4e3b4180fc
CI / benchmark-publish (pull_request) Has been skipped
CI / build (pull_request) Successful in 14s
CI / helm (pull_request) Successful in 45s
CI / lint (pull_request) Successful in 3m18s
CI / quality (pull_request) Successful in 3m43s
CI / security (pull_request) Successful in 4m9s
CI / typecheck (pull_request) Successful in 4m25s
CI / unit_tests (pull_request) Successful in 9m27s
CI / docker (pull_request) Successful in 1m42s
CI / e2e_tests (pull_request) Failing after 15m11s
CI / coverage (pull_request) Successful in 13m27s
CI / integration_tests (pull_request) Successful in 25m8s
CI / status-check (pull_request) Failing after 1s
CI / benchmark-regression (pull_request) Successful in 54m54s
Add kubeconform manifest validation to the existing helm CI job. The helm job already had helm lint and helm template steps (added in #1085). This commit completes the optional acceptance criterion from #1089 by adding kubeconform v0.7.0 to validate rendered manifests against the Kubernetes 1.29.0 schema in strict mode. Changes: - Install kubeconform v0.7.0 in the helm CI job - Add 'Validate rendered manifests with kubeconform' step after helm template smoke render (strict mode, ignore-missing-schemas, kubernetes-version 1.29.0) - Add 5 BDD scenarios to ci_workflow_validation.feature covering: - helm job existence - helm lint step - helm template step - kubeconform validation step - status-check dependency on helm job ISSUES CLOSED: #1089
184 lines
7.3 KiB
Gherkin
184 lines
7.3 KiB
Gherkin
Feature: CI workflow validation
|
|
As a developer
|
|
I want to ensure the CI workflow exists and uses nox sessions
|
|
So that all CI checks run through the same tooling as local development
|
|
|
|
Scenario: CI workflow file exists
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
Then the CI workflow file should exist
|
|
|
|
Scenario: CI workflow references nox for lint
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should have a job named "lint"
|
|
And the job "lint" should run "nox -s lint"
|
|
|
|
Scenario: CI workflow references nox for typecheck
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should have a job named "typecheck"
|
|
And the job "typecheck" should run "nox -s typecheck"
|
|
|
|
Scenario: CI workflow references nox for unit tests
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should have a job named "unit_tests"
|
|
And the job "unit_tests" should run "nox -s unit_tests"
|
|
|
|
Scenario: CI workflow references nox for integration tests
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should have a job named "integration_tests"
|
|
And the job "integration_tests" should run "nox -s integration_tests"
|
|
|
|
Scenario: CI workflow references nox for coverage
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should have a job named "coverage"
|
|
And the job "coverage" should run "nox -s coverage_report"
|
|
|
|
Scenario: CI workflow references nox for security
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should have a job named "security"
|
|
And the job "security" should run "nox -s security_scan"
|
|
|
|
Scenario: CI workflow references nox for build
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should have a job named "build"
|
|
And the job "build" should run "nox -s build"
|
|
|
|
Scenario: CI workflow uses Python 3.13
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow env should set "PYTHON_VERSION" to "3.13"
|
|
|
|
Scenario: CI workflow coverage job depends on lint and typecheck
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the job "coverage" should depend on "lint"
|
|
And the job "coverage" should depend on "typecheck"
|
|
|
|
Scenario: All required nox sessions are referenced
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should reference these nox sessions:
|
|
| session |
|
|
| lint |
|
|
| typecheck |
|
|
| unit_tests |
|
|
| integration_tests |
|
|
| coverage_report |
|
|
| security_scan |
|
|
| dead_code |
|
|
| complexity |
|
|
| build |
|
|
|
|
# --- Release pipeline scenarios ---
|
|
|
|
Scenario: Release workflow file exists
|
|
Given the CI workflow file at ".forgejo/workflows/release.yml"
|
|
Then the CI workflow file should exist
|
|
|
|
Scenario: Release workflow YAML is valid
|
|
Given the CI workflow file at ".forgejo/workflows/release.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow YAML should be valid
|
|
|
|
Scenario: Release workflow triggers on version tags
|
|
Given the CI workflow file at ".forgejo/workflows/release.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should trigger on push tags matching "v*"
|
|
|
|
Scenario: Release workflow has build-wheel job
|
|
Given the CI workflow file at ".forgejo/workflows/release.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should have a job named "build-wheel"
|
|
And the job "build-wheel" should run "nox -s build"
|
|
|
|
Scenario: Release workflow has build-docker job
|
|
Given the CI workflow file at ".forgejo/workflows/release.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should have a job named "build-docker"
|
|
|
|
Scenario: Release workflow has create-release job
|
|
Given the CI workflow file at ".forgejo/workflows/release.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should have a job named "create-release"
|
|
|
|
Scenario: Release workflow create-release depends on build jobs
|
|
Given the CI workflow file at ".forgejo/workflows/release.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the job "create-release" should depend on "build-wheel"
|
|
And the job "create-release" should depend on "build-docker"
|
|
|
|
# --- Status-check consolidation job ---
|
|
|
|
Scenario: CI workflow has status-check consolidation job
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should have a job named "status-check"
|
|
|
|
Scenario: Status-check job depends on all required jobs
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the job "status-check" should depend on "lint"
|
|
And the job "status-check" should depend on "typecheck"
|
|
And the job "status-check" should depend on "security"
|
|
And the job "status-check" should depend on "unit_tests"
|
|
And the job "status-check" should depend on "coverage"
|
|
|
|
# --- Coverage threshold ---
|
|
|
|
Scenario: CI coverage threshold is 97%
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the coverage job should enforce a 97% threshold
|
|
|
|
# --- Branch triggers ---
|
|
|
|
Scenario: CI workflow triggers on push to master
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should trigger on push to "master"
|
|
|
|
Scenario: CI workflow triggers on pull requests to master
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should trigger on pull_request to "master"
|
|
|
|
# --- Dependency caching ---
|
|
|
|
Scenario: CI workflow uses dependency caching
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then at least one job should use actions/cache
|
|
|
|
# --- Helm CI job ---
|
|
|
|
Scenario: CI workflow has helm validation job
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the workflow should have a job named "helm"
|
|
|
|
Scenario: Helm job runs helm lint
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the job "helm" should run "helm lint"
|
|
|
|
Scenario: Helm job runs helm template
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the job "helm" should run "helm template"
|
|
|
|
Scenario: Helm job validates rendered manifests with kubeconform
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the job "helm" should run "kubeconform"
|
|
|
|
Scenario: Status-check job depends on helm job
|
|
Given the CI workflow file at ".forgejo/workflows/ci.yml"
|
|
When I parse the CI workflow YAML
|
|
Then the job "status-check" should depend on "helm"
|