Merge branch 'develop' into fix/reports-from-admins
[akkoma] / .gitlab-ci.yml
1 image: elixir:1.9.4
2
3 variables: &global_variables
4 POSTGRES_DB: pleroma_test
5 POSTGRES_USER: postgres
6 POSTGRES_PASSWORD: postgres
7 DB_HOST: postgres
8 MIX_ENV: test
9
10 cache: &global_cache_policy
11 key: ${CI_COMMIT_REF_SLUG}
12 paths:
13 - deps
14 - _build
15
16 stages:
17 - build
18 - test
19 - benchmark
20 - deploy
21 - release
22 - docker
23
24 before_script:
25 - apt-get update && apt-get install -y cmake
26 - mix local.hex --force
27 - mix local.rebar --force
28 - apt-get -qq update
29 - apt-get install -y libmagic-dev
30
31 build:
32 stage: build
33 script:
34 - mix deps.get
35 - mix compile --force
36
37 spec-build:
38 stage: test
39 artifacts:
40 paths:
41 - spec.json
42 script:
43 - mix pleroma.openapi_spec spec.json
44
45 benchmark:
46 stage: benchmark
47 when: manual
48 variables:
49 MIX_ENV: benchmark
50 services:
51 - name: postgres:9.6
52 alias: postgres
53 command: ["postgres", "-c", "fsync=off", "-c", "synchronous_commit=off", "-c", "full_page_writes=off"]
54 script:
55 - mix deps.get
56 - mix ecto.create
57 - mix ecto.migrate
58 - mix pleroma.load_testing
59
60 unit-testing:
61 stage: test
62 retry: 2
63 cache: &testing_cache_policy
64 <<: *global_cache_policy
65 policy: pull
66
67 services:
68 - name: postgres:13
69 alias: postgres
70 command: ["postgres", "-c", "fsync=off", "-c", "synchronous_commit=off", "-c", "full_page_writes=off"]
71 script:
72 - apt-get update && apt-get install -y libimage-exiftool-perl ffmpeg
73 - mix deps.get
74 - mix ecto.create
75 - mix ecto.migrate
76 - mix coveralls --preload-modules
77
78 # Removed to fix CI issue. In this early state it wasn't adding much value anyway.
79 # TODO Fix and reinstate federated testing
80 # federated-testing:
81 # stage: test
82 # cache: *testing_cache_policy
83 # services:
84 # - name: minibikini/postgres-with-rum:12
85 # alias: postgres
86 # command: ["postgres", "-c", "fsync=off", "-c", "synchronous_commit=off", "-c", "full_page_writes=off"]
87 # script:
88 # - mix deps.get
89 # - mix ecto.create
90 # - mix ecto.migrate
91 # - epmd -daemon
92 # - mix test --trace --only federated
93
94 unit-testing-rum:
95 stage: test
96 retry: 2
97 cache: *testing_cache_policy
98 services:
99 - name: minibikini/postgres-with-rum:12
100 alias: postgres
101 command: ["postgres", "-c", "fsync=off", "-c", "synchronous_commit=off", "-c", "full_page_writes=off"]
102 variables:
103 <<: *global_variables
104 RUM_ENABLED: "true"
105 script:
106 - apt-get update && apt-get install -y libimage-exiftool-perl ffmpeg
107 - mix deps.get
108 - mix ecto.create
109 - mix ecto.migrate
110 - "mix ecto.migrate --migrations-path priv/repo/optional_migrations/rum_indexing/"
111 - mix test --preload-modules
112
113 lint:
114 stage: test
115 cache: *testing_cache_policy
116 script:
117 - mix format --check-formatted
118
119 analysis:
120 stage: test
121 cache: *testing_cache_policy
122 script:
123 - mix deps.get
124 - mix credo --strict --only=warnings,todo,fixme,consistency,readability
125
126 docs-deploy:
127 stage: deploy
128 cache: *testing_cache_policy
129 image: alpine:latest
130 only:
131 - stable@pleroma/pleroma
132 - develop@pleroma/pleroma
133 before_script:
134 - apk add curl
135 script:
136 - curl -X POST -F"token=$DOCS_PIPELINE_TRIGGER" -F'ref=master' -F"variables[BRANCH]=$CI_COMMIT_REF_NAME" https://git.pleroma.social/api/v4/projects/673/trigger/pipeline
137 review_app:
138 image: alpine:3.9
139 stage: deploy
140 before_script:
141 - apk update && apk add openssh-client git
142 when: manual
143 environment:
144 name: review/$CI_COMMIT_REF_NAME
145 url: https://$CI_ENVIRONMENT_SLUG.pleroma.online/
146 on_stop: stop_review_app
147 only:
148 - branches
149 except:
150 - master
151 - develop
152 script:
153 - echo "$CI_ENVIRONMENT_SLUG"
154 - mkdir -p ~/.ssh
155 - eval $(ssh-agent -s)
156 - echo "$SSH_PRIVATE_KEY" | tr -d '\r' | ssh-add -
157 - ssh-keyscan -H "pleroma.online" >> ~/.ssh/known_hosts
158 - (ssh -t dokku@pleroma.online -- apps:create "$CI_ENVIRONMENT_SLUG") || true
159 - (ssh -t dokku@pleroma.online -- git:set "$CI_ENVIRONMENT_SLUG" keep-git-dir true) || true
160 - ssh -t dokku@pleroma.online -- config:set "$CI_ENVIRONMENT_SLUG" APP_NAME="$CI_ENVIRONMENT_SLUG" APP_HOST="$CI_ENVIRONMENT_SLUG.pleroma.online" MIX_ENV=dokku
161 - (ssh -t dokku@pleroma.online -- postgres:create $(echo $CI_ENVIRONMENT_SLUG | sed -e 's/-/_/g')_db) || true
162 - (ssh -t dokku@pleroma.online -- postgres:link $(echo $CI_ENVIRONMENT_SLUG | sed -e 's/-/_/g')_db "$CI_ENVIRONMENT_SLUG") || true
163 - (ssh -t dokku@pleroma.online -- certs:add "$CI_ENVIRONMENT_SLUG" /home/dokku/server.crt /home/dokku/server.key) || true
164 - git push -f dokku@pleroma.online:$CI_ENVIRONMENT_SLUG $CI_COMMIT_SHA:refs/heads/master
165
166 spec-deploy:
167 stage: deploy
168 artifacts:
169 paths:
170 - spec.json
171 only:
172 - develop@pleroma/pleroma
173 image: alpine:latest
174 before_script:
175 - apk add curl
176 script:
177 - curl -X POST -F"token=$API_DOCS_PIPELINE_TRIGGER" -F'ref=master' -F"variables[BRANCH]=$CI_COMMIT_REF_NAME" -F"variables[JOB_REF]=$CI_JOB_ID" https://git.pleroma.social/api/v4/projects/1130/trigger/pipeline
178
179
180 stop_review_app:
181 image: alpine:3.9
182 stage: deploy
183 before_script:
184 - apk update && apk add openssh-client git
185 when: manual
186 environment:
187 name: review/$CI_COMMIT_REF_NAME
188 action: stop
189 script:
190 - echo "$CI_ENVIRONMENT_SLUG"
191 - mkdir -p ~/.ssh
192 - eval $(ssh-agent -s)
193 - echo "$SSH_PRIVATE_KEY" | tr -d '\r' | ssh-add -
194 - ssh-keyscan -H "pleroma.online" >> ~/.ssh/known_hosts
195 - ssh -t dokku@pleroma.online -- --force apps:destroy "$CI_ENVIRONMENT_SLUG"
196 - ssh -t dokku@pleroma.online -- --force postgres:destroy $(echo $CI_ENVIRONMENT_SLUG | sed -e 's/-/_/g')_db
197
198 amd64:
199 stage: release
200 image: elixir:1.10.3
201 only: &release-only
202 - stable@pleroma/pleroma
203 - develop@pleroma/pleroma
204 - /^maint/.*$/@pleroma/pleroma
205 - /^release/.*$/@pleroma/pleroma
206 artifacts: &release-artifacts
207 name: "pleroma-$CI_COMMIT_REF_NAME-$CI_COMMIT_SHORT_SHA-$CI_JOB_NAME"
208 paths:
209 - release/*
210 # Ideally it would be never for master branch and with the next commit for develop,
211 # but Gitlab does not support neither `only` for artifacts
212 # nor setting it to never from .gitlab-ci.yml
213 # nor expiring with the next commit
214 expire_in: 42 yrs
215
216 cache: &release-cache
217 key: $CI_COMMIT_REF_NAME-$CI_JOB_NAME
218 paths:
219 - deps
220 variables: &release-variables
221 MIX_ENV: prod
222 before_script: &before-release
223 - apt-get update && apt-get install -y cmake libmagic-dev
224 - echo "import Mix.Config" > config/prod.secret.exs
225 - mix local.hex --force
226 - mix local.rebar --force
227 script: &release
228 - mix deps.get --only prod
229 - mkdir release
230 - export PLEROMA_BUILD_BRANCH=$CI_COMMIT_REF_NAME
231 - mix release --path release
232
233
234 amd64-musl:
235 stage: release
236 artifacts: *release-artifacts
237 only: *release-only
238 image: elixir:1.10.3-alpine
239 cache: *release-cache
240 variables: *release-variables
241 before_script: &before-release-musl
242 - apk add git gcc g++ musl-dev make cmake file-dev
243 - echo "import Mix.Config" > config/prod.secret.exs
244 - mix local.hex --force
245 - mix local.rebar --force
246 script: *release
247
248 arm:
249 stage: release
250 artifacts: *release-artifacts
251 only: *release-only
252 tags:
253 - arm32-specified
254 image: arm32v7/elixir:1.10.3
255 cache: *release-cache
256 variables: *release-variables
257 before_script: *before-release
258 script: *release
259
260 arm-musl:
261 stage: release
262 artifacts: *release-artifacts
263 only: *release-only
264 tags:
265 - arm32-specified
266 image: arm32v7/elixir:1.10.3-alpine
267 cache: *release-cache
268 variables: *release-variables
269 before_script: *before-release-musl
270 script: *release
271
272 arm64:
273 stage: release
274 artifacts: *release-artifacts
275 only: *release-only
276 tags:
277 - arm
278 image: arm64v8/elixir:1.10.3
279 cache: *release-cache
280 variables: *release-variables
281 before_script: *before-release
282 script: *release
283
284 arm64-musl:
285 stage: release
286 artifacts: *release-artifacts
287 only: *release-only
288 tags:
289 - arm
290 image: arm64v8/elixir:1.10.3-alpine
291 cache: *release-cache
292 variables: *release-variables
293 before_script: *before-release-musl
294 script: *release
295
296 docker:
297 stage: docker
298 image: docker:latest
299 cache: {}
300 dependencies: []
301 variables: &docker-variables
302 DOCKER_DRIVER: overlay2
303 DOCKER_HOST: unix:///var/run/docker.sock
304 IMAGE_TAG: $CI_REGISTRY_IMAGE:$CI_COMMIT_SHORT_SHA
305 IMAGE_TAG_SLUG: $CI_REGISTRY_IMAGE:$CI_COMMIT_REF_SLUG
306 IMAGE_TAG_LATEST: $CI_REGISTRY_IMAGE:latest
307 IMAGE_TAG_LATEST_STABLE: $CI_REGISTRY_IMAGE:latest-stable
308 DOCKER_BUILDX_URL: https://github.com/docker/buildx/releases/download/v0.4.1/buildx-v0.4.1.linux-amd64
309 DOCKER_BUILDX_HASH: 71a7d01439aa8c165a25b59c44d3f016fddbd98b
310 before_script: &before-docker
311 - docker login -u $CI_REGISTRY_USER -p $CI_REGISTRY_PASSWORD $CI_REGISTRY
312 - docker pull $IMAGE_TAG_SLUG || true
313 - export CI_JOB_TIMESTAMP=$(date --utc -Iseconds)
314 - export CI_VCS_REF=$CI_COMMIT_SHORT_SHA
315 allow_failure: true
316 script:
317 - mkdir -p /root/.docker/cli-plugins
318 - wget "${DOCKER_BUILDX_URL}" -O ~/.docker/cli-plugins/docker-buildx
319 - echo "${DOCKER_BUILDX_HASH} /root/.docker/cli-plugins/docker-buildx" | sha1sum -c
320 - chmod +x ~/.docker/cli-plugins/docker-buildx
321 - docker run --rm --privileged multiarch/qemu-user-static --reset -p yes
322 - docker buildx create --name mbuilder --driver docker-container --use
323 - docker buildx inspect --bootstrap
324 - docker buildx build --platform linux/amd64,linux/arm/v7,linux/arm64/v8 --push --cache-from $IMAGE_TAG_SLUG --build-arg VCS_REF=$CI_VCS_REF --build-arg BUILD_DATE=$CI_JOB_TIMESTAMP -t $IMAGE_TAG -t $IMAGE_TAG_SLUG -t $IMAGE_TAG_LATEST .
325 tags:
326 - dind
327 only:
328 - develop@pleroma/pleroma
329
330 docker-stable:
331 stage: docker
332 image: docker:latest
333 cache: {}
334 dependencies: []
335 variables: *docker-variables
336 before_script: *before-docker
337 allow_failure: true
338 script:
339 - mkdir -p /root/.docker/cli-plugins
340 - wget "${DOCKER_BUILDX_URL}" -O ~/.docker/cli-plugins/docker-buildx
341 - echo "${DOCKER_BUILDX_HASH} /root/.docker/cli-plugins/docker-buildx" | sha1sum -c
342 - chmod +x ~/.docker/cli-plugins/docker-buildx
343 - docker run --rm --privileged multiarch/qemu-user-static --reset -p yes
344 - docker buildx create --name mbuilder --driver docker-container --use
345 - docker buildx inspect --bootstrap
346 - docker buildx build --platform linux/amd64,linux/arm/v7,linux/arm64/v8 --push --cache-from $IMAGE_TAG_SLUG --build-arg VCS_REF=$CI_VCS_REF --build-arg BUILD_DATE=$CI_JOB_TIMESTAMP -t $IMAGE_TAG -t $IMAGE_TAG_SLUG -t $IMAGE_TAG_LATEST_STABLE .
347 tags:
348 - dind
349 only:
350 - stable@pleroma/pleroma
351
352 docker-release:
353 stage: docker
354 image: docker:latest
355 cache: {}
356 dependencies: []
357 variables: *docker-variables
358 before_script: *before-docker
359 allow_failure: true
360 script:
361 script:
362 - mkdir -p /root/.docker/cli-plugins
363 - wget "${DOCKER_BUILDX_URL}" -O ~/.docker/cli-plugins/docker-buildx
364 - echo "${DOCKER_BUILDX_HASH} /root/.docker/cli-plugins/docker-buildx" | sha1sum -c
365 - chmod +x ~/.docker/cli-plugins/docker-buildx
366 - docker run --rm --privileged multiarch/qemu-user-static --reset -p yes
367 - docker buildx create --name mbuilder --driver docker-container --use
368 - docker buildx inspect --bootstrap
369 - docker buildx build --platform linux/amd64,linux/arm/v7,linux/arm64/v8 --push --cache-from $IMAGE_TAG_SLUG --build-arg VCS_REF=$CI_VCS_REF --build-arg BUILD_DATE=$CI_JOB_TIMESTAMP -t $IMAGE_TAG -t $IMAGE_TAG_SLUG .
370 tags:
371 - dind
372 only:
373 - /^release/.*$/@pleroma/pleroma