Files
cleveragents-core/features/ci_workflow_validation.feature
brent.edwards 00897be24a
CI / build (push) Successful in 21s
CI / lint (push) Successful in 3m30s
CI / typecheck (push) Successful in 3m55s
CI / benchmark-regression (push) Has been skipped
CI / security (push) Successful in 3m57s
CI / quality (push) Successful in 3m59s
CI / integration_tests (push) Successful in 5m52s
CI / e2e_tests (push) Successful in 8m15s
CI / coverage (push) Failing after 13m33s
CI / unit_tests (push) Failing after 17m29s
CI / benchmark-publish (push) Successful in 19m11s
CI / docker (push) Has been skipped
CI / status-check (push) Failing after 3s
feat(ci): CI/CD pipeline definitions (#983)
## Summary

Complete CI/CD pipeline definitions: release workflow, caching, status-check consolidation, and documentation.

### Changes

**New: Release pipeline** (`.forgejo/workflows/release.yml`):
- Triggered on `v*` tags
- 3 jobs: `build-wheel` → `build-docker` → `create-release`
- Builds wheel via `nox -s build`, Docker image via multi-stage Dockerfile
- Creates Forgejo release via API with wheel artifact attached
- Configurable registry push via `REGISTRY_*` secrets

**Updated: CI pipeline** (`.forgejo/workflows/ci.yml`):
- Added `actions/cache@v3` for `~/.cache/uv` on all 8 primary jobs (keyed on `pyproject.toml` hash)
- Added `status-check` consolidation job depending on all required checks — single gate for branch protection

**Updated: CONTRIBUTING.md**:
- New CI/CD section: pipeline overview, job table, required merge checks, release process, secrets documentation

**Tests**:
- 13 new Behave scenarios validating workflow YAML structure, tag triggers, job definitions, dependencies
- 9 new Robot tests validating file existence, content, nox session references

### Quality Gates

| Session | Result |
|---|---|
| `nox -s lint` | PASS |
| `nox -s typecheck` | PASS (0 errors) |
| `nox -s unit_tests` | PASS (10,819 scenarios) |
| `nox -s coverage_report` | 97.9% (>= 97%) |

Closes #858

Reviewed-on: #983
Co-authored-by: Brent E. Edwards <brent.edwards@cleverthis.com>
Co-committed-by: Brent E. Edwards <brent.edwards@cleverthis.com>
2026-03-21 00:29:49 +00:00

157 lines
6.3 KiB
Gherkin

Feature: CI workflow validation
As a developer
I want to ensure the CI workflow exists and uses nox sessions
So that all CI checks run through the same tooling as local development
Scenario: CI workflow file exists
Given the CI workflow file at ".forgejo/workflows/ci.yml"
Then the CI workflow file should exist
Scenario: CI workflow references nox for lint
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "lint"
And the job "lint" should run "nox -s lint"
Scenario: CI workflow references nox for typecheck
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "typecheck"
And the job "typecheck" should run "nox -s typecheck"
Scenario: CI workflow references nox for unit tests
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "unit_tests"
And the job "unit_tests" should run "nox -s unit_tests"
Scenario: CI workflow references nox for integration tests
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "integration_tests"
And the job "integration_tests" should run "nox -s integration_tests"
Scenario: CI workflow references nox for coverage
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "coverage"
And the job "coverage" should run "nox -s coverage_report"
Scenario: CI workflow references nox for security
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "security"
And the job "security" should run "nox -s security_scan"
Scenario: CI workflow references nox for build
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "build"
And the job "build" should run "nox -s build"
Scenario: CI workflow uses Python 3.13
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow env should set "PYTHON_VERSION" to "3.13"
Scenario: CI workflow coverage job depends on lint and typecheck
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the job "coverage" should depend on "lint"
And the job "coverage" should depend on "typecheck"
Scenario: All required nox sessions are referenced
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should reference these nox sessions:
| session |
| lint |
| typecheck |
| unit_tests |
| integration_tests |
| coverage_report |
| security_scan |
| dead_code |
| complexity |
| build |
# --- Release pipeline scenarios ---
Scenario: Release workflow file exists
Given the CI workflow file at ".forgejo/workflows/release.yml"
Then the CI workflow file should exist
Scenario: Release workflow YAML is valid
Given the CI workflow file at ".forgejo/workflows/release.yml"
When I parse the CI workflow YAML
Then the workflow YAML should be valid
Scenario: Release workflow triggers on version tags
Given the CI workflow file at ".forgejo/workflows/release.yml"
When I parse the CI workflow YAML
Then the workflow should trigger on push tags matching "v*"
Scenario: Release workflow has build-wheel job
Given the CI workflow file at ".forgejo/workflows/release.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "build-wheel"
And the job "build-wheel" should run "nox -s build"
Scenario: Release workflow has build-docker job
Given the CI workflow file at ".forgejo/workflows/release.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "build-docker"
Scenario: Release workflow has create-release job
Given the CI workflow file at ".forgejo/workflows/release.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "create-release"
Scenario: Release workflow create-release depends on build jobs
Given the CI workflow file at ".forgejo/workflows/release.yml"
When I parse the CI workflow YAML
Then the job "create-release" should depend on "build-wheel"
And the job "create-release" should depend on "build-docker"
# --- Status-check consolidation job ---
Scenario: CI workflow has status-check consolidation job
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "status-check"
Scenario: Status-check job depends on all required jobs
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the job "status-check" should depend on "lint"
And the job "status-check" should depend on "typecheck"
And the job "status-check" should depend on "security"
And the job "status-check" should depend on "unit_tests"
And the job "status-check" should depend on "coverage"
# --- Coverage threshold ---
Scenario: CI coverage threshold is 97%
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the coverage job should enforce a 97% threshold
# --- Branch triggers ---
Scenario: CI workflow triggers on push to master
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should trigger on push to "master"
Scenario: CI workflow triggers on pull requests to master
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should trigger on pull_request to "master"
# --- Dependency caching ---
Scenario: CI workflow uses dependency caching
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then at least one job should use actions/cache