| 1 | # Tests every pull request into main, so main can always be deployed. The |
| 2 | # "Default branch" ruleset requires this workflow ("CI") to pass before a |
| 3 | # pull request merges; people may still push to main directly, agents |
| 4 | # may not. Deploy (deploy.yml) ships what lands on main. |
| 5 | # |
| 6 | # rust every crate's tests, natively |
| 7 | # typescript type checks and tests of the apps and TS services, the |
| 8 | # deploy and ops scripts, and the deploy manifest |
| 9 | # build the site, sudo and the docs build as they deploy |
| 10 | # |
| 11 | # On a push to main only `rust` runs, to keep main's caches current: a pull |
| 12 | # request's run restores from main's cache, never from another pull |
| 13 | # request's, so without it each pull request would start from nothing. |
| 14 | name: CI |
| 15 | |
| 16 | on: |
| 17 | pull_request: |
| 18 | branches: [main] |
| 19 | push: |
| 20 | branches: [main] |
| 21 | workflow_dispatch: |
| 22 | |
| 23 | # Its token only reads: it checks the code out and nothing more. |
| 24 | permissions: |
| 25 | contents: read |
| 26 | |
| 27 | concurrency: |
| 28 | group: ci-${{ github.ref }} |
| 29 | cancel-in-progress: true |
| 30 | |
| 31 | env: |
| 32 | CARGO_TERM_COLOR: never |
| 33 | WRANGLER_SEND_METRICS: "false" |
| 34 | |
| 35 | jobs: |
| 36 | rust: |
| 37 | name: Rust |
| 38 | runs-on: g1t-4core |
| 39 | timeout-minutes: 45 |
| 40 | steps: |
| 41 | - uses: actions/checkout@v5 |
| 42 | - name: Cache crates |
| 43 | uses: actions/cache@v4 |
| 44 | with: |
| 45 | path: ~/.cargo/registry/cache |
| 46 | key: cargo-crates-${{ runner.os }}-${{ hashFiles('Cargo.lock') }} |
| 47 | restore-keys: cargo-crates-${{ runner.os }}- |
| 48 | - name: Cache the test build |
| 49 | uses: actions/cache@v4 |
| 50 | with: |
| 51 | path: | |
| 52 | target/debug |
| 53 | !target/debug/incremental |
| 54 | key: cargo-test-${{ runner.os }}-${{ hashFiles('Cargo.lock', 'services/runner/base.json') }} |
| 55 | restore-keys: cargo-test-${{ runner.os }}- |
| 56 | # The workspace's library crates, which Cargo compiles again on every |
| 57 | # checkout, come back from the repository's Actions cache when their |
| 58 | # inputs did not change (scripts/sccache.sh). Test harnesses and |
| 59 | # Workers' own crates are linked, and still compiled. |
| 60 | - name: sccache |
| 61 | run: bash scripts/sccache.sh install |
| 62 | - name: Tests |
| 63 | run: cargo test --workspace --locked --quiet |
| 64 | - name: sccache's hits and misses |
| 65 | if: ${{ always() }} |
| 66 | run: bash scripts/sccache.sh stats |
| 67 | |
| 68 | typescript: |
| 69 | name: TypeScript |
| 70 | if: ${{ github.event_name != 'push' }} |
| 71 | runs-on: ubuntu-latest |
| 72 | timeout-minutes: 30 |
| 73 | steps: |
| 74 | - uses: actions/checkout@v5 |
| 75 | - name: Install |
| 76 | run: npm ci --no-audit --no-fund |
| 77 | - name: Type checks |
| 78 | run: npm run typecheck |
| 79 | - name: Tests |
| 80 | run: npm test --workspaces --if-present |
| 81 | - name: The deploy tool's tests |
| 82 | run: npm run test:deploy |
| 83 | - name: The ops scripts' tests |
| 84 | run: npm run test:ops |
| 85 | - name: The manifest matches every wrangler.jsonc |
| 86 | run: node scripts/deploy.mjs manifest --check |
| 87 | |
| 88 | build: |
| 89 | name: Build |
| 90 | if: ${{ github.event_name != 'push' }} |
| 91 | runs-on: ubuntu-latest |
| 92 | timeout-minutes: 30 |
| 93 | steps: |
| 94 | - uses: actions/checkout@v5 |
| 95 | - name: Install |
| 96 | run: npm ci --no-audit --no-fund |
| 97 | - name: The site, sudo and the docs |
| 98 | run: node scripts/deploy.mjs build --only web,sudo,docs |