diff --git a/.gitea/workflows/tests.yaml b/.gitea/workflows/tests.yaml index 99104c8..5ef2290 100644 --- a/.gitea/workflows/tests.yaml +++ b/.gitea/workflows/tests.yaml @@ -1,3 +1,7 @@ +# Tests - ensure code quality, via the shared workflow. +# +# Checks include: PHPStan, PHPUnit, and PHP-CS-Fixer. +# name: Tests on: @@ -14,43 +18,26 @@ on: jobs: test: - runs-on: ubuntu-latest + uses: private/ci/.gitea/workflows/php-test.yaml@v1 + with: + php-version: '8.5' - steps: - - name: Checkout - uses: actions/checkout@v4 + # profiles defines what to test: + # * web-app: full test suite (default) + # * auth-gateway: skip template check + # * api-gateway: skip interface checks + profile: auth-gateway - - name: Setup PHP - uses: shivammathur/setup-php@v2 - with: - php-version: '8.5' - extensions: apcu, mbstring - coverage: xdebug - ini-values: apc.enable_cli=1 + # coverage defines how to check test-coverage: + # * pcov: recommended (default) + # * xdebug + coverage: 'pcov' + # 0-100 percentage of test-coverage required + coverage-min: '75' - # Authenticate to GitHub to raise API rate limit from 60 → 5,000 req/hour. - # Uses the same token that publish.yaml uses to sync to GitHub. - - name: Configure GitHub OAuth token - env: - GITHUB_TOKEN: ${{ secrets.SYNC_GITHUB_TOKEN }} - run: composer config --global github-oauth.github.com "$GITHUB_TOKEN" + # does failing our "conformance" check make the test suite fail + conformance-blocking: false - # Cache Composer's download cache so repeated CI runs don't re-download - # packages at all. Keyed on composer.lock hash — cache busts automatically - # when dependencies change. - - name: Cache Composer dependencies - uses: actions/cache@v4 - with: - path: ~/.composer/cache - key: composer-${{ runner.os }}-${{ hashFiles('composer.lock') }} - restore-keys: | - composer-${{ runner.os }}- - - - name: Install dependencies - run: composer install --prefer-dist --no-progress - - - name: Run php-cs-fixer - run: vendor/bin/php-cs-fixer fix --dry-run --diff - - - name: Run tests - run: XDEBUG_MODE=coverage vendor/bin/phpunit --coverage-text + secrets: + # github token so composer can download dependencies + SYNC_GITHUB_TOKEN: ${{ secrets.SYNC_GITHUB_TOKEN }} diff --git a/docker-bake.hcl b/docker-bake.hcl index 4f556de..aa77051 100644 --- a/docker-bake.hcl +++ b/docker-bake.hcl @@ -1,23 +1,13 @@ -# preauth build config — one published variant from one Dockerfile. +# Preauth build config # -# docker buildx bake # build, no push -# docker buildx bake --push # build and push -# docker buildx bake --print # resolve and print, without building -# MAX_REQUESTS=0 docker buildx bake # override any variable +# CI (develop.yaml / docker.yaml) invokes this with --file so the compose +# file that lives in the same directory is not merged in as extra targets. # -# CI (.gitea/workflows/develop.yaml, docker.yaml) invokes this, so the build -# definition lives here rather than in the workflow files. +# DOCKERHUB_TARGET is the org/repo (Gitea Settings → Variables) +# CI sets TAG=latest + VERSION= for tag pushes, +# TAG=develop for pushes to main. # -# Naming contract (portfolio, identical to context-shuttle and task-weaver): -# DOCKERHUB_TARGET is the org/repo (Gitea Settings → Variables; value -# digitaladapt/preauth). Tag suffixes are decided HERE, not in CI: -# main push → :develop -# tag push → :latest and : (leading 'v' stripped) -# CI sets TAG=develop for main pushes, TAG=latest + VERSION= for -# tag pushes. Both amd64 and arm64 are always built (ARM server). -# -# Variables can be overridden from the environment, e.g.: -# DOCKERHUB_TARGET=digitaladapt/preauth TAG=develop docker buildx bake --push +# MAX_REQUESTS=0 docker buildx bake # specify variables to override variable "DOCKERHUB_TARGET" { default = "digitaladapt/preauth"