
|
local_state("MIRROR_AFTER_PULL", "__MIRROR_IMAGE__")
|
|
local_state("RENOVATE_AFTER_PULL", "__RENOVATE_IMAGE__")
|
|
"""
|
|
|
|
remote_script = (
|
|
remote_script
|
|
.replace("__MIRROR_IMAGE__", mirror_image)
|
|
.replace("__GHCR_RUNNER_IMAGE__", ghcr_runner_image)
|
|
.replace("__RENOVATE_IMAGE__", renovate_image)
|
|
.replace("__PYTHON_IMAGE__", python_image)
|
|
.replace("__NODE_IMAGE__", node_image)
|
|
)
|
|
|
|
for host in hosts:
|
|
print(f"\n=== {host} ===")
|
|
ssh @(host) @(remote_script)
|