104 lines
3.4 KiB
YAML
104 lines
3.4 KiB
YAML
stages:
|
|
- build
|
|
- test
|
|
- deploy
|
|
|
|
# The container registry (port 5050) is not reachable from the runners, so
|
|
# nothing is pushed. Once it is, add a job that pushes $CI_REGISTRY_IMAGE.
|
|
|
|
# Checks that the Dockerfile builds. Uses the runner host's Docker daemon, so
|
|
# the runner needs /var/run/docker.sock in [runners.docker] volumes (no dind).
|
|
build:
|
|
stage: build
|
|
image: docker:27
|
|
tags:
|
|
- local
|
|
rules:
|
|
- if: $CI_PIPELINE_SOURCE == "merge_request_event"
|
|
- if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH
|
|
script:
|
|
- docker build --pull -t chat-ci:$CI_JOB_ID .
|
|
after_script:
|
|
- docker rmi chat-ci:$CI_JOB_ID || true
|
|
|
|
test:
|
|
stage: test
|
|
image: debian:13
|
|
tags:
|
|
- local
|
|
services:
|
|
# no PostGIS needed: the settings use the plain postgresql backend
|
|
- name: postgres:17
|
|
alias: chat_db
|
|
- name: redis:7
|
|
alias: redis
|
|
rules:
|
|
- if: $CI_PIPELINE_SOURCE == "merge_request_event"
|
|
- if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH
|
|
cache:
|
|
key: pip
|
|
paths:
|
|
- .cache/pip
|
|
variables:
|
|
PIP_CACHE_DIR: $CI_PROJECT_DIR/.cache/pip
|
|
# postgres service
|
|
POSTGRES_USER: ci
|
|
POSTGRES_PASSWORD: ci-password
|
|
POSTGRES_DB: chat_db
|
|
# app settings; dummy values only, real secrets never belong in a test job
|
|
DEBUG: "true"
|
|
DB_NAME: chat_db
|
|
DB_USER: ci
|
|
DB_PASSWORD: ci-password
|
|
DB_HOST: chat_db
|
|
DB_PORT: "5432"
|
|
REDIS_BASE_URL: redis://redis:6379/1
|
|
ACCOUNTS_BASE_PUBLIC_URL: https://accounts.invalid
|
|
OAUTH2_PROVIDER_BASE_PUBLIC_URL: https://accounts.invalid/oauth2
|
|
OAUTH2_PROVIDER_BASE_PRIVATE_URL: https://accounts.invalid/oauth2
|
|
OAUTH2_PROVIDER_CLIENT_ID: ci
|
|
OAUTH2_PROVIDER_CLIENT_SECRET: ci
|
|
MINIO_ENDPOINT: minio.invalid
|
|
MINIO_ACCESS_KEY: ci
|
|
MINIO_SECRET_KEY: ci
|
|
before_script:
|
|
# keep in sync with the Dockerfile
|
|
- apt-get update
|
|
- apt-get install -y python3 python3-pip binutils libproj-dev gdal-bin
|
|
- pip3 install --break-system-packages --ignore-installed -r requirements.txt
|
|
- pip3 install --break-system-packages setuptools
|
|
script:
|
|
- python3 manage.py check
|
|
- python3 manage.py makemigrations --check --dry-run
|
|
# the suite is pytest-style; `manage.py test` would silently run 0 tests
|
|
- python3 -m pytest -q --junitxml=report.xml
|
|
artifacts:
|
|
when: always
|
|
reports:
|
|
junit: report.xml
|
|
|
|
# Runs on the staging host through a shell runner tagged `staging` that can use
|
|
# the docker CLI. The compose stack keeps a git checkout of this repo (mounted
|
|
# at /app), so this updates that checkout and restarts the service.
|
|
# Set DEPLOY_DIR in Settings > CI/CD > Variables (the directory that holds
|
|
# docker-compose.yml). DEPLOY_CHECKOUT and DEPLOY_SERVICE default to `chat`;
|
|
# override them there if the checkout directory or compose service is named
|
|
# differently.
|
|
deploy_staging:
|
|
stage: deploy
|
|
tags:
|
|
- staging
|
|
rules:
|
|
- if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH
|
|
when: manual
|
|
allow_failure: true # otherwise the pipeline shows "blocked" until someone deploys
|
|
resource_group: staging # never run two deploys at once
|
|
environment:
|
|
name: staging
|
|
variables:
|
|
DEPLOY_CHECKOUT: chat
|
|
DEPLOY_SERVICE: chat
|
|
script:
|
|
- cd "${DEPLOY_DIR:?set DEPLOY_DIR in Settings > CI/CD > Variables}"
|
|
- git -C "$DEPLOY_CHECKOUT" pull --ff-only origin "$CI_DEFAULT_BRANCH"
|
|
- docker compose up -d --build "$DEPLOY_SERVICE"
|