From 22d69657b2442d4e72cc9fb6319dafe63836c42d Mon Sep 17 00:00:00 2001 From: Flea Flicker Date: Thu, 21 May 2026 12:49:21 +0000 Subject: [PATCH] ci: move .github/workflows to .gitea/workflows for Gitea Actions --- receiptwitness/.gitea/workflows/ci.yml | 626 +++++++++++++++++++++++++ 1 file changed, 626 insertions(+) create mode 100644 receiptwitness/.gitea/workflows/ci.yml diff --git a/receiptwitness/.gitea/workflows/ci.yml b/receiptwitness/.gitea/workflows/ci.yml new file mode 100644 index 0000000..8f6b2ee --- /dev/null +++ b/receiptwitness/.gitea/workflows/ci.yml @@ -0,0 +1,626 @@ +name: CI + +on: + push: + branches: [main, dev, uat] + pull_request: + branches: [main, dev, uat] + +concurrency: + group: ci-{gitea.ref} + cancel-in-progress: true + +env: + REGISTRY: ghcr.io + IMAGE_NAME: cartsnitch/cartsnitch + RECEIPTWITNESS_IMAGE_NAME: cartsnitch/receiptwitness + API_IMAGE_NAME: cartsnitch/api + AUTH_IMAGE_NAME: cartsnitch/auth + +jobs: + lint: + runs-on: ubuntu-latest + steps: + - uses: https://github.com/actions/checkout@v4 + - uses: https://github.com/actions/setup-node@v4 + with: + node-version: "20" + cache: npm + - run: npm ci + - name: ESLint + run: npx eslint . + - name: Type check + run: npx tsc --noEmit + + test: + runs-on: ubuntu-latest + steps: + - uses: https://github.com/actions/checkout@v4 + - uses: https://github.com/actions/setup-node@v4 + with: + node-version: "20" + cache: npm + - run: npm ci + - name: Run tests + run: npx vitest run + + audit: + runs-on: ubuntu-latest + steps: + - uses: https://github.com/actions/checkout@v4 + - uses: https://github.com/actions/setup-node@v4 + with: + node-version: "20" + cache: npm + - run: npm ci + - name: Check for vulnerabilities + run: npm audit --audit-level=high + + e2e: + runs-on: ubuntu-latest + steps: + - uses: https://github.com/actions/checkout@v4 + - uses: https://github.com/actions/setup-node@v4 + with: + node-version: "20" + cache: npm + - run: npm ci + - run: npx playwright install --with-deps chromium + - run: npx playwright test + + lighthouse: + runs-on: ubuntu-latest + needs: [test] + steps: + - uses: https://github.com/actions/checkout@v4 + - uses: https://github.com/actions/setup-node@v4 + with: + node-version: "20" + cache: npm + - run: npm ci + - run: npm run build + - name: Install Chromium for Lighthouse + run: | + npm install -g playwright + npx playwright install --with-deps chromium + - name: Start preview server + run: | + npm run preview & + npx wait-on http://localhost:4173/ --timeout 30000 + - name: Run Lighthouse CI + run: | + CHROME_PATH=$(find /home/runner/.cache/ms-playwright -name chrome -type f 2>/dev/null | head -1) + npm install -g @lhci/cli + CHROME_PATH="$CHROME_PATH" lhci autorun --chrome-flags="--headless=new --no-sandbox --disable-gpu --disable-dev-shm-usage" + + build-and-push: + runs-on: ubuntu-latest + if: gitea.event == 'push' + needs: [lint, test, e2e] + outputs: + calver_tag: {_calver_version_} + sha_tag: sha-{gitea.sha} + steps: + - uses: https://github.com/actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Generate CalVer tag + id: calver + if: gitea.event == 'push' && gitea.ref == 'refs/heads/main' + run: | + DATE_TAG=$(date -u +%Y.%m.%d) + EXISTING=$(git tag -l "v${DATE_TAG}*" | sort -V | tail -1) + if [ -z "$EXISTING" ]; then + VERSION="$DATE_TAG" + elif [ "$EXISTING" = "v${DATE_TAG}" ]; then + VERSION="${DATE_TAG}.2" + else + BUILD_NUM=$(echo "$EXISTING" | sed "s/v${DATE_TAG}\.//") + VERSION="${DATE_TAG}.$((BUILD_NUM + 1))" + fi + echo "_calver_version_=$VERSION" >> "$GITHUB_OUTPUT" + echo "CalVer tag: $VERSION" + + - name: Log in to Docker Hub + if: gitea.event == 'push' + uses: https://github.com/docker/login-action@v3 + with: + username: '{'{ secrets.DOCKERHUB_USERNAME }'}' + password: '{'{ secrets.DOCKERHUB_TOKEN }'}' + + - name: Log in to GHCR + if: gitea.event == 'push' + uses: https://github.com/docker/login-action@v3 + with: + registry: ${{ env.REGISTRY }} + username: ${{ gitea.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Extract metadata + id: meta + uses: https://github.com/docker/metadata-action@v5 + with: + images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} + tags: | + type=sha,prefix=sha-,format=long + type=raw,value=${{ steps.calver.outputs.calver_tag }},enable=${{ gitea.ref == 'refs/heads/main' }} + type=raw,value=latest,enable=${{ gitea.ref == 'refs/heads/main' }} + + - name: Build Docker image + uses: https://github.com/docker/build-push-action@v6 + with: + context: . + load: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + target: prod + cache-from: type=gha + cache-to: type=gha,mode=max + + - name: Scan frontend image for vulnerabilities + uses: https://github.com/anchore/scan-action@v5 + id: scan + env: + GRYPE_CONFIG: .grype.yaml + with: + image: "${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:sha-${{ gitea.sha }}" + fail-build: true + severity-cutoff: high + only-fixed: "true" + output-format: sarif + + + + - name: Push Docker image + if: gitea.event == 'push' + uses: https://github.com/docker/build-push-action@v6 + with: + context: . + push: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + target: prod + cache-from: type=gha + + - name: Create git tag + if: gitea.event == 'push' && gitea.ref == 'refs/heads/main' + run: | + git tag "v${{ steps.calver.outputs.calver_tag }}" + git push origin "v${{ steps.calver.outputs.calver_tag }}" + + build-and-push-receiptwitness: + runs-on: ubuntu-latest + if: gitea.event == 'push' + needs: [lint, test] + outputs: + calver_tag: {calver.outputs.calver_tag} + sha_tag: sha-{gitea.sha} + steps: + - uses: https://github.com/actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Generate CalVer tag + id: calver + if: gitea.event == 'push' && gitea.ref == 'refs/heads/main' + run: | + DATE_TAG=$(date -u +%Y.%m.%d) + EXISTING=$(git tag -l "v${DATE_TAG}*" | sort -V | tail -1) + if [ -z "$EXISTING" ]; then VERSION="$DATE_TAG" + elif [ "$EXISTING" = "v${DATE_TAG}" ]; then VERSION="${DATE_TAG}.2" + else BUILD_NUM=$(echo "$EXISTING" | sed "s/v${DATE_TAG}\.//"); VERSION="${DATE_TAG}.$((BUILD_NUM + 1))"; fi + echo "calver_tag=$VERSION" >> "$GITHUB_OUTPUT" + + - name: Log in to Docker Hub + if: gitea.event == 'push' + uses: https://github.com/docker/login-action@v3 + with: + username: '{'{ secrets.DOCKERHUB_USERNAME }'}' + password: '{'{ secrets.DOCKERHUB_TOKEN }'}' + + - name: Log in to GHCR + if: gitea.event == 'push' + uses: https://github.com/docker/login-action@v3 + with: + registry: ${{ env.REGISTRY }} + username: ${{ gitea.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Extract metadata + id: meta + uses: https://github.com/docker/metadata-action@v5 + with: + images: ${{ env.REGISTRY }}/${{ env.RECEIPTWITNESS_IMAGE_NAME }} + tags: | + type=sha,prefix=sha-,format=long + type=raw,value=${{ steps.calver.outputs.calver_tag }},enable=${{ gitea.ref == 'refs/heads/main' }} + type=raw,value=latest,enable=${{ gitea.ref == 'refs/heads/main' }} + + - name: Build Docker image + uses: https://github.com/docker/build-push-action@v6 + with: + context: . + file: ./Dockerfile + load: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + build-args: | + APT_CACHE_BUST=${{ gitea.run_id }} + cache-from: type=gha + cache-to: type=gha,mode=max + + - name: Scan receiptwitness image for vulnerabilities + uses: https://github.com/anchore/scan-action@v5 + id: scan + env: + GRYPE_CONFIG: .grype.yaml + with: + image: "${{ env.REGISTRY }}/${{ env.RECEIPTWITNESS_IMAGE_NAME }}:sha-${{ gitea.sha }}" + fail-build: true + severity-cutoff: high + only-fixed: "true" + output-format: sarif + + + + - name: Push Docker image + if: gitea.event == 'push' + uses: https://github.com/docker/build-push-action@v6 + with: + context: . + file: ./Dockerfile + push: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + build-args: | + APT_CACHE_BUST=${{ gitea.run_id }} + cache-from: type=gha + + build-and-push-api: + runs-on: ubuntu-latest + if: gitea.event == 'push' + needs: [lint, test] + outputs: + calver_tag: {calver.outputs.calver_tag} + sha_tag: sha-{gitea.sha} + steps: + - uses: https://github.com/actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Generate CalVer tag + id: calver + if: gitea.event == 'push' && gitea.ref == 'refs/heads/main' + run: | + DATE_TAG=$(date -u +%Y.%m.%d) + EXISTING=$(git tag -l "v${DATE_TAG}*" | sort -V | tail -1) + if [ -z "$EXISTING" ]; then VERSION="$DATE_TAG" + elif [ "$EXISTING" = "v${DATE_TAG}" ]; then VERSION="${DATE_TAG}.2" + else BUILD_NUM=$(echo "$EXISTING" | sed "s/v${DATE_TAG}\.//"); VERSION="${DATE_TAG}.$((BUILD_NUM + 1))"; fi + echo "calver_tag=$VERSION" >> "$GITHUB_OUTPUT" + + - name: Log in to Docker Hub + if: gitea.event == 'push' + uses: https://github.com/docker/login-action@v3 + with: + username: '{'{ secrets.DOCKERHUB_USERNAME }'}' + password: '{'{ secrets.DOCKERHUB_TOKEN }'}' + + - name: Log in to GHCR + if: gitea.event == 'push' + uses: https://github.com/docker/login-action@v3 + with: + registry: ${{ env.REGISTRY }} + username: ${{ gitea.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Extract metadata (API) + id: meta + uses: https://github.com/docker/metadata-action@v5 + with: + images: ${{ env.REGISTRY }}/${{ env.API_IMAGE_NAME }} + tags: | + type=sha,prefix=sha-,format=long + type=raw,value=${{ steps.calver.outputs.calver_tag }},enable=${{ gitea.ref == 'refs/heads/main' }} + type=raw,value=latest,enable=${{ gitea.ref == 'refs/heads/main' }} + + - name: Build Docker image + uses: https://github.com/docker/build-push-action@v6 + with: + context: ./api + file: ./api/Dockerfile + load: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + build-args: | + APT_CACHE_BUST=${{ gitea.run_id }} + cache-from: type=gha + cache-to: type=gha,mode=max + + - name: Scan api image for vulnerabilities + uses: https://github.com/anchore/scan-action@v5 + id: scan + env: + GRYPE_CONFIG: .grype.yaml + with: + image: "${{ env.REGISTRY }}/${{ env.API_IMAGE_NAME }}:sha-${{ gitea.sha }}" + fail-build: true + severity-cutoff: high + only-fixed: "true" + output-format: sarif + + + + - name: Push Docker image + if: gitea.event == 'push' + uses: https://github.com/docker/build-push-action@v6 + with: + context: ./api + file: ./api/Dockerfile + push: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + build-args: | + APT_CACHE_BUST=${{ gitea.run_id }} + cache-from: type=gha + + build-and-push-auth: + runs-on: ubuntu-latest + if: gitea.event == 'push' + needs: [lint, test] + outputs: + calver_tag: {calver.outputs.calver_tag} + sha_tag: sha-{gitea.sha} + steps: + - uses: https://github.com/actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Generate CalVer tag + id: calver + if: gitea.event == 'push' && gitea.ref == 'refs/heads/main' + run: | + DATE_TAG=$(date -u +%Y.%m.%d) + EXISTING=$(git tag -l "v${DATE_TAG}*" | sort -V | tail -1) + if [ -z "$EXISTING" ]; then VERSION="$DATE_TAG" + elif [ "$EXISTING" = "v${DATE_TAG}" ]; then VERSION="${DATE_TAG}.2" + else BUILD_NUM=$(echo "$EXISTING" | sed "s/v${DATE_TAG}\.//"); VERSION="${DATE_TAG}.$((BUILD_NUM + 1))"; fi + echo "calver_tag=$VERSION" >> "$GITHUB_OUTPUT" + + - name: Log in to Docker Hub + if: gitea.event == 'push' + uses: https://github.com/docker/login-action@v3 + with: + username: '{'{ secrets.DOCKERHUB_USERNAME }'}' + password: '{'{ secrets.DOCKERHUB_TOKEN }'}' + + - name: Log in to GHCR + if: gitea.event == 'push' + uses: https://github.com/docker/login-action@v3 + with: + registry: ${{ env.REGISTRY }} + username: ${{ gitea.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Extract metadata (auth) + id: meta + uses: https://github.com/docker/metadata-action@v5 + with: + images: ${{ env.REGISTRY }}/${{ env.AUTH_IMAGE_NAME }} + tags: | + type=sha,prefix=sha-,format=long + type=raw,value=${{ steps.calver.outputs.calver_tag }},enable=${{ gitea.ref == 'refs/heads/main' }} + type=raw,value=latest,enable=${{ gitea.ref == 'refs/heads/main' }} + + - name: Build Docker image + uses: https://github.com/docker/build-push-action@v6 + with: + context: ./auth + file: ./auth/Dockerfile + load: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + build-args: | + APT_CACHE_BUST=${{ gitea.run_id }} + cache-from: type=gha + cache-to: type=gha,mode=max + + - name: Scan auth image for vulnerabilities + uses: https://github.com/anchore/scan-action@v5 + id: scan + env: + GRYPE_CONFIG: .grype.yaml + with: + image: "${{ env.REGISTRY }}/${{ env.AUTH_IMAGE_NAME }}:sha-${{ gitea.sha }}" + fail-build: true + severity-cutoff: high + only-fixed: "true" + output-format: sarif + + + + - name: Push Docker image + if: gitea.event == 'push' + uses: https://github.com/docker/build-push-action@v6 + with: + context: ./auth + file: ./auth/Dockerfile + push: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + build-args: | + APT_CACHE_BUST=${{ gitea.run_id }} + cache-from: type=gha + + deploy-dev: + runs-on: ubuntu-latest + needs: [build-and-push, build-and-push-receiptwitness, build-and-push-api, build-and-push-auth] + if: gitea.event == 'push' && (gitea.ref == 'refs/heads/dev' || gitea.ref == 'refs/heads/main') + steps: + - name: Checkout infra repo + uses: https://github.com/actions/checkout@v4 + with: + repository: cartsnitch/infra + token: ${{ secrets.GITEA_TOKEN }} + ref: main + path: infra + + - name: Install kubectl + uses: azure/setup-kubectl@v4 + + - name: Install kustomize + uses: imranismail/setup-kustomize@v2 + + - name: Determine image tag for frontend + id: frontend_tag + run: | + if [ "${{ gitea.ref }}" == "refs/heads/main" ]; then + echo "tag=${{ needs.build-and-push.outputs.calver_tag }}" >> "$GITHUB_OUTPUT" + else + echo "tag=${{ needs.build-and-push.outputs.sha_tag }}" >> "$GITHUB_OUTPUT" + fi + + - name: Update frontend image tag + run: | + cd infra/apps/overlays/dev + kustomize edit set image ghcr.io/cartsnitch/cartsnitch:${{ steps.frontend_tag.outputs.tag }} + + - name: Determine image tag for receiptwitness + id: receiptwitness_tag + run: | + if [ "${{ gitea.ref }}" == "refs/heads/main" ]; then + echo "tag=${{ needs.build-and-push-receiptwitness.outputs.calver_tag }}" >> "$GITHUB_OUTPUT" + else + echo "tag=${{ needs.build-and-push-receiptwitness.outputs.sha_tag }}" >> "$GITHUB_OUTPUT" + fi + + - name: Update receiptwitness image tag + run: | + cd infra/apps/overlays/dev + kustomize edit set image ghcr.io/cartsnitch/receiptwitness:${{ steps.receiptwitness_tag.outputs.tag }} + + - name: Determine image tag for api + id: api_tag + run: | + if [ "${{ gitea.ref }}" == "refs/heads/main" ]; then + echo "tag=${{ needs.build-and-push-api.outputs.calver_tag }}" >> "$GITHUB_OUTPUT" + else + echo "tag=${{ needs.build-and-push-api.outputs.sha_tag }}" >> "$GITHUB_OUTPUT" + fi + + - name: Update api image tag + run: | + cd infra/apps/overlays/dev + kustomize edit set image ghcr.io/cartsnitch/api:${{ steps.api_tag.outputs.tag }} + + - name: Determine image tag for auth + id: auth_tag + run: | + if [ "${{ gitea.ref }}" == "refs/heads/main" ]; then + echo "tag=${{ needs.build-and-push-auth.outputs.calver_tag }}" >> "$GITHUB_OUTPUT" + else + echo "tag=${{ needs.build-and-push-auth.outputs.sha_tag }}" >> "$GITHUB_OUTPUT" + fi + + - name: Update auth image tag + run: | + cd infra/apps/overlays/dev + kustomize edit set image ghcr.io/cartsnitch/auth:${{ steps.auth_tag.outputs.tag }} + + - name: Commit and push to infra + run: | + cd infra + git config user.name "cartsnitch-ci[bot]" + git config user.email "cartsnitch-ci[bot]@users.noreply.github.com" + git add apps/overlays/dev/kustomization.yaml + git diff --cached --quiet && echo "No image changes to deploy" && exit 0 + git commit -m "ci(dev): update cartsnitch, receiptwitness, api, and auth images" + git pull --rebase origin main + git push origin main + + deploy-uat: + runs-on: ubuntu-latest + needs: [build-and-push, build-and-push-receiptwitness, build-and-push-api, build-and-push-auth] + if: gitea.event == 'push' && (gitea.ref == 'refs/heads/uat' || gitea.ref == 'refs/heads/main') + steps: + - name: Checkout infra repo + uses: https://github.com/actions/checkout@v4 + with: + repository: cartsnitch/infra + token: ${{ secrets.GITEA_TOKEN }} + ref: main + path: infra + + - name: Install kubectl + uses: azure/setup-kubectl@v4 + + - name: Install kustomize + uses: imranismail/setup-kustomize@v2 + + - name: Determine image tag for frontend + id: frontend_tag + run: | + if [ "${{ gitea.ref }}" == "refs/heads/main" ]; then + echo "tag=${{ needs.build-and-push.outputs.calver_tag }}" >> "$GITHUB_OUTPUT" + else + echo "tag=${{ needs.build-and-push.outputs.sha_tag }}" >> "$GITHUB_OUTPUT" + fi + + - name: Update frontend image tag + run: | + cd infra/apps/overlays/uat + kustomize edit set image ghcr.io/cartsnitch/cartsnitch:${{ steps.frontend_tag.outputs.tag }} + + - name: Determine image tag for receiptwitness + id: receiptwitness_tag + run: | + if [ "${{ gitea.ref }}" == "refs/heads/main" ]; then + echo "tag=${{ needs.build-and-push-receiptwitness.outputs.calver_tag }}" >> "$GITHUB_OUTPUT" + else + echo "tag=${{ needs.build-and-push-receiptwitness.outputs.sha_tag }}" >> "$GITHUB_OUTPUT" + fi + + - name: Update receiptwitness image tag + run: | + cd infra/apps/overlays/uat + kustomize edit set image ghcr.io/cartsnitch/receiptwitness:${{ steps.receiptwitness_tag.outputs.tag }} + + - name: Determine image tag for api + id: api_tag + run: | + if [ "${{ gitea.ref }}" == "refs/heads/main" ]; then + echo "tag=${{ needs.build-and-push-api.outputs.calver_tag }}" >> "$GITHUB_OUTPUT" + else + echo "tag=${{ needs.build-and-push-api.outputs.sha_tag }}" >> "$GITHUB_OUTPUT" + fi + + - name: Update api image tag + run: | + cd infra/apps/overlays/uat + kustomize edit set image ghcr.io/cartsnitch/api:${{ steps.api_tag.outputs.tag }} + + - name: Determine image tag for auth + id: auth_tag + run: | + if [ "${{ gitea.ref }}" == "refs/heads/main" ]; then + echo "tag=${{ needs.build-and-push-auth.outputs.calver_tag }}" >> "$GITHUB_OUTPUT" + else + echo "tag=${{ needs.build-and-push-auth.outputs.sha_tag }}" >> "$GITHUB_OUTPUT" + fi + + - name: Update auth image tag + run: | + cd infra/apps/overlays/uat + kustomize edit set image ghcr.io/cartsnitch/auth:${{ steps.auth_tag.outputs.tag }} + + - name: Commit and push to infra + run: | + cd infra + git config user.name "cartsnitch-ci[bot]" + git config user.email "cartsnitch-ci[bot]@users.noreply.github.com" + git add apps/overlays/uat/kustomization.yaml + git diff --cached --quiet && echo "No image changes to deploy" && exit 0 + git commit -m "ci(uat): update cartsnitch, receiptwitness, api, and auth images" + git pull --rebase origin main + git push origin main \ No newline at end of file