stages: - build - test - deploy # The container registry (port 5050) is not reachable from the runners, so # nothing is pushed. Once it is, add a job that pushes $CI_REGISTRY_IMAGE. # Checks that the Dockerfile builds. Uses the runner host's Docker daemon, so # the runner needs /var/run/docker.sock in [runners.docker] volumes (no dind). build: stage: build image: docker:27 tags: - local rules: - if: $CI_PIPELINE_SOURCE == "merge_request_event" - if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH script: - docker build --pull -t chat-ci:$CI_JOB_ID . after_script: - docker rmi chat-ci:$CI_JOB_ID || true test: stage: test image: debian:13 tags: - local services: # no PostGIS needed: the settings use the plain postgresql backend - name: postgres:17 alias: chat_db - name: redis:7 alias: redis rules: - if: $CI_PIPELINE_SOURCE == "merge_request_event" - if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH cache: key: pip paths: - .cache/pip variables: PIP_CACHE_DIR: $CI_PROJECT_DIR/.cache/pip # postgres service POSTGRES_USER: ci POSTGRES_PASSWORD: ci-password POSTGRES_DB: chat_db # app settings; dummy values only, real secrets never belong in a test job DEBUG: "true" DB_NAME: chat_db DB_USER: ci DB_PASSWORD: ci-password DB_HOST: chat_db DB_PORT: "5432" REDIS_BASE_URL: redis://redis:6379/1 ACCOUNTS_BASE_PUBLIC_URL: https://accounts.invalid OAUTH2_PROVIDER_BASE_PUBLIC_URL: https://accounts.invalid/oauth2 OAUTH2_PROVIDER_BASE_PRIVATE_URL: https://accounts.invalid/oauth2 OAUTH2_PROVIDER_CLIENT_ID: ci OAUTH2_PROVIDER_CLIENT_SECRET: ci MINIO_ENDPOINT: minio.invalid MINIO_ACCESS_KEY: ci MINIO_SECRET_KEY: ci before_script: # keep in sync with the Dockerfile - apt-get update - apt-get install -y python3 python3-pip binutils libproj-dev gdal-bin - pip3 install --break-system-packages --ignore-installed -r requirements.txt - pip3 install --break-system-packages setuptools script: - python3 manage.py check - python3 manage.py makemigrations --check --dry-run # the suite is pytest-style; `manage.py test` would silently run 0 tests - python3 -m pytest -q --junitxml=report.xml artifacts: when: always reports: junit: report.xml # Runs on the staging host through a shell runner tagged `staging` that can use # the docker CLI. The compose stack keeps a git checkout of this repo (mounted # at /app), so this updates that checkout and restarts the service. # Set DEPLOY_DIR in Settings > CI/CD > Variables (the directory that holds # docker-compose.yml). DEPLOY_CHECKOUT and DEPLOY_SERVICE default to `chat`; # override them there if the checkout directory or compose service is named # differently. deploy_staging: stage: deploy tags: - staging rules: - if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH when: manual allow_failure: true # otherwise the pipeline shows "blocked" until someone deploys resource_group: staging # never run two deploys at once environment: name: staging variables: DEPLOY_CHECKOUT: chat DEPLOY_SERVICE: chat script: - cd "${DEPLOY_DIR:?set DEPLOY_DIR in Settings > CI/CD > Variables}" - git -C "$DEPLOY_CHECKOUT" pull --ff-only origin "$CI_DEFAULT_BRANCH" - docker compose up -d --build "$DEPLOY_SERVICE"