CI: Use own package as base
[akkoma] / .gitlab-ci.yml
1 image: git.pleroma.social:5050/pleroma/pleroma/ci-base
2
3 variables: &global_variables
4 POSTGRES_DB: pleroma_test
5 POSTGRES_USER: postgres
6 POSTGRES_PASSWORD: postgres
7 DB_HOST: postgres
8 MIX_ENV: test
9
10 cache: &global_cache_policy
11 key:
12 files:
13 - mix.lock
14 paths:
15 - deps
16 - _build
17
18 stages:
19 - build
20 - test
21 - benchmark
22 - deploy
23 - release
24 - docker
25
26 before_script:
27 - echo $MIX_ENV
28 - rm -rf _build/*/lib/pleroma
29 - mix deps.get
30
31 after_script:
32 - rm -rf _build/*/lib/pleroma
33
34 build:
35 stage: build
36 only:
37 changes:
38 - "**/*.ex"
39 - "**/*.exs"
40 - "mix.lock"
41 script:
42 - mix compile --force
43
44 spec-build:
45 stage: test
46 only:
47 changes:
48 - "lib/pleroma/web/api_spec/**/*.ex"
49 - "lib/pleroma/web/api_spec.ex"
50 artifacts:
51 paths:
52 - spec.json
53 script:
54 - mix pleroma.openapi_spec spec.json
55
56 benchmark:
57 stage: benchmark
58 when: manual
59 variables:
60 MIX_ENV: benchmark
61 services:
62 - name: postgres:9.6
63 alias: postgres
64 command: ["postgres", "-c", "fsync=off", "-c", "synchronous_commit=off", "-c", "full_page_writes=off"]
65 script:
66 - mix ecto.create
67 - mix ecto.migrate
68 - mix pleroma.load_testing
69
70 unit-testing:
71 stage: test
72 only:
73 changes:
74 - "**/*.ex"
75 - "**/*.exs"
76 - "mix.lock"
77 cache: &testing_cache_policy
78 <<: *global_cache_policy
79 policy: pull
80
81 services:
82 - name: postgres:13
83 alias: postgres
84 command: ["postgres", "-c", "fsync=off", "-c", "synchronous_commit=off", "-c", "full_page_writes=off"]
85 script:
86 - mix ecto.create
87 - mix ecto.migrate
88 - mix coveralls --preload-modules
89
90 unit-testing-erratic:
91 stage: test
92 retry: 2
93 only:
94 changes:
95 - "**/*.ex"
96 - "**/*.exs"
97 - "mix.lock"
98 cache: &testing_cache_policy
99 <<: *global_cache_policy
100 policy: pull
101
102 services:
103 - name: postgres:13
104 alias: postgres
105 command: ["postgres", "-c", "fsync=off", "-c", "synchronous_commit=off", "-c", "full_page_writes=off"]
106 script:
107 - mix ecto.create
108 - mix ecto.migrate
109 - mix test --only=erratic
110
111 # Removed to fix CI issue. In this early state it wasn't adding much value anyway.
112 # TODO Fix and reinstate federated testing
113 # federated-testing:
114 # stage: test
115 # cache: *testing_cache_policy
116 # services:
117 # - name: minibikini/postgres-with-rum:12
118 # alias: postgres
119 # command: ["postgres", "-c", "fsync=off", "-c", "synchronous_commit=off", "-c", "full_page_writes=off"]
120 # script:
121 # - mix deps.get
122 # - mix ecto.create
123 # - mix ecto.migrate
124 # - epmd -daemon
125 # - mix test --trace --only federated
126
127 unit-testing-rum:
128 stage: test
129 only:
130 changes:
131 - "**/*.ex"
132 - "**/*.exs"
133 - "mix.lock"
134 cache: *testing_cache_policy
135 services:
136 - name: minibikini/postgres-with-rum:12
137 alias: postgres
138 command: ["postgres", "-c", "fsync=off", "-c", "synchronous_commit=off", "-c", "full_page_writes=off"]
139 variables:
140 <<: *global_variables
141 RUM_ENABLED: "true"
142 script:
143 - mix ecto.create
144 - mix ecto.migrate
145 - "mix ecto.migrate --migrations-path priv/repo/optional_migrations/rum_indexing/"
146 - mix test --preload-modules
147
148 lint:
149 image: elixir:1.12
150 stage: test
151 only:
152 changes:
153 - "**/*.ex"
154 - "**/*.exs"
155 - "mix.lock"
156 cache: *testing_cache_policy
157 script:
158 - mix format --check-formatted
159
160 analysis:
161 stage: test
162 only:
163 changes:
164 - "**/*.ex"
165 - "**/*.exs"
166 - "mix.lock"
167 cache: *testing_cache_policy
168 script:
169 - mix credo --strict --only=warnings,todo,fixme,consistency,readability
170
171 cycles:
172 stage: test
173 image: elixir:1.11
174 only:
175 changes:
176 - "**/*.ex"
177 - "**/*.exs"
178 - "mix.lock"
179 cache: {}
180 script:
181 - mix deps.get
182 - mix compile
183 - mix xref graph --format cycles --label compile | awk '{print $0} END{exit ($0 != "No cycles found")}'
184
185 docs-deploy:
186 stage: deploy
187 cache: *testing_cache_policy
188 image: alpine:latest
189 only:
190 - stable@pleroma/pleroma
191 - develop@pleroma/pleroma
192 before_script:
193 - apk add curl
194 script:
195 - curl -X POST -F"token=$DOCS_PIPELINE_TRIGGER" -F'ref=master' -F"variables[BRANCH]=$CI_COMMIT_REF_NAME" https://git.pleroma.social/api/v4/projects/673/trigger/pipeline
196 review_app:
197 image: alpine:3.9
198 stage: deploy
199 before_script:
200 - apk update && apk add openssh-client git
201 when: manual
202 environment:
203 name: review/$CI_COMMIT_REF_NAME
204 url: https://$CI_ENVIRONMENT_SLUG.pleroma.online/
205 on_stop: stop_review_app
206 only:
207 - branches
208 except:
209 - master
210 - develop
211 script:
212 - echo "$CI_ENVIRONMENT_SLUG"
213 - mkdir -p ~/.ssh
214 - eval $(ssh-agent -s)
215 - echo "$SSH_PRIVATE_KEY" | tr -d '\r' | ssh-add -
216 - ssh-keyscan -H "pleroma.online" >> ~/.ssh/known_hosts
217 - (ssh -t dokku@pleroma.online -- apps:create "$CI_ENVIRONMENT_SLUG") || true
218 - (ssh -t dokku@pleroma.online -- git:set "$CI_ENVIRONMENT_SLUG" keep-git-dir true) || true
219 - ssh -t dokku@pleroma.online -- config:set "$CI_ENVIRONMENT_SLUG" APP_NAME="$CI_ENVIRONMENT_SLUG" APP_HOST="$CI_ENVIRONMENT_SLUG.pleroma.online" MIX_ENV=dokku
220 - (ssh -t dokku@pleroma.online -- postgres:create $(echo $CI_ENVIRONMENT_SLUG | sed -e 's/-/_/g')_db) || true
221 - (ssh -t dokku@pleroma.online -- postgres:link $(echo $CI_ENVIRONMENT_SLUG | sed -e 's/-/_/g')_db "$CI_ENVIRONMENT_SLUG") || true
222 - (ssh -t dokku@pleroma.online -- certs:add "$CI_ENVIRONMENT_SLUG" /home/dokku/server.crt /home/dokku/server.key) || true
223 - git push -f dokku@pleroma.online:$CI_ENVIRONMENT_SLUG $CI_COMMIT_SHA:refs/heads/master
224
225 spec-deploy:
226 stage: deploy
227 artifacts:
228 paths:
229 - spec.json
230 only:
231 - develop@pleroma/pleroma
232 image: alpine:latest
233 before_script:
234 - apk add curl
235 script:
236 - curl -X POST -F"token=$API_DOCS_PIPELINE_TRIGGER" -F'ref=master' -F"variables[BRANCH]=$CI_COMMIT_REF_NAME" -F"variables[JOB_REF]=$CI_JOB_ID" https://git.pleroma.social/api/v4/projects/1130/trigger/pipeline
237
238
239 stop_review_app:
240 image: alpine:3.9
241 stage: deploy
242 before_script:
243 - apk update && apk add openssh-client git
244 when: manual
245 environment:
246 name: review/$CI_COMMIT_REF_NAME
247 action: stop
248 script:
249 - echo "$CI_ENVIRONMENT_SLUG"
250 - mkdir -p ~/.ssh
251 - eval $(ssh-agent -s)
252 - echo "$SSH_PRIVATE_KEY" | tr -d '\r' | ssh-add -
253 - ssh-keyscan -H "pleroma.online" >> ~/.ssh/known_hosts
254 - ssh -t dokku@pleroma.online -- --force apps:destroy "$CI_ENVIRONMENT_SLUG"
255 - ssh -t dokku@pleroma.online -- --force postgres:destroy $(echo $CI_ENVIRONMENT_SLUG | sed -e 's/-/_/g')_db
256
257 amd64:
258 stage: release
259 image: elixir:1.10.4
260 only: &release-only
261 - stable@pleroma/pleroma
262 - develop@pleroma/pleroma
263 - /^maint/.*$/@pleroma/pleroma
264 - /^release/.*$/@pleroma/pleroma
265 artifacts: &release-artifacts
266 name: "pleroma-$CI_COMMIT_REF_NAME-$CI_COMMIT_SHORT_SHA-$CI_JOB_NAME"
267 paths:
268 - release/*
269 # Ideally it would be never for master branch and with the next commit for develop,
270 # but Gitlab does not support neither `only` for artifacts
271 # nor setting it to never from .gitlab-ci.yml
272 # nor expiring with the next commit
273 expire_in: 42 yrs
274
275 cache: &release-cache
276 key: $CI_COMMIT_REF_NAME-$CI_JOB_NAME
277 paths:
278 - deps
279 variables: &release-variables
280 MIX_ENV: prod
281 before_script: &before-release
282 - apt-get update && apt-get install -y cmake libmagic-dev
283 - echo "import Mix.Config" > config/prod.secret.exs
284 - mix local.hex --force
285 - mix local.rebar --force
286 script: &release
287 - mix deps.get --only prod
288 - mkdir release
289 - export PLEROMA_BUILD_BRANCH=$CI_COMMIT_REF_NAME
290 - mix release --path release
291
292
293 amd64-musl:
294 stage: release
295 artifacts: *release-artifacts
296 only: *release-only
297 image: elixir:1.10.4-alpine
298 cache: *release-cache
299 variables: *release-variables
300 before_script: &before-release-musl
301 - apk add git gcc g++ musl-dev make cmake file-dev
302 - echo "import Mix.Config" > config/prod.secret.exs
303 - mix local.hex --force
304 - mix local.rebar --force
305 script: *release
306
307 arm:
308 stage: release
309 artifacts: *release-artifacts
310 only: *release-only
311 tags:
312 - arm32-specified
313 image: arm32v7/elixir:1.10.4
314 cache: *release-cache
315 variables: *release-variables
316 before_script: *before-release
317 script: *release
318
319 arm-musl:
320 stage: release
321 artifacts: *release-artifacts
322 only: *release-only
323 tags:
324 - arm32-specified
325 image: arm32v7/elixir:1.10.4-alpine
326 cache: *release-cache
327 variables: *release-variables
328 before_script: *before-release-musl
329 script: *release
330
331 arm64:
332 stage: release
333 artifacts: *release-artifacts
334 only: *release-only
335 tags:
336 - arm
337 image: arm64v8/elixir:1.10.4
338 cache: *release-cache
339 variables: *release-variables
340 before_script: *before-release
341 script: *release
342
343 arm64-musl:
344 stage: release
345 artifacts: *release-artifacts
346 only: *release-only
347 tags:
348 - arm
349 image: arm64v8/elixir:1.10.4-alpine
350 cache: *release-cache
351 variables: *release-variables
352 before_script: *before-release-musl
353 script: *release
354
355 docker:
356 stage: docker
357 image: docker:latest
358 cache: {}
359 dependencies: []
360 variables: &docker-variables
361 DOCKER_DRIVER: overlay2
362 DOCKER_HOST: unix:///var/run/docker.sock
363 IMAGE_TAG: $CI_REGISTRY_IMAGE:$CI_COMMIT_SHORT_SHA
364 IMAGE_TAG_SLUG: $CI_REGISTRY_IMAGE:$CI_COMMIT_REF_SLUG
365 IMAGE_TAG_LATEST: $CI_REGISTRY_IMAGE:latest
366 IMAGE_TAG_LATEST_STABLE: $CI_REGISTRY_IMAGE:latest-stable
367 DOCKER_BUILDX_URL: https://github.com/docker/buildx/releases/download/v0.6.3/buildx-v0.6.3.linux-amd64
368 DOCKER_BUILDX_HASH: 980e6b9655f971991fbbb5fd6cd19f1672386195
369 before_script: &before-docker
370 - docker login -u $CI_REGISTRY_USER -p $CI_REGISTRY_PASSWORD $CI_REGISTRY
371 - docker pull $IMAGE_TAG_SLUG || true
372 - export CI_JOB_TIMESTAMP=$(date --utc -Iseconds)
373 - export CI_VCS_REF=$CI_COMMIT_SHORT_SHA
374 allow_failure: true
375 script:
376 - mkdir -p /root/.docker/cli-plugins
377 - wget "${DOCKER_BUILDX_URL}" -O ~/.docker/cli-plugins/docker-buildx
378 - echo "${DOCKER_BUILDX_HASH} /root/.docker/cli-plugins/docker-buildx" | sha1sum -c
379 - chmod +x ~/.docker/cli-plugins/docker-buildx
380 - docker run --rm --privileged multiarch/qemu-user-static --reset -p yes
381 - docker buildx create --name mbuilder --driver docker-container --use
382 - docker buildx inspect --bootstrap
383 - docker buildx build --platform linux/amd64,linux/arm/v7,linux/arm64/v8 --push --cache-from $IMAGE_TAG_SLUG --build-arg VCS_REF=$CI_VCS_REF --build-arg BUILD_DATE=$CI_JOB_TIMESTAMP -t $IMAGE_TAG -t $IMAGE_TAG_SLUG -t $IMAGE_TAG_LATEST .
384 tags:
385 - dind
386 only:
387 - develop@pleroma/pleroma
388
389 docker-stable:
390 stage: docker
391 image: docker:latest
392 cache: {}
393 dependencies: []
394 variables: *docker-variables
395 before_script: *before-docker
396 allow_failure: true
397 script:
398 - mkdir -p /root/.docker/cli-plugins
399 - wget "${DOCKER_BUILDX_URL}" -O ~/.docker/cli-plugins/docker-buildx
400 - echo "${DOCKER_BUILDX_HASH} /root/.docker/cli-plugins/docker-buildx" | sha1sum -c
401 - chmod +x ~/.docker/cli-plugins/docker-buildx
402 - docker run --rm --privileged multiarch/qemu-user-static --reset -p yes
403 - docker buildx create --name mbuilder --driver docker-container --use
404 - docker buildx inspect --bootstrap
405 - docker buildx build --platform linux/amd64,linux/arm/v7,linux/arm64/v8 --push --cache-from $IMAGE_TAG_SLUG --build-arg VCS_REF=$CI_VCS_REF --build-arg BUILD_DATE=$CI_JOB_TIMESTAMP -t $IMAGE_TAG -t $IMAGE_TAG_SLUG -t $IMAGE_TAG_LATEST_STABLE .
406 tags:
407 - dind
408 only:
409 - stable@pleroma/pleroma
410
411 docker-release:
412 stage: docker
413 image: docker:latest
414 cache: {}
415 dependencies: []
416 variables: *docker-variables
417 before_script: *before-docker
418 allow_failure: true
419 script:
420 script:
421 - mkdir -p /root/.docker/cli-plugins
422 - wget "${DOCKER_BUILDX_URL}" -O ~/.docker/cli-plugins/docker-buildx
423 - echo "${DOCKER_BUILDX_HASH} /root/.docker/cli-plugins/docker-buildx" | sha1sum -c
424 - chmod +x ~/.docker/cli-plugins/docker-buildx
425 - docker run --rm --privileged multiarch/qemu-user-static --reset -p yes
426 - docker buildx create --name mbuilder --driver docker-container --use
427 - docker buildx inspect --bootstrap
428 - docker buildx build --platform linux/amd64,linux/arm/v7,linux/arm64/v8 --push --cache-from $IMAGE_TAG_SLUG --build-arg VCS_REF=$CI_VCS_REF --build-arg BUILD_DATE=$CI_JOB_TIMESTAMP -t $IMAGE_TAG -t $IMAGE_TAG_SLUG .
429 tags:
430 - dind
431 only:
432 - /^release/.*$/@pleroma/pleroma
433
434 docker-adhoc:
435 stage: docker
436 image: docker:latest
437 cache: {}
438 dependencies: []
439 variables: *docker-variables
440 before_script: *before-docker
441 allow_failure: true
442 script:
443 script:
444 - mkdir -p /root/.docker/cli-plugins
445 - wget "${DOCKER_BUILDX_URL}" -O ~/.docker/cli-plugins/docker-buildx
446 - echo "${DOCKER_BUILDX_HASH} /root/.docker/cli-plugins/docker-buildx" | sha1sum -c
447 - chmod +x ~/.docker/cli-plugins/docker-buildx
448 - docker run --rm --privileged multiarch/qemu-user-static --reset -p yes
449 - docker buildx create --name mbuilder --driver docker-container --use
450 - docker buildx inspect --bootstrap
451 - docker buildx build --platform linux/amd64,linux/arm/v7,linux/arm64/v8 --push --cache-from $IMAGE_TAG_SLUG --build-arg VCS_REF=$CI_VCS_REF --build-arg BUILD_DATE=$CI_JOB_TIMESTAMP -t $IMAGE_TAG -t $IMAGE_TAG_SLUG .
452 tags:
453 - dind
454 only:
455 - /^build-docker/.*$/@pleroma/pleroma