# The gate, running on our own hardware (G7.3). # # This is the dogfood: windy-git verifies itself before anything else migrates. # # `runs-on: veron-1` is a label this runner actually provides. NEVER # `ubuntu-latest` (G7.5) — a self-hosted runner has no such label, so a workflow # naming it queues forever and presents as a hung CI system rather than a typo. name: check on: push: branches: [main] pull_request: jobs: gate: runs-on: veron-1 # Run IN a Python 3.12 image rather than trusting the runner image's # toolchain. The first real CI run wedged here: catthehacker/ubuntu:act-22.04 # ships Python 3.10.12, this project declares requires-python >=3.12, and pip # answered that by backtracking through the entire release history of every # dependency looking for something 3.10-compatible. It churned for 14 minutes # at 100% CPU with `-q` hiding all of it, and would have churned until the # runner timeout. A version mismatch presenting as a hang, not an error. container: image: python:3.12-bookworm # And a hard ceiling, so a wedged step is a red check in minutes rather than # an occupied runner for half an hour. timeout-minutes: 12 services: postgres: image: postgres:16-alpine env: POSTGRES_USER: windygit POSTGRES_PASSWORD: windygit POSTGRES_DB: windygit options: >- --health-cmd "pg_isready -U windygit" --health-interval 5s --health-retries 10 steps: - uses: actions/checkout@v4 - name: install run: | python3 --version python3 -m venv .venv .venv/bin/pip install -q --upgrade pip .venv/bin/pip install -e ".[dev]" - name: lint run: .venv/bin/ruff check api scripts - name: vocabulary audit (D-9) run: python3 scripts/vocab_audit.py - name: tests run: .venv/bin/pytest -q # G0.4 — a migration nobody has run is a migration nobody can trust. This # is the step that caught two bugs review did not: SQLAlchemy Enum # persisting .name instead of .value, and create_table re-emitting # CREATE TYPE without checkfirst. - name: migration round-trip (upgrade -> downgrade -> upgrade) env: DATABASE_URL: postgresql://windygit:windygit@postgres:5432/windygit run: | .venv/bin/alembic upgrade head .venv/bin/alembic downgrade base .venv/bin/alembic upgrade head # I-12 — the honesty check. Nine sibling services cannot name the commit # they are running; one reports another repo's commit entirely. - name: /version must equal HEAD run: | HEAD_SHA=$(git rev-parse HEAD) COMMIT_SHA=deadbeefdeadbeefdeadbeefdeadbeefdeadbeef \ .venv/bin/python -c " import os, sys sys.path.insert(0, '.') from api.app.buildinfo import get_build_info info = get_build_info() expected = '$HEAD_SHA' assert info.commit_sha == expected, f'{info.commit_sha} != {expected}' print('I-12 holds: env override ignored, reported', info.commit_sha[:12]) "