Files
cleveragents-core/features/ci_workflow_validation.feature
T
freemo 4e3b4180fc
CI / benchmark-publish (pull_request) Has been skipped
CI / build (pull_request) Successful in 14s
CI / helm (pull_request) Successful in 45s
CI / lint (pull_request) Successful in 3m18s
CI / quality (pull_request) Successful in 3m43s
CI / security (pull_request) Successful in 4m9s
CI / typecheck (pull_request) Successful in 4m25s
CI / unit_tests (pull_request) Successful in 9m27s
CI / docker (pull_request) Successful in 1m42s
CI / e2e_tests (pull_request) Failing after 15m11s
CI / coverage (pull_request) Successful in 13m27s
CI / integration_tests (pull_request) Successful in 25m8s
CI / status-check (pull_request) Failing after 1s
CI / benchmark-regression (pull_request) Successful in 54m54s
feat(ci): add Helm chart lint and template validation to CI
Add kubeconform manifest validation to the existing helm CI job.
The helm job already had helm lint and helm template steps (added in
#1085). This commit completes the optional acceptance criterion from
#1089 by adding kubeconform v0.7.0 to validate rendered manifests
against the Kubernetes 1.29.0 schema in strict mode.

Changes:
- Install kubeconform v0.7.0 in the helm CI job
- Add 'Validate rendered manifests with kubeconform' step after
  helm template smoke render (strict mode, ignore-missing-schemas,
  kubernetes-version 1.29.0)
- Add 5 BDD scenarios to ci_workflow_validation.feature covering:
  - helm job existence
  - helm lint step
  - helm template step
  - kubeconform validation step
  - status-check dependency on helm job

ISSUES CLOSED: #1089
2026-04-02 07:47:09 +00:00

184 lines
7.3 KiB
Gherkin

Feature: CI workflow validation
As a developer
I want to ensure the CI workflow exists and uses nox sessions
So that all CI checks run through the same tooling as local development
Scenario: CI workflow file exists
Given the CI workflow file at ".forgejo/workflows/ci.yml"
Then the CI workflow file should exist
Scenario: CI workflow references nox for lint
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "lint"
And the job "lint" should run "nox -s lint"
Scenario: CI workflow references nox for typecheck
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "typecheck"
And the job "typecheck" should run "nox -s typecheck"
Scenario: CI workflow references nox for unit tests
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "unit_tests"
And the job "unit_tests" should run "nox -s unit_tests"
Scenario: CI workflow references nox for integration tests
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "integration_tests"
And the job "integration_tests" should run "nox -s integration_tests"
Scenario: CI workflow references nox for coverage
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "coverage"
And the job "coverage" should run "nox -s coverage_report"
Scenario: CI workflow references nox for security
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "security"
And the job "security" should run "nox -s security_scan"
Scenario: CI workflow references nox for build
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "build"
And the job "build" should run "nox -s build"
Scenario: CI workflow uses Python 3.13
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow env should set "PYTHON_VERSION" to "3.13"
Scenario: CI workflow coverage job depends on lint and typecheck
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the job "coverage" should depend on "lint"
And the job "coverage" should depend on "typecheck"
Scenario: All required nox sessions are referenced
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should reference these nox sessions:
| session |
| lint |
| typecheck |
| unit_tests |
| integration_tests |
| coverage_report |
| security_scan |
| dead_code |
| complexity |
| build |
# --- Release pipeline scenarios ---
Scenario: Release workflow file exists
Given the CI workflow file at ".forgejo/workflows/release.yml"
Then the CI workflow file should exist
Scenario: Release workflow YAML is valid
Given the CI workflow file at ".forgejo/workflows/release.yml"
When I parse the CI workflow YAML
Then the workflow YAML should be valid
Scenario: Release workflow triggers on version tags
Given the CI workflow file at ".forgejo/workflows/release.yml"
When I parse the CI workflow YAML
Then the workflow should trigger on push tags matching "v*"
Scenario: Release workflow has build-wheel job
Given the CI workflow file at ".forgejo/workflows/release.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "build-wheel"
And the job "build-wheel" should run "nox -s build"
Scenario: Release workflow has build-docker job
Given the CI workflow file at ".forgejo/workflows/release.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "build-docker"
Scenario: Release workflow has create-release job
Given the CI workflow file at ".forgejo/workflows/release.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "create-release"
Scenario: Release workflow create-release depends on build jobs
Given the CI workflow file at ".forgejo/workflows/release.yml"
When I parse the CI workflow YAML
Then the job "create-release" should depend on "build-wheel"
And the job "create-release" should depend on "build-docker"
# --- Status-check consolidation job ---
Scenario: CI workflow has status-check consolidation job
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "status-check"
Scenario: Status-check job depends on all required jobs
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the job "status-check" should depend on "lint"
And the job "status-check" should depend on "typecheck"
And the job "status-check" should depend on "security"
And the job "status-check" should depend on "unit_tests"
And the job "status-check" should depend on "coverage"
# --- Coverage threshold ---
Scenario: CI coverage threshold is 97%
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the coverage job should enforce a 97% threshold
# --- Branch triggers ---
Scenario: CI workflow triggers on push to master
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should trigger on push to "master"
Scenario: CI workflow triggers on pull requests to master
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should trigger on pull_request to "master"
# --- Dependency caching ---
Scenario: CI workflow uses dependency caching
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then at least one job should use actions/cache
# --- Helm CI job ---
Scenario: CI workflow has helm validation job
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the workflow should have a job named "helm"
Scenario: Helm job runs helm lint
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the job "helm" should run "helm lint"
Scenario: Helm job runs helm template
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the job "helm" should run "helm template"
Scenario: Helm job validates rendered manifests with kubeconform
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the job "helm" should run "kubeconform"
Scenario: Status-check job depends on helm job
Given the CI workflow file at ".forgejo/workflows/ci.yml"
When I parse the CI workflow YAML
Then the job "status-check" should depend on "helm"