Add the Gitea Actions workflows

Ports n3xd's four: pre-commit, backend tests, sharded Playwright and a
compose smoke test. Everything comes from the committed .env.example, so
no repository secrets are needed; Actions still has to be enabled per
repository and a runner registered with the ubuntu-latest label.

container_name, published ports and image tags are all daemon-global, so
two shards on one runner would fight over them. compose.ci.yml resets
them and tags per project. test-backend keeps the fixed names because it
reaches Postgres from the runner host.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KkmeRiyeYmVZqJVwuyHq9o
This commit is contained in:
Melvin Strobl
2026-08-15 21:20:05 +02:00
co-authored by Claude Opus 5
parent 9cede8dbb5
commit 8a221bfe50
5 changed files with 342 additions and 0 deletions
+63
View File
@@ -0,0 +1,63 @@
name: Compose Smoke Test
# Lives in this repository rather than the workspace root: the stack it starts
# is entirely app-local (docker/compose*.yml + .env.example). A root workflow
# would additionally need a token to check out the private submodules and would
# have to run scripts/setup.sh to generate secrets, for the same coverage.
on:
push:
branches:
- main
paths:
- backend/**
- frontend/**
- docker/compose*.yml
- .env.example
- .gitea/workflows/test-compose.yml
pull_request:
types:
- opened
- synchronize
paths:
- backend/**
- frontend/**
- docker/compose*.yml
- .env.example
- .gitea/workflows/test-compose.yml
env:
# compose.ci.yml drops the fixed container_names and host ports so this job
# can share a runner host with the Playwright shards.
COMPOSE_FILE: docker/compose.yml:docker/compose.dev.yml:docker/compose.ci.yml
# Own project name so this job's `down -v` cannot reach another stack.
COMPOSE_PROJECT_NAME: fluksio-app-ci-compose
jobs:
test-compose:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Write .env
run: cp .env.example .env
# The Playwright job runs the SPA off a Vite server inside its own
# container, so the nginx image is only ever built there. This job is what
# covers it — the SPA fallback in frontend/nginx.conf is the part that
# breaks silently.
- run: docker compose build backend frontend
- run: docker compose down -v --remove-orphans
# db and prestart come along as depends_on; --wait blocks on the backend
# healthcheck in docker/compose.yml.
- run: docker compose up -d --wait backend frontend
# Nothing is published on the host (compose.ci.yml), so the checks run
# from inside the backend container against the project network.
- name: Backend is up
run: docker compose exec -T backend curl -f http://localhost:8000/api/v1/utils/health-check/
- name: Frontend is up
run: docker compose exec -T backend curl -f http://frontend/
- name: An authenticated route serves the SPA shell
run: docker compose exec -T backend curl -f http://frontend/flows
- name: Tear down
if: always()
run: docker compose down -v --remove-orphans