mirror of
https://github.com/suitenumerique/meet.git
synced 2026-09-01 21:28:00 +00:00
7538cd886b
The repository is already called meet, so the file name said nothing about what the workflow holds. The print-statement check now excludes the whole workflows directory rather than one file by name: its own grep carries the literal print(, so the rename would otherwise match it on the deleted lines and fail the job.
398 lines
12 KiB
YAML
398 lines
12 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
pull_request:
|
|
branches:
|
|
- "*"
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
lint-git:
|
|
runs-on: ubuntu-latest
|
|
if: github.event_name == 'pull_request' # Makes sense only for pull requests
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
with:
|
|
fetch-depth: 0
|
|
- name: show
|
|
run: git log
|
|
- name: Enforce absence of print statements in code
|
|
if: always()
|
|
run: |
|
|
! git diff origin/${{ github.event.pull_request.base.ref }}..HEAD -- . ':(exclude).github/workflows/**' | grep "print("
|
|
- name: Check absence of fixup commits
|
|
if: always()
|
|
run: |
|
|
! git log | grep 'fixup!'
|
|
- name: Install gitlint
|
|
if: always()
|
|
run: "pip install --user --only-binary=:all: requests==2.34.2 gitlint-core==0.19.1"
|
|
- name: Lint commit messages added to main
|
|
if: always()
|
|
run: ~/.local/bin/gitlint --commits origin/${{ github.event.pull_request.base.ref }}..HEAD
|
|
|
|
check-changelog:
|
|
runs-on: ubuntu-latest
|
|
if: |
|
|
contains(github.event.pull_request.labels.*.name, 'noChangeLog') == false &&
|
|
github.event_name == 'pull_request'
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
with:
|
|
fetch-depth: 50
|
|
- name: Check that the CHANGELOG has been modified in the current branch
|
|
run: git diff --name-only ${{ github.event.pull_request.base.sha }} ${{ github.event.after }} | grep 'CHANGELOG.md'
|
|
|
|
lint-changelog:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
- name: Check CHANGELOG max line length
|
|
run: |
|
|
max_line_length=$(cat CHANGELOG.md | grep -Ev "^\[.*\]: https://github.com" | wc -L)
|
|
if [ $max_line_length -ge 80 ]; then
|
|
echo "ERROR: CHANGELOG has lines longer than 80 characters."
|
|
exit 1
|
|
fi
|
|
|
|
build-mails:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/mail
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
|
|
- name: Install Node.js
|
|
uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0
|
|
with:
|
|
node-version: "22"
|
|
|
|
- name: Restore the mail templates
|
|
uses: actions/cache@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0
|
|
id: mail-templates
|
|
with:
|
|
path: "src/backend/core/templates/mail"
|
|
key: mail-templates-${{ hashFiles('src/mail/mjml') }}
|
|
|
|
- name: Install yarn
|
|
if: steps.mail-templates.outputs.cache-hit != 'true'
|
|
run: npm install -g --ignore-scripts yarn@1.22.22
|
|
|
|
- name: Install node dependencies
|
|
if: steps.mail-templates.outputs.cache-hit != 'true'
|
|
run: yarn install --frozen-lockfile --ignore-scripts
|
|
|
|
- name: Build mails
|
|
if: steps.mail-templates.outputs.cache-hit != 'true'
|
|
run: yarn build
|
|
|
|
- name: Cache mail templates
|
|
if: steps.mail-templates.outputs.cache-hit != 'true'
|
|
uses: actions/cache@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0
|
|
with:
|
|
path: "src/backend/core/templates/mail"
|
|
key: mail-templates-${{ hashFiles('src/mail/mjml') }}
|
|
|
|
lint-back:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/backend
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
- name: Install Python
|
|
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7.6.0
|
|
- name: Install the project
|
|
run: uv sync --locked --all-extras
|
|
|
|
- name: Check code formatting with ruff
|
|
run: uv run --no-sync ruff format . --diff
|
|
- name: Lint code with ruff
|
|
run: uv run --no-sync ruff check .
|
|
- name: Lint code with pylint
|
|
run: uv run --no-sync pylint meet demo core
|
|
|
|
lint-agents:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/agents
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
- name: Install Python
|
|
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7.6.0
|
|
- name: Install the project
|
|
run: uv sync --locked --all-extras
|
|
- name: Check code formatting with ruff
|
|
run: uv run --no-sync ruff format . --diff
|
|
- name: Lint code with ruff
|
|
run: uv run --no-sync ruff check .
|
|
|
|
lint-summary:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/summary
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
- name: Install Python
|
|
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
cache: "pip"
|
|
- name: Install development dependencies
|
|
run: "pip install --user --only-binary=:all: .[dev]"
|
|
- name: Check code formatting with ruff
|
|
run: ~/.local/bin/ruff format . --diff
|
|
- name: Lint code with ruff
|
|
run: ~/.local/bin/ruff check .
|
|
|
|
test-back:
|
|
runs-on: ubuntu-latest
|
|
needs: build-mails
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/backend
|
|
|
|
services:
|
|
postgres:
|
|
image: postgres:16
|
|
env:
|
|
POSTGRES_DB: meet
|
|
POSTGRES_USER: dinum
|
|
POSTGRES_PASSWORD: pass
|
|
ports:
|
|
- 5432:5432
|
|
# needed because the postgres container does not provide a healthcheck
|
|
options: --health-cmd pg_isready --health-interval 10s --health-timeout 5s --health-retries 5
|
|
redis:
|
|
image: redis:5
|
|
ports:
|
|
- 6379:6379
|
|
# Set health checks to wait until redis has started
|
|
options: >-
|
|
--health-cmd "redis-cli ping"
|
|
--health-interval 10s
|
|
--health-timeout 5s
|
|
--health-retries 5
|
|
|
|
env:
|
|
DJANGO_CONFIGURATION: Test
|
|
DJANGO_SETTINGS_MODULE: meet.settings
|
|
DJANGO_SECRET_KEY: ThisIsAnExampleKeyForTestPurposeOnly
|
|
OIDC_OP_JWKS_ENDPOINT: /endpoint-for-test-purpose-only
|
|
DB_HOST: localhost
|
|
DB_NAME: meet
|
|
DB_USER: dinum
|
|
DB_PASSWORD: pass
|
|
DB_PORT: 5432
|
|
REDIS_URL: redis://localhost:6379/1
|
|
STORAGES_STATICFILES_BACKEND: django.contrib.staticfiles.storage.StaticFilesStorage
|
|
AWS_S3_ENDPOINT_URL: http://localhost:9000
|
|
AWS_S3_ACCESS_KEY_ID: meet
|
|
AWS_S3_SECRET_ACCESS_KEY: password
|
|
OIDC_RS_CLIENT_ID: meet
|
|
OIDC_RS_CLIENT_SECRET: ThisIsAnExampleKeyForDevPurposeOnly
|
|
OIDC_OP_INTROSPECTION_ENDPOINT: https://oidc.example.com/introspect
|
|
OIDC_OP_URL: https://oidc.example.com
|
|
MEDIA_BASE_URL: http://localhost:8083
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
|
|
- name: Create writable /data
|
|
run: |
|
|
sudo mkdir -p /data/media && \
|
|
sudo mkdir -p /data/static
|
|
|
|
- name: Restore the mail templates
|
|
uses: actions/cache@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0
|
|
id: mail-templates
|
|
with:
|
|
path: "src/backend/core/templates/mail"
|
|
key: mail-templates-${{ hashFiles('src/mail/mjml') }}
|
|
|
|
- name: Start MinIO
|
|
run: |
|
|
docker pull minio/minio
|
|
docker run -d --name minio \
|
|
-p 9000:9000 \
|
|
-e "MINIO_ACCESS_KEY=meet" \
|
|
-e "MINIO_SECRET_KEY=password" \
|
|
-v /data/media:/data \
|
|
minio/minio server --console-address :9001 /data
|
|
|
|
# Tool to wait for a service to be ready
|
|
- name: Install Dockerize
|
|
run: |
|
|
curl --proto "=https" --proto-redir "=https" --tlsv1.2 -sSLf \
|
|
https://github.com/jwilder/dockerize/releases/download/v0.8.0/dockerize-linux-amd64-v0.8.0.tar.gz |
|
|
sudo tar -C /usr/local/bin -xzv
|
|
|
|
- name: Wait for MinIO to be ready
|
|
run: |
|
|
dockerize -wait tcp://localhost:9000 -timeout 10s
|
|
|
|
- name: Configure MinIO
|
|
run: |
|
|
MINIO=$(docker ps | grep minio/minio | sed -E 's/.*\s+([a-zA-Z0-9_-]+)$/\1/')
|
|
docker exec ${MINIO} sh -c \
|
|
"mc alias set meet http://localhost:9000 meet password && \
|
|
mc alias ls && \
|
|
mc mb meet/meet-media-storage"
|
|
|
|
- name: Install Python
|
|
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7.6.0
|
|
- name: Install the dependencies
|
|
run: uv sync --locked --all-extras
|
|
|
|
- name: Install gettext (required to compile messages)
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y gettext
|
|
|
|
- name: Generate a MO file from strings extracted from the project
|
|
run: uv run --no-sync python manage.py compilemessages
|
|
|
|
- name: Run tests
|
|
run: uv run --no-sync pytest -n 2
|
|
|
|
test-summary:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/summary
|
|
|
|
env:
|
|
AUTHORIZED_TENANTS: '[{"id": "test-tenant", "api_key": "test-api-token", "webhook_url": "https://example.com/webhook", "webhook_api_key": "test-webhook-api-key"}]'
|
|
AWS_STORAGE_BUCKET_NAME: "http://meet-media-storage"
|
|
AWS_S3_ENDPOINT_URL: "minio:9000"
|
|
AWS_S3_ACCESS_KEY_ID: "meet"
|
|
AWS_S3_SECRET_ACCESS_KEY: "password"
|
|
WHISPERX_BASE_URL: "https://configure-your-url.com"
|
|
WHISPERX_ASR_MODEL: "large-v2"
|
|
WHISPERX_API_KEY: "test-whisperx-secret"
|
|
WHISPERX_DEFAULT_LANGUAGE: "fr"
|
|
LLM_BASE_URL: "https://configure-your-url.com"
|
|
LLM_API_KEY: "test-llm-secret"
|
|
LLM_MODEL: "test-llm-model"
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
|
|
- name: Install ffmpeg
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y ffmpeg
|
|
|
|
- name: Install Python
|
|
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
cache: "pip"
|
|
|
|
- name: Install development dependencies
|
|
run: "pip install --user --only-binary=:all: .[dev]"
|
|
|
|
- name: Run summary tests
|
|
run: ~/.local/bin/pytest
|
|
|
|
lint-front:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
|
|
- name: Install dependencies
|
|
run: cd src/frontend/ && npm ci --ignore-scripts
|
|
|
|
- name: Check linting
|
|
run: cd src/frontend/ && npm run lint
|
|
|
|
- name: Check format
|
|
run: cd src/frontend/ && npm run check
|
|
|
|
lint-sdk:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/sdk/library
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
|
|
- name: Install dependencies
|
|
run: npm ci --ignore-scripts
|
|
|
|
- name: Check linting
|
|
run: npm run lint
|
|
|
|
- name: Check format
|
|
run: npm run check
|
|
|
|
build-sdk:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
needs: lint-sdk
|
|
defaults:
|
|
run:
|
|
working-directory: src/sdk/library
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
|
|
- name: Install dependencies
|
|
run: npm ci --ignore-scripts
|
|
|
|
- name: Build SDK
|
|
run: npm run build
|