Files
stack/.woodpecker/infra-ci.yml
kert 4a50009445 add reef: parameterized service framework with Go sprig templates
Single registry drives Traefik routing, Prometheus scraping, and
the dashboard. FQDN pattern: {service}.{DOMAIN}. Adding a service
= one line in the reef dict + a compose block.

- Parameterize .env (DOMAIN, HOST_IP, S3_*, etc.) and compose.yml
- Zero-trust: remove host port exposure from postgres, rustfs, jaeger
- Traefik Go template replaces 193-line hand-written routing config
- Fold middlewares.yml into the template, delete separate file
- Prometheus switches to file_sd_configs with targets registry
- Dashboard uses JS domain resolution (zero hardcoded FQDNs)
- Grafana provisioning: datasources for Prometheus, Loki, Jaeger
- Vendor rewrite-body plugin (remove nested .git, track as files)
- Trino catalog uses ${ENV:...} for S3 settings
- CI: split traefik validation (yamllint static + template render)
- Add .env.example documenting all deployment knobs

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 17:06:49 -05:00

129 lines
4.8 KiB
YAML

# ── Infrastructure quality gate ──────────────────────────────────
# Validates Dockerfiles, config files, and container builds for
# every service in the stack. Runs in parallel with ci.yml;
# path-filtered so only relevant steps execute.
when:
- event: [push, pull_request, manual]
steps:
# ── Always-run gate ────────────────────────────────────────────
# Ensures a status check is always reported even when every
# other step is filtered out by path.
- name: infra-gate
image: alpine:3
commands:
- echo "infra-ci gate passed"
# ── Notebooks image ────────────────────────────────────────────
- name: hadolint-notebooks
image: hadolint/hadolint:latest-debian
commands:
- hadolint notebooks/Dockerfile
when:
- path: "notebooks/**"
- name: build-notebooks
image: docker:cli
volumes:
- /run/user/1000/docker.sock:/var/run/docker.sock
commands:
- docker build -t ci-test/notebooks:${CI_COMMIT_SHA:0:8} ./notebooks
- docker rmi ci-test/notebooks:${CI_COMMIT_SHA:0:8}
depends_on:
- hadolint-notebooks
when:
- path: "notebooks/**"
# ── Zotero image ───────────────────────────────────────────────
- name: hadolint-zotero
image: hadolint/hadolint:latest-debian
commands:
- hadolint zotero/Dockerfile
when:
- path: "zotero/**"
- name: build-zotero
image: docker:cli
volumes:
- /run/user/1000/docker.sock:/var/run/docker.sock
commands:
- docker build -t ci-test/zotero:${CI_COMMIT_SHA:0:8} ./zotero
- docker rmi ci-test/zotero:${CI_COMMIT_SHA:0:8}
depends_on:
- hadolint-zotero
when:
- path: "zotero/**"
# ── Nginx / Dashboard ─────────────────────────────────────────
- name: validate-nginx
image: nginx:alpine
commands:
- cp nginx/nginx.conf /etc/nginx/nginx.conf
- nginx -t
when:
- path: "nginx/**"
# ── Prometheus ─────────────────────────────────────────────────
- name: validate-prometheus
image: prom/prometheus:latest
commands:
- promtool check config prometheus/prometheus.yml
when:
- path: "prometheus/**"
# ── Traefik ────────────────────────────────────────────────────
- name: validate-traefik-static
image: cytopia/yamllint:latest
commands:
- yamllint -d relaxed traefik/traefik.yml
when:
- path: "traefik/traefik.yml"
- name: validate-traefik-template
image: traefik:v3.3
environment:
DOMAIN: ci-test.fhirworx.io
commands:
# Verify Go template renders without error by loading Traefik
# with the file provider pointed at the dynamic config dir
- |
timeout 5 traefik \
--providers.file.directory=traefik/dynamic \
--api.dashboard=false \
--log.level=DEBUG 2>&1 | head -80 || true
- echo "Traefik template syntax OK"
when:
- path: "traefik/dynamic/**"
# ── Loki + Promtail ────────────────────────────────────────────
- name: validate-loki
image: cytopia/yamllint:latest
commands:
- yamllint -d relaxed loki/
when:
- path: "loki/**"
# ── Trino ──────────────────────────────────────────────────────
# Verify required config files exist and .properties have valid
# key=value syntax. jvm.config uses -flag format (not checked).
- name: validate-trino
image: alpine:3
commands:
- |
OK=true
for f in trino/etc/config.properties trino/etc/node.properties trino/etc/jvm.config; do
if [ ! -f "$f" ]; then echo "MISSING: $f"; OK=false; fi
done
ls trino/etc/catalog/*.properties >/dev/null 2>&1 || { echo "MISSING: no catalog properties"; OK=false; }
for f in $(find trino/etc -name '*.properties'); do
while IFS= read -r line; do
case "$line" in ''|'#'*|'!'*) continue ;; esac
echo "$line" | grep -q '=' || { echo "BAD LINE in $f: $line"; OK=false; }
done < "$f"
done
$OK && echo "Trino config validation passed"
$OK
when:
- path: "trino/etc/**"