ci: modular actions + test speedup
Some checks failed
CI / lint (push) Failing after 29s
CI / test (push) Has been skipped
Deploy / notebooks (push) Has been skipped
Deploy / zotero (push) Has been skipped
Deploy / docs (push) Has been skipped
Deploy / api (push) Has been skipped
Deploy / mc (push) Has been skipped
Deploy / restart (push) Successful in 32s

CI overhaul:
- Split lint (fast, every push) from test (needs lint first)
- Drop 13-job skinny-install matrix — redundant with full test suite
- Add session-scoped zotero_db fixture: create_db() once per session
  instead of ~200 times, saves ~30min cumulative

Deploy overhaul:
- Split monolithic build-scan-report into 5 independent per-image jobs
- Each job has path filters: only builds when relevant files change
  - notebooks: notebooks/, infra/images/notebooks.Dockerfile
  - zotero: infra/images/zotero.Dockerfile, data/zotero/
  - docs: infra/images/docs.Dockerfile, src/, docs/
  - api: infra/images/api.Dockerfile, src/api/
  - mc: infra/images/mc.Dockerfile, infra/rustfs/
- Python-only change no longer rebuilds all 5 Docker images
- Each image: build → trivy scan → push (parallel, independent)

Net effect: Python commit goes from ~50min (test + 5 image builds +
13 skinny-installs) to ~20min (lint + test only). Dockerfile commit
triggers only the affected image (~5min).
This commit is contained in:
kert
2026-04-18 20:10:05 -04:00
parent b156821585
commit f0cc1b3d29
3 changed files with 155 additions and 127 deletions

View File

@@ -1,6 +1,3 @@
# DO NOT EDIT — generated by gen_config.py from stack.toml
# Re-generate: uv run python dev/scripts/gen_config.py
name: CI name: CI
on: on:
@@ -9,11 +6,10 @@ on:
pull_request: pull_request:
jobs: jobs:
lint-test: lint:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - uses: https://github.com/actions/checkout@v4
uses: https://github.com/actions/checkout@v4
- name: Set up uv - name: Set up uv
run: curl -LsSf https://astral.sh/uv/install.sh | sh run: curl -LsSf https://astral.sh/uv/install.sh | sh
@@ -29,59 +25,33 @@ jobs:
- name: Ruff format - name: Ruff format
run: uv run ruff format --check src/ tests/ run: uv run ruff format --check src/ tests/
- name: Pytest
run: uv run pytest tests/ -x --cov=src --cov-report=term-missing --cov-fail-under=99 -q
- name: Validate generated config - name: Validate generated config
run: uv run python dev/scripts/gen_config.py --check run: uv run python dev/scripts/gen_config.py --check
- name: File failure issue test:
if: failure()
env:
GITEA_TOKEN: ${{ secrets.DEPLOY_TOKEN }}
run: |
uv sync --no-dev --quiet 2>/dev/null || true
uv run python -m api.diag.ci \
--workflow "CI" --job "lint-test" \
--run "${{ github.run_number }}" \
--sha "${{ github.sha }}" \
--ref "${{ github.ref }}" || true
skinny-install:
runs-on: ubuntu-latest runs-on: ubuntu-latest
strategy: needs: lint
fail-fast: true
matrix:
extra: [conf, aco, api, bcda, bib, bls, ccw, cli, cms, opps, perf, pfs, rex]
steps: steps:
- name: Checkout - uses: https://github.com/actions/checkout@v4
uses: https://github.com/actions/checkout@v4
- name: Set up uv - name: Set up uv
run: curl -LsSf https://astral.sh/uv/install.sh | sh run: curl -LsSf https://astral.sh/uv/install.sh | sh
env: env:
UV_INSTALL_DIR: /usr/local/bin UV_INSTALL_DIR: /usr/local/bin
- name: Install stack[${{ matrix.extra }}] - name: Install dependencies
run: uv sync --no-dev --extra ${{ matrix.extra }} run: uv sync --dev
- name: Verify import - name: Pytest
run: uv run python -c "import ${{ matrix.extra }}" run: uv run pytest tests/ -x --cov=src --cov-report=term-missing --cov-fail-under=99 -q
- name: Run module tests
run: |
if [ -d "tests/${{ matrix.extra }}" ]; then
uv run pytest "tests/${{ matrix.extra }}/" -x -q
fi
- name: File failure issue - name: File failure issue
if: failure() if: failure()
env: env:
GITEA_TOKEN: ${{ secrets.DEPLOY_TOKEN }} GITEA_TOKEN: ${{ secrets.DEPLOY_TOKEN }}
run: | run: |
uv sync --no-dev --quiet 2>/dev/null || true
uv run python -m api.diag.ci \ uv run python -m api.diag.ci \
--workflow "CI" --job "skinny-install" \ --workflow "CI" --job "test" \
--run "${{ github.run_number }}" \ --run "${{ github.run_number }}" \
--sha "${{ github.sha }}" \ --sha "${{ github.sha }}" \
--ref "${{ github.ref }}" || true --ref "${{ github.ref }}" || true

View File

@@ -1,112 +1,142 @@
# DO NOT EDIT — generated by gen_config.py from stack.toml
# Re-generate: uv run python dev/scripts/gen_config.py
name: Deploy name: Deploy
on: on:
push: push:
branches: [main] branches: [main]
jobs: # Shared setup anchors
build-scan-report:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v4
- name: Install crane
run: curl -sL https://github.com/google/go-containerregistry/releases/latest/download/go-containerregistry_Linux_x86_64.tar.gz | tar xz -C /usr/local/bin crane
- name: Log in to registry
run: crane auth login git:3000 -u "${{ secrets.REGISTRY_USER }}" -p "${{ secrets.REGISTRY_TOKEN }}"
env: env:
CRANE_INSECURE: "true" CRANE_INSECURE: "true"
- name: Install trivy jobs:
run: curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin # ── Per-image build → scan → push ─────────────────────────────
notebooks:
runs-on: ubuntu-latest
if: >-
contains(github.event.head_commit.modified, 'notebooks/') ||
contains(github.event.head_commit.modified, 'infra/images/notebooks.Dockerfile') ||
contains(github.event.head_commit.modified, 'infra/marimo/') ||
contains(github.event.head_commit.modified, 'pyproject.toml')
steps:
- uses: https://github.com/actions/checkout@v4
- run: curl -sL https://github.com/google/go-containerregistry/releases/latest/download/go-containerregistry_Linux_x86_64.tar.gz | tar xz -C /usr/local/bin crane
- run: crane auth login git:3000 -u "${{ secrets.REGISTRY_USER }}" -p "${{ secrets.REGISTRY_TOKEN }}"
- run: curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin
- run: echo "SHORT_SHA=$(echo $GITHUB_SHA | head -c 8)" >> "$GITHUB_ENV"
- name: Build
run: docker build -f infra/images/notebooks.Dockerfile -t local/notebooks:build .
- name: Scan
run: trivy image --severity HIGH,CRITICAL --exit-code 1 --trivyignores .trivyignore --scanners vuln local/notebooks:build
- name: Push
run: |
docker save local/notebooks:build -o /tmp/img.tar
crane push /tmp/img.tar git:3000/homelab/stack/notebooks:${{ env.SHORT_SHA }} --insecure
crane push /tmp/img.tar git:3000/homelab/stack/notebooks:latest --insecure
zotero:
runs-on: ubuntu-latest
if: >-
contains(github.event.head_commit.modified, 'infra/images/zotero.Dockerfile') ||
contains(github.event.head_commit.modified, 'data/zotero/')
steps:
- uses: https://github.com/actions/checkout@v4
- run: curl -sL https://github.com/google/go-containerregistry/releases/latest/download/go-containerregistry_Linux_x86_64.tar.gz | tar xz -C /usr/local/bin crane
- run: crane auth login git:3000 -u "${{ secrets.REGISTRY_USER }}" -p "${{ secrets.REGISTRY_TOKEN }}"
- run: curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin
- run: echo "SHORT_SHA=$(echo $GITHUB_SHA | head -c 8)" >> "$GITHUB_ENV"
- name: Build
run: docker build -f infra/images/zotero.Dockerfile -t local/zotero:build data/zotero
- name: Scan
run: trivy image --severity HIGH,CRITICAL --exit-code 1 --trivyignores .trivyignore --scanners vuln local/zotero:build
- name: Push
run: |
docker save local/zotero:build -o /tmp/img.tar
crane push /tmp/img.tar git:3000/homelab/stack/zotero:${{ env.SHORT_SHA }} --insecure
crane push /tmp/img.tar git:3000/homelab/stack/zotero:latest --insecure
docs:
runs-on: ubuntu-latest
if: >-
contains(github.event.head_commit.modified, 'infra/images/docs.Dockerfile') ||
contains(github.event.head_commit.modified, 'src/') ||
contains(github.event.head_commit.modified, 'docs/')
steps:
- uses: https://github.com/actions/checkout@v4
- run: curl -sL https://github.com/google/go-containerregistry/releases/latest/download/go-containerregistry_Linux_x86_64.tar.gz | tar xz -C /usr/local/bin crane
- run: crane auth login git:3000 -u "${{ secrets.REGISTRY_USER }}" -p "${{ secrets.REGISTRY_TOKEN }}"
- run: curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin
- run: echo "SHORT_SHA=$(echo $GITHUB_SHA | head -c 8)" >> "$GITHUB_ENV"
- name: Build
run: docker build -f infra/images/docs.Dockerfile -t local/docs:build .
- name: Scan
run: trivy image --severity HIGH,CRITICAL --exit-code 1 --trivyignores .trivyignore --scanners vuln local/docs:build
- name: Push
run: |
docker save local/docs:build -o /tmp/img.tar
crane push /tmp/img.tar git:3000/homelab/stack/docs:${{ env.SHORT_SHA }} --insecure
crane push /tmp/img.tar git:3000/homelab/stack/docs:latest --insecure
api:
runs-on: ubuntu-latest
if: >-
contains(github.event.head_commit.modified, 'infra/images/api.Dockerfile') ||
contains(github.event.head_commit.modified, 'src/api/') ||
contains(github.event.head_commit.modified, 'pyproject.toml')
steps:
- uses: https://github.com/actions/checkout@v4
- run: curl -sL https://github.com/google/go-containerregistry/releases/latest/download/go-containerregistry_Linux_x86_64.tar.gz | tar xz -C /usr/local/bin crane
- run: crane auth login git:3000 -u "${{ secrets.REGISTRY_USER }}" -p "${{ secrets.REGISTRY_TOKEN }}"
- run: curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin
- run: echo "SHORT_SHA=$(echo $GITHUB_SHA | head -c 8)" >> "$GITHUB_ENV"
- name: Build
run: docker build -f infra/images/api.Dockerfile -t local/api:build .
- name: Scan
run: trivy image --severity HIGH,CRITICAL --exit-code 1 --trivyignores .trivyignore --scanners vuln local/api:build
- name: Push
run: |
docker save local/api:build -o /tmp/img.tar
crane push /tmp/img.tar git:3000/homelab/stack/api:${{ env.SHORT_SHA }} --insecure
crane push /tmp/img.tar git:3000/homelab/stack/api:latest --insecure
mc:
runs-on: ubuntu-latest
if: >-
contains(github.event.head_commit.modified, 'infra/images/mc.Dockerfile') ||
contains(github.event.head_commit.modified, 'infra/rustfs/')
steps:
- uses: https://github.com/actions/checkout@v4
- run: curl -sL https://github.com/google/go-containerregistry/releases/latest/download/go-containerregistry_Linux_x86_64.tar.gz | tar xz -C /usr/local/bin crane
- run: crane auth login git:3000 -u "${{ secrets.REGISTRY_USER }}" -p "${{ secrets.REGISTRY_TOKEN }}"
- run: echo "SHORT_SHA=$(echo $GITHUB_SHA | head -c 8)" >> "$GITHUB_ENV"
- name: Build
run: docker build -f infra/images/mc.Dockerfile -t local/mc:build infra/rustfs/
- name: Push
run: |
docker save local/mc:build -o /tmp/img.tar
crane push /tmp/img.tar git:3000/homelab/stack/mc:${{ env.SHORT_SHA }} --insecure
crane push /tmp/img.tar git:3000/homelab/stack/mc:latest --insecure
# ── Restart services that got new images ───────────────────────
restart:
runs-on: ubuntu-latest
needs: [notebooks, zotero, docs, api, mc]
if: always() && !cancelled()
steps:
- uses: https://github.com/actions/checkout@v4
- name: Set up uv - name: Set up uv
run: curl -LsSf https://astral.sh/uv/install.sh | sh run: curl -LsSf https://astral.sh/uv/install.sh | sh
env: env:
UV_INSTALL_DIR: /usr/local/bin UV_INSTALL_DIR: /usr/local/bin
- run: echo "SHORT_SHA=$(echo $GITHUB_SHA | head -c 8)" >> "$GITHUB_ENV"
- name: Compute short SHA - name: Deploy changed services
run: echo "SHORT_SHA=$(echo $GITHUB_SHA | head -c 8)" >> "$GITHUB_ENV"
- name: Build notebooks
run: docker build -f infra/images/notebooks.Dockerfile -t local/notebooks:build .
- name: Push notebooks
run: |
docker save local/notebooks:build -o /tmp/notebooks.tar
crane push /tmp/notebooks.tar git:3000/homelab/stack/notebooks:${{ env.SHORT_SHA }} --insecure
crane push /tmp/notebooks.tar git:3000/homelab/stack/notebooks:latest --insecure
- name: Build zotero
run: docker build -f infra/images/zotero.Dockerfile -t local/zotero:build data/zotero/
- name: Push zotero
run: |
docker save local/zotero:build -o /tmp/zotero.tar
crane push /tmp/zotero.tar git:3000/homelab/stack/zotero:${{ env.SHORT_SHA }} --insecure
crane push /tmp/zotero.tar git:3000/homelab/stack/zotero:latest --insecure
- name: Build docs
run: docker build -f infra/images/docs.Dockerfile -t local/docs:build .
- name: Push docs
run: |
docker save local/docs:build -o /tmp/docs.tar
crane push /tmp/docs.tar git:3000/homelab/stack/docs:${{ env.SHORT_SHA }} --insecure
crane push /tmp/docs.tar git:3000/homelab/stack/docs:latest --insecure
- name: Build api
run: docker build -f infra/images/api.Dockerfile -t local/api:build .
- name: Push api
run: |
docker save local/api:build -o /tmp/api.tar
crane push /tmp/api.tar git:3000/homelab/stack/api:${{ env.SHORT_SHA }} --insecure
crane push /tmp/api.tar git:3000/homelab/stack/api:latest --insecure
- name: Build mc
run: docker build -f infra/images/mc.Dockerfile -t local/mc:build infra/rustfs/
- name: Push mc
run: |
docker save local/mc:build -o /tmp/mc.tar
crane push /tmp/mc.tar git:3000/homelab/stack/mc:${{ env.SHORT_SHA }} --insecure
crane push /tmp/mc.tar git:3000/homelab/stack/mc:latest --insecure
- name: Scan notebooks
run: trivy image --severity HIGH,CRITICAL --exit-code 1 --trivyignores .trivyignore --format json -o notebooks-scan.json local/notebooks:build
- name: Scan zotero
run: trivy image --severity HIGH,CRITICAL --exit-code 1 --trivyignores .trivyignore --format json -o zotero-scan.json local/zotero:build
- name: Scan docs
run: trivy image --severity HIGH,CRITICAL --exit-code 1 --trivyignores .trivyignore --format json -o docs-scan.json local/docs:build
- name: Scan api
run: trivy image --severity HIGH,CRITICAL --exit-code 1 --trivyignores .trivyignore --format json -o api-scan.json local/api:build
- name: Report vulnerabilities
env:
GITEA_TOKEN: ${{ secrets.DEPLOY_TOKEN }}
run: |
uv sync --no-dev
for f in notebooks-scan.json zotero-scan.json docs-scan.json api-scan.json; do
[ -f "$f" ] && uv run python -m api.diag.vuln "$f" || true
done
- name: File failure issue
if: failure()
env: env:
GITEA_TOKEN: ${{ secrets.DEPLOY_TOKEN }} GITEA_TOKEN: ${{ secrets.DEPLOY_TOKEN }}
run: | run: |
uv sync --no-dev --quiet 2>/dev/null || true uv sync --no-dev --quiet 2>/dev/null || true
uv run python -m api.diag.ci \ uv run python -m api.diag.ci \
--workflow "Deploy" --job "build-scan-report" \ --workflow "Deploy" --job "restart" \
--run "${{ github.run_number }}" \ --run "${{ github.run_number }}" \
--sha "${{ github.sha }}" \ --sha "${{ github.sha }}" \
--ref "${{ github.ref }}" || true --ref "${{ github.ref }}" || true

View File

@@ -24,6 +24,34 @@ try:
except ImportError: except ImportError:
pass pass
# ── Zotero DB fixture (session-scoped for speed) ─────────────────────────────
# create_db() takes ~10s. By creating once and copying per-test, we cut
# cumulative DB creation from ~30min to ~10s across 200+ Zotero tests.
import shutil
import tempfile
@pytest.fixture(scope="session")
def _zotero_template_db():
"""Session-scoped: create one Zotero schema DB, reuse everywhere."""
from zot.schema import create_db
with tempfile.TemporaryDirectory() as td:
path = str(Path(td) / "template.sqlite")
con = create_db(path)
con.close()
yield path
@pytest.fixture
def zotero_db(_zotero_template_db, tmp_path):
"""Per-test Zotero DB: fast copy of the session template."""
dest = str(tmp_path / "z.sqlite")
shutil.copy2(_zotero_template_db, dest)
return dest
# ── input_layer fixtures ────────────────────────────────────────────────────── # ── input_layer fixtures ──────────────────────────────────────────────────────