4
0

e2e.yml 8.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230
  1. name: End-to-end tests
  2. on:
  3. pull_request:
  4. branches: [main]
  5. workflow_dispatch:
  6. # A second push to the same branch makes the run in flight pointless.
  7. concurrency:
  8. group: e2e-${{ github.ref }}
  9. cancel-in-progress: true
  10. # The suite runs one test at a time against one seeded database, so more
  11. # workers would only trip over each other. More databases do not: resetting
  12. # and seeding one takes about fifteen seconds. So the specs are split across
  13. # shards, each on its own runner with its own database, and the cloud specs
  14. # run beside them. The last job merges what they found into one report and is
  15. # the one check a pull request waits on.
  16. jobs:
  17. e2e:
  18. name: Playwright (${{ matrix.name }})
  19. runs-on: ubuntu-latest
  20. timeout-minutes: 30
  21. strategy:
  22. # A failure in one shard says nothing about the others; let them finish.
  23. fail-fast: false
  24. matrix:
  25. include:
  26. - { id: shard-1, name: shard 1 of 4, shard: 1/4 }
  27. - { id: shard-2, name: shard 2 of 4, shard: 2/4 }
  28. - { id: shard-3, name: shard 3 of 4, shard: 3/4 }
  29. - { id: shard-4, name: shard 4 of 4, shard: 4/4 }
  30. # The same build started in cloud mode: plan limits, the sign-up
  31. # pitch and Google sign-in only exist there.
  32. - { id: cloud, name: cloud, mode: cloud }
  33. services:
  34. postgres:
  35. image: postgres:16-alpine
  36. env:
  37. POSTGRES_USER: torqvoice
  38. POSTGRES_PASSWORD: torqvoice
  39. # The name has to carry "e2e" or "test": the harness refuses to reset
  40. # a database whose name says nothing about being throwaway.
  41. POSTGRES_DB: torqvoice_e2e
  42. ports:
  43. - 5432:5432
  44. options: >-
  45. --health-cmd "pg_isready -U torqvoice -d torqvoice_e2e"
  46. --health-interval 10s
  47. --health-timeout 5s
  48. --health-retries 5
  49. env:
  50. # Playwright starts the app itself on this port and resets this database
  51. # before it does; both come from playwright.config.ts.
  52. E2E_DATABASE_URL: postgresql://torqvoice:torqvoice@127.0.0.1:5432/torqvoice_e2e
  53. E2E_MODE: ${{ matrix.mode }}
  54. # The cloud job mints a one-day cloud token from it; without the token the
  55. # app ignores TORQVOICE_MODE=cloud. Only the cloud job gets it.
  56. TORQVOICE_COM_LICENSE_SIGNING_PRIVATE_KEY: ${{ matrix.mode == 'cloud' && secrets.TORQVOICE_COM_LICENSE_SIGNING_PRIVATE_KEY || '' }}
  57. steps:
  58. # A pull request from a fork gets no secrets, so the cloud job has no key
  59. # to mint its cloud token with and the app would refuse cloud mode. That
  60. # says nothing about the contribution, so the job skips instead of failing.
  61. # The self-hosted shards need no key and always run.
  62. - name: Check for the cloud signing key
  63. id: gate
  64. run: |
  65. if [ "${{ matrix.mode }}" = "cloud" ] && [ -z "$TORQVOICE_COM_LICENSE_SIGNING_PRIVATE_KEY" ]; then
  66. echo "::notice title=Cloud specs skipped::No TORQVOICE_COM_LICENSE_SIGNING_PRIVATE_KEY here (a fork or Dependabot pull request), so the cloud specs cannot run."
  67. echo "run=false" >> "$GITHUB_OUTPUT"
  68. else
  69. echo "run=true" >> "$GITHUB_OUTPUT"
  70. fi
  71. - uses: actions/checkout@v4
  72. if: ${{ steps.gate.outputs.run == 'true' }}
  73. - uses: actions/setup-node@v4
  74. if: ${{ steps.gate.outputs.run == 'true' }}
  75. with:
  76. node-version: 22
  77. cache: npm
  78. # A fresh one per run: the sessions it signs live as long as the job, and
  79. # a short or guessable value makes better-auth warn on every request.
  80. - name: Make a session secret for this run
  81. if: ${{ steps.gate.outputs.run == 'true' }}
  82. run: echo "BETTER_AUTH_SECRET=$(openssl rand -base64 32)" >> "$GITHUB_ENV"
  83. - run: npm ci
  84. if: ${{ steps.gate.outputs.run == 'true' }}
  85. - run: npx prisma generate
  86. if: ${{ steps.gate.outputs.run == 'true' }}
  87. # Keyed on the pinned version, because the image tag and this download
  88. # have to be the same build.
  89. - name: Cache the browser
  90. if: ${{ steps.gate.outputs.run == 'true' }}
  91. uses: actions/cache@v4
  92. with:
  93. path: ~/.cache/ms-playwright
  94. key: playwright-${{ runner.os }}-${{ hashFiles('package-lock.json') }}
  95. - name: Install the browser
  96. if: ${{ steps.gate.outputs.run == 'true' }}
  97. run: npx playwright install --with-deps chromium
  98. # The seed copies bundled vehicle photos when they are in the tree and
  99. # downloads fifty of them from Unsplash when they are not, one after
  100. # another, which is minutes of a cold run and the flakiest thing in it.
  101. # Cached, a warm run copies them off disk instead.
  102. - name: Cache the seed's photos
  103. if: ${{ steps.gate.outputs.run == 'true' }}
  104. uses: actions/cache@v4
  105. with:
  106. # Where prepare-db.ts points the seed's DATA_ROOT, so a test run
  107. # cannot disturb a running instance's own uploads.
  108. path: e2e/.data
  109. key: seed-photos-${{ hashFiles('prisma/seed_dummy_data.ts') }}
  110. restore-keys: |
  111. seed-photos-
  112. # Next reuses its compiler cache across builds when it is given one.
  113. # Every job reads it; only the first shard writes it back, so five jobs
  114. # do not race to save the same entry.
  115. - name: Restore the build cache
  116. if: ${{ steps.gate.outputs.run == 'true' }}
  117. uses: actions/cache/restore@v4
  118. with:
  119. path: .next/cache
  120. key: next-${{ hashFiles('package-lock.json') }}-${{ github.sha }}
  121. restore-keys: |
  122. next-${{ hashFiles('package-lock.json') }}-
  123. next-
  124. # NEXT_PUBLIC_APP_URL is baked into the client bundle, and better-auth
  125. # refuses a sign-in from an origin the build was not made for, so it has
  126. # to match the base URL the suite uses.
  127. - name: Build
  128. if: ${{ steps.gate.outputs.run == 'true' }}
  129. run: npm run build
  130. env:
  131. NEXT_PUBLIC_APP_URL: http://127.0.0.1:3100
  132. - name: Save the build cache
  133. if: ${{ steps.gate.outputs.run == 'true' && (matrix.id == 'shard-1') }}
  134. uses: actions/cache/save@v4
  135. with:
  136. path: .next/cache
  137. key: next-${{ hashFiles('package-lock.json') }}-${{ github.sha }}
  138. - name: Run the specs
  139. if: ${{ steps.gate.outputs.run == 'true' }}
  140. run: npx playwright test ${{ matrix.shard && format('--shard={0}', matrix.shard) || '' }}
  141. # The blob carries the results with their traces, screenshots and videos;
  142. # the report job turns every job's blob into one HTML report.
  143. - name: Upload the blob report
  144. if: ${{ steps.gate.outputs.run == 'true' && (!cancelled()) }}
  145. uses: actions/upload-artifact@v4
  146. with:
  147. name: blob-report-${{ matrix.id }}
  148. path: blob-report/
  149. retention-days: 1
  150. if-no-files-found: ignore
  151. report:
  152. # Named as the single job used to be, so a required check keeps its name.
  153. name: Playwright
  154. needs: e2e
  155. if: ${{ !cancelled() }}
  156. runs-on: ubuntu-latest
  157. timeout-minutes: 10
  158. steps:
  159. - uses: actions/checkout@v4
  160. - uses: actions/setup-node@v4
  161. with:
  162. node-version: 22
  163. cache: npm
  164. - run: npm ci
  165. - name: Download the blob reports
  166. uses: actions/download-artifact@v4
  167. with:
  168. pattern: blob-report-*
  169. path: all-blob-reports
  170. # Each job's blob lands in a folder of its own. The merge wants them side
  171. # by side, and two jobs may give their file the same name.
  172. - name: Gather the blobs
  173. run: |
  174. mkdir -p blob-reports
  175. for dir in all-blob-reports/*/; do
  176. [ -d "$dir" ] || continue
  177. job=$(basename "$dir")
  178. for file in "$dir"*.zip; do
  179. [ -e "$file" ] || continue
  180. mv "$file" "blob-reports/${job}-$(basename "$file")"
  181. done
  182. done
  183. ls -la blob-reports
  184. - name: Merge the reports
  185. run: npx playwright merge-reports --reporter html ./blob-reports
  186. - name: Upload the report
  187. uses: actions/upload-artifact@v4
  188. with:
  189. name: playwright-report
  190. path: playwright-report/
  191. retention-days: 7
  192. if-no-files-found: ignore
  193. # Green only when every shard and the cloud specs are.
  194. - name: Every job passed
  195. if: ${{ always() }}
  196. run: |
  197. if [ "${{ needs.e2e.result }}" != "success" ]; then
  198. echo "The e2e jobs finished as: ${{ needs.e2e.result }}"
  199. exit 1
  200. fi