Add the Gitea Actions workflows

Ports n3xd's four: pre-commit, backend tests, sharded Playwright and a
compose smoke test. Everything comes from the committed .env.example, so
no repository secrets are needed; Actions still has to be enabled per
repository and a runner registered with the ubuntu-latest label.

container_name, published ports and image tags are all daemon-global, so
two shards on one runner would fight over them. compose.ci.yml resets
them and tags per project. test-backend keeps the fixed names because it
reaches Postgres from the runner host.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KkmeRiyeYmVZqJVwuyHq9o
This commit is contained in:
Melvin Strobl
2026-08-15 21:20:05 +02:00
co-authored by Claude Opus 5
parent 9cede8dbb5
commit 8a221bfe50
5 changed files with 342 additions and 0 deletions
+61
View File
@@ -0,0 +1,61 @@
# CI isolation overrides — layered on top of compose.yml + compose.dev.yml by
# the Playwright shards and the compose smoke job in .gitea/workflows/.
#
# A self-hosted runner can put several jobs on the same host. A per-job
# COMPOSE_PROJECT_NAME keeps their containers, networks and volumes apart, but
# it does not cover the two things that are global to the Docker daemon:
#
# 1. `container_name` ignores the project name, so a second job fails with
# "the container name /fluksio-db is already in use".
# 2. Published host ports are first come, first served.
#
# Neither is needed in CI: everything reaches everything else by compose
# service name on the project network.
services:
proxy:
ports: !reset []
db:
container_name: !reset null
ports: !reset []
redis:
container_name: !reset null
adminer:
container_name: !reset null
ports: !reset []
mailcatcher:
ports: !reset []
prestart:
container_name: !reset null
backend:
container_name: !reset null
ports: !reset []
frontend:
container_name: !reset null
ports: !reset []
# Baked at build time. compose.dev.yml bakes http://localhost:8000, which
# resolves to the playwright container itself; the browser has to reach the
# API by service name on the project network instead.
build:
args:
- VITE_API_URL=http://backend:8000
# Image tags are daemon-global too, and this one no longer holds the same
# bytes as the smoke job's: without a per-job tag the two jobs overwrite
# each other's `fluksio-frontend:latest` and the SPA calls the wrong API.
image: '${DOCKER_IMAGE_FRONTEND?Variable not set}:${COMPOSE_PROJECT_NAME:-ci}'
playwright:
ports: !reset []
# frontend/playwright.config.ts defaults baseURL to http://app.localhost,
# which is right for a local run against the integrated stack but resolves
# to 127.0.0.1 in here. In CI the nginx `frontend` service serves the SPA.
# This origin must stay in BACKEND_CORS_ORIGINS (.env.example).
environment:
- PLAYWRIGHT_BASE_URL=http://frontend