Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
34 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
81 changes: 81 additions & 0 deletions .github/workflows/ci.yml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,81 @@
---
name: CI
"on":
push:
branches:
- main
pull_request:
merge_group:

permissions: {}
jobs:
determine-image-tag:
name: Determine Image Tag
runs-on: ubuntu-latest
permissions:
contents: read
outputs:
tag: ${{ steps.set-tag.outputs.tag }}
steps:
- name: Set image tag
id: set-tag
run: |
if [ -n "${{ github.event.pull_request.number }}" ]; then
TAG="pr-${{ github.event.pull_request.number }}"
echo "::notice::Using PR-based tag: $TAG"
else
# Sanitize ref_name by replacing / with -
TAG="${{ github.ref_name }}"
TAG="${TAG//\//-}"
echo "::notice::Using branch/tag-based tag: $TAG"
fi

# Validate tag format
if [[ ! "$TAG" =~ ^[a-zA-Z0-9._-]+$ ]]; then
echo "::error::Invalid image tag format: $TAG"
exit 1
fi

echo "tag=$TAG" >> $GITHUB_OUTPUT

lint:
permissions:
contents: read
uses: ./.github/workflows/lint.yml

docker:
needs: determine-image-tag
uses: ./.github/workflows/docker-build-push.yml
secrets: inherit
permissions:
contents: read
packages: write
with:
image-tag: ${{ needs.determine-image-tag.outputs.tag }}
apps: |
[
{"name": "ev-node-evm-single", "dockerfile": "apps/evm/single/Dockerfile"},
{"name": "ev-node-testapp", "dockerfile": "apps/testapp/Dockerfile"}
]

test:
permissions:
actions: read
contents: read
uses: ./.github/workflows/test.yml
secrets: inherit

docker-tests:
needs: [determine-image-tag, docker]
uses: ./.github/workflows/docker-tests.yml
secrets: inherit
permissions:
contents: read
with:
image-tag: ${{ needs.determine-image-tag.outputs.tag }}

proto:
permissions:
contents: read
pull-requests: write
uses: ./.github/workflows/proto.yml
66 changes: 0 additions & 66 deletions .github/workflows/ci_release.yml

This file was deleted.

50 changes: 50 additions & 0 deletions .github/workflows/docker-build-push.yml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
---
Comment thread
auricom marked this conversation as resolved.
# This workflow builds and pushes Docker images to GHCR
name: Build Docker Images
permissions: {}
"on":
workflow_call:
inputs:
image-tag:
required: true
type: string
description: 'Docker image tag (e.g., v1.2.3, pr-123, sha-abc123)'
apps:
required: true
type: string
description: 'JSON array of apps to build (e.g., [{"name": "testapp", "dockerfile": "apps/testapp/Dockerfile"}])'

jobs:
build-images:
name: Build ${{ matrix.app.name }}
# skip building images for merge groups as they are already built on PRs and main
if: github.event_name != 'merge_group'
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
strategy:
matrix:
app: ${{ fromJson(inputs.apps) }}
steps:
- name: Checkout code
uses: actions/checkout@v5

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
Comment thread Fixed
Comment thread Dismissed

- name: Log in to GHCR
uses: docker/login-action@v3
Comment thread Fixed
Comment thread Dismissed
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Build and push ${{ matrix.app.name }} Docker image
uses: docker/build-push-action@v6
Comment thread Fixed
Comment thread Fixed
Comment thread Dismissed
with:
context: .
file: ${{ matrix.app.dockerfile }}
push: true
platforms: linux/amd64,linux/arm64
tags: ghcr.io/${{ github.repository_owner }}/${{ matrix.app.name }}:${{ inputs.image-tag }}
51 changes: 51 additions & 0 deletions .github/workflows/docker-tests.yml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
---
# This workflow runs tests that require Docker images to be built first
name: Docker E2E Tests
permissions: {}
Comment thread
auricom marked this conversation as resolved.
"on":
workflow_call:
inputs:
image-tag:
required: true
type: string
workflow_dispatch:
inputs:
image-tag:
description: 'Docker image tag to use for tests (e.g., v1.2.3, pr-123, sha-abc123)'
required: true
type: string

jobs:
docker-tests:
permissions:
contents: read
name: Docker E2E Tests
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- name: set up go
uses: actions/setup-go@v6
with:
go-version-file: ./test/docker-e2e/go.mod
- name: Run Docker E2E Tests
run: make test-docker-e2e
env:
EV_NODE_IMAGE_REPO: ghcr.io/${{ github.repository_owner }}/ev-node-testapp
EV_NODE_IMAGE_TAG: ${{ inputs.image-tag }}

docker-upgrade-tests:
Comment thread Fixed
name: Docker Upgrade E2E Tests
permissions:
contents: read
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- name: set up go
uses: actions/setup-go@v6
with:
go-version-file: ./test/docker-e2e/go.mod
- name: Run Docker Upgrade E2E Tests
run: make test-docker-upgrade-e2e
env:
EVM_SINGLE_IMAGE_REPO: ghcr.io/${{ github.repository_owner }}/ev-node-evm-single
EVM_SINGLE_NODE_IMAGE_TAG: ${{ inputs.image-tag }}
Comment thread Fixed
46 changes: 37 additions & 9 deletions .github/workflows/lint.yml
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,10 @@
---
# lint runs all linters in this repository
# This workflow is triggered by ci_release.yml workflow
# This workflow is triggered by ci.yml workflow
name: lint
on:
permissions:
contents: read
"on":
workflow_call:

jobs:
Expand All@@ -13,8 +16,8 @@
- uses: actions/setup-go@v6
with:
go-version-file: ./go.mod
# This steps sets the GIT_DIFF environment variable to true
# if files defined in PATTERS changed
# This steps sets the GIT_DIFF environment variable to true
# if files defined in PATTERS changed
- uses: technote-space/get-diff-action@v6.1.2
with:
# This job will pass without running if go.mod, go.sum, and *.go
Expand All@@ -30,32 +33,57 @@
github-token: ${{ secrets.github_token }}
if: env.GIT_DIFF

# hadolint lints the Dockerfile
hadolint:
uses: evstack/.github/.github/workflows/reusable_dockerfile_lint.yml@v0.5.0 # yamllint disable-line rule:line-length
Comment thread
auricom marked this conversation as resolved.
with:
dockerfile: Dockerfile
failure-threshold: error
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: hadolint/hadolint-action@v3.3.0
Comment thread Dismissed
with:
recursive: true
failure-threshold: error

yamllint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0
- uses: technote-space/get-diff-action@v6.1.2

Check warning

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'lint' step
Uses Step
uses 'technote-space/get-diff-action' with ref 'v6.1.2', not a pinned commit hash
with:
PATTERNS: |
**/*.yml
**/*.yaml
- uses: evstack/.github/.github/actions/yamllint@v0.5.0
if: env.GIT_DIFF

markdown-lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0
- uses: technote-space/get-diff-action@v6.1.2
Comment thread Dismissed
with:
PATTERNS: |
**/*.md
- uses: evstack/.github/.github/actions/markdown-lint@v0.5.0
if: env.GIT_DIFF

# Checks that the .goreleaser.yaml file is valid
goreleaser-check:
runs-on: ubuntu-latest
steps:
- name: checkout
uses: actions/checkout@v5
with:
fetch-depth: 0
- uses: technote-space/get-diff-action@v6.1.2
Comment thread Dismissed
with:
PATTERNS: |
.goreleaser.yaml
.goreleaser.yml
- uses: goreleaser/goreleaser-action@v6
with:
version: latest
args: check
if: env.GIT_DIFF
Loading
Loading