reusable-app-prod.yml 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346
  1. name: Reusable build and test app for production
  2. on:
  3. workflow_call:
  4. inputs:
  5. node-version:
  6. required: true
  7. type: string
  8. skip-e2e-test:
  9. type: boolean
  10. secrets:
  11. SLACK_WEBHOOK_URL:
  12. required: true
  13. workflow_dispatch:
  14. inputs:
  15. node-version:
  16. required: true
  17. type: string
  18. default: 24.x
  19. skip-e2e-test:
  20. type: boolean
  21. default: false
  22. secrets:
  23. SLACK_WEBHOOK_URL:
  24. required: true
  25. jobs:
  26. build-prod:
  27. runs-on: ubuntu-latest
  28. outputs:
  29. PROD_FILES: ${{ steps.archive-prod-files.outputs.file }}
  30. steps:
  31. - uses: actions/checkout@v4
  32. - uses: pnpm/action-setup@v4
  33. - uses: actions/setup-node@v4
  34. with:
  35. node-version: ${{ inputs.node-version }}
  36. cache: 'pnpm'
  37. - name: Install turbo
  38. run: |
  39. pnpm add turbo --global
  40. - name: Install dependencies
  41. run: |
  42. pnpm install --frozen-lockfile
  43. - name: Build
  44. working-directory: ./apps/app
  45. run: |
  46. turbo run build --env-mode=loose
  47. env:
  48. ANALYZE: 1
  49. - name: Assemble production artifacts
  50. run: bash apps/app/bin/assemble-prod.sh
  51. - name: Check for broken symlinks in .next/node_modules
  52. run: bash apps/app/bin/check-next-symlinks.sh
  53. - name: Archive production files
  54. id: archive-prod-files
  55. run: |
  56. tar -zcf production.tar.gz --exclude ./apps/app/.next/cache \
  57. package.json \
  58. node_modules \
  59. tsconfig.base.json \
  60. apps/app/.next \
  61. apps/app/config \
  62. apps/app/dist \
  63. apps/app/prisma \
  64. apps/app/public \
  65. apps/app/resource \
  66. apps/app/tmp \
  67. apps/app/.env.production* \
  68. apps/app/node_modules \
  69. apps/app/next.config.js \
  70. apps/app/package.json \
  71. apps/app/tsconfig.json
  72. echo "file=production.tar.gz" >> $GITHUB_OUTPUT
  73. - name: Upload production files as artifact
  74. uses: actions/upload-artifact@v4
  75. with:
  76. name: Production Files (node${{ inputs.node-version }})
  77. path: ${{ steps.archive-prod-files.outputs.file }}
  78. - name: Upload report as artifact
  79. uses: actions/upload-artifact@v4
  80. with:
  81. name: Bundle Analyzing Report (node${{ inputs.node-version }})
  82. path: |
  83. apps/app/.next/analyze
  84. - name: Slack Notification
  85. uses: weseek/ghaction-slack-notification@master
  86. if: failure()
  87. with:
  88. type: ${{ job.status }}
  89. job_name: '*Node CI for growi - build-prod (${{ inputs.node-version }})*'
  90. channel: '#ci'
  91. isCompactMode: true
  92. url: ${{ secrets.SLACK_WEBHOOK_URL }}
  93. launch-prod:
  94. needs: [build-prod]
  95. runs-on: ubuntu-latest
  96. strategy:
  97. matrix:
  98. mongodb-version: ['6.0', '8.0']
  99. services:
  100. mongodb:
  101. image: mongo:${{ matrix.mongodb-version }}
  102. ports:
  103. - 27017/tcp
  104. elasticsearch:
  105. image: docker.elastic.co/elasticsearch/elasticsearch:9.0.1
  106. ports:
  107. - 9200/tcp
  108. env:
  109. discovery.type: single-node
  110. # ES 9.x enables security (HTTPS + auth) by default; disable for plaintext CI access
  111. xpack.security.enabled: false
  112. steps:
  113. - uses: actions/setup-node@v4
  114. with:
  115. node-version: ${{ inputs.node-version }}
  116. - name: Download production files artifact
  117. uses: actions/download-artifact@v4
  118. with:
  119. name: Production Files (node${{ inputs.node-version }})
  120. - name: Extract production files
  121. run: |
  122. tar -xf ${{ needs.build-prod.outputs.PROD_FILES }}
  123. # Run after extraction so pnpm/action-setup@v4 can read packageManager from package.json
  124. - uses: pnpm/action-setup@v4
  125. - name: pnpm run server:ci
  126. working-directory: ./apps/app
  127. run: |
  128. cp config/ci/.env.local.for-ci .env.production.local
  129. pnpm run server:ci
  130. env:
  131. MONGO_URI: mongodb://localhost:${{ job.services.mongodb.ports['27017'] }}/growi
  132. ELASTICSEARCH_URI: http://localhost:${{ job.services.elasticsearch.ports['9200'] }}/growi
  133. - name: Slack Notification
  134. uses: weseek/ghaction-slack-notification@master
  135. if: failure()
  136. with:
  137. type: ${{ job.status }}
  138. job_name: '*Node CI for growi - build-prod (${{ inputs.node-version }})*'
  139. channel: '#ci'
  140. isCompactMode: true
  141. url: ${{ secrets.SLACK_WEBHOOK_URL }}
  142. run-playwright:
  143. needs: [build-prod]
  144. if: |
  145. github.event_name == 'workflow_dispatch' ||
  146. (!inputs.skip-e2e-test && startsWith(github.head_ref, 'mergify/merge-queue/'))
  147. runs-on: ubuntu-latest
  148. container:
  149. # Match the Playwright version
  150. # https://github.com/microsoft/playwright/issues/20010
  151. image: mcr.microsoft.com/playwright:v1.58.2-jammy
  152. strategy:
  153. fail-fast: false
  154. matrix:
  155. browser: [chromium, firefox, webkit]
  156. shard: [1/2, 2/2]
  157. mongodb-version: ['6.0', '8.0']
  158. services:
  159. mongodb:
  160. image: mongo:${{ matrix.mongodb-version }}
  161. ports:
  162. - 27017/tcp
  163. elasticsearch:
  164. image: docker.elastic.co/elasticsearch/elasticsearch:9.0.1
  165. ports:
  166. - 9200/tcp
  167. env:
  168. discovery.type: single-node
  169. # ES 9.x enables security (HTTPS + auth) by default; disable for plaintext CI access
  170. xpack.security.enabled: false
  171. steps:
  172. - uses: actions/checkout@v4
  173. - uses: pnpm/action-setup@v4
  174. - uses: actions/setup-node@v4
  175. with:
  176. node-version: ${{ inputs.node-version }}
  177. cache: 'pnpm'
  178. - name: Install dependencies
  179. run: |
  180. pnpm install --frozen-lockfile
  181. - name: Install Playwright browsers
  182. run: |
  183. pnpm playwright install --with-deps ${{ matrix.browser }}
  184. - name: Download production files artifact
  185. uses: actions/download-artifact@v4
  186. with:
  187. name: Production Files (node${{ inputs.node-version }})
  188. - name: Extract production files to isolated directory
  189. run: |
  190. mkdir -p /tmp/growi-prod
  191. tar -xf ${{ needs.build-prod.outputs.PROD_FILES }} -C /tmp/growi-prod
  192. - name: Copy dotenv file for ci
  193. run: |
  194. cat apps/app/config/ci/.env.local.for-ci >> /tmp/growi-prod/apps/app/.env.production.local
  195. - name: Playwright Run (--project=chromium/installer)
  196. if: ${{ matrix.browser == 'chromium' }}
  197. working-directory: ./apps/app
  198. run: |
  199. pnpm playwright test --project=chromium/installer
  200. env:
  201. DEBUG: pw:api
  202. HOME: /root # ref: https://github.com/microsoft/playwright/issues/6500
  203. GROWI_WEBSERVER_COMMAND: 'cd /tmp/growi-prod/apps/app && pnpm run server'
  204. MONGO_URI: mongodb://mongodb:27017/growi-playwright-installer
  205. ELASTICSEARCH_URI: http://elasticsearch:9200/growi
  206. - name: Copy dotenv file for automatic installation
  207. run: |
  208. cat apps/app/config/ci/.env.local.for-auto-install >> /tmp/growi-prod/apps/app/.env.production.local
  209. - name: Playwright Run
  210. working-directory: ./apps/app
  211. run: |
  212. pnpm playwright test --project=${{ matrix.browser }} --shard=${{ matrix.shard }}
  213. env:
  214. DEBUG: pw:api
  215. HOME: /root # ref: https://github.com/microsoft/playwright/issues/6500
  216. GROWI_WEBSERVER_COMMAND: 'cd /tmp/growi-prod/apps/app && pnpm run server'
  217. MONGO_URI: mongodb://mongodb:27017/growi-playwright
  218. ELASTICSEARCH_URI: http://elasticsearch:9200/growi
  219. - name: Copy dotenv file for automatic installation with allowing guest mode
  220. run: |
  221. cat apps/app/config/ci/.env.local.for-auto-install-with-allowing-guest >> /tmp/growi-prod/apps/app/.env.production.local
  222. - name: Playwright Run (--project=${browser}/guest-mode)
  223. working-directory: ./apps/app
  224. run: |
  225. pnpm playwright test --project=${{ matrix.browser }}/guest-mode --shard=${{ matrix.shard }}
  226. env:
  227. DEBUG: pw:api
  228. HOME: /root # ref: https://github.com/microsoft/playwright/issues/6500
  229. GROWI_WEBSERVER_COMMAND: 'cd /tmp/growi-prod/apps/app && pnpm run server'
  230. MONGO_URI: mongodb://mongodb:27017/growi-playwright-guest-mode
  231. ELASTICSEARCH_URI: http://elasticsearch:9200/growi
  232. - name: Generate shard ID
  233. id: shard-id
  234. if: always()
  235. run: |
  236. SHARD_ID=$(echo "${{ matrix.shard }}" | tr '/' '-')
  237. echo "shard_id=${SHARD_ID}" >> $GITHUB_OUTPUT
  238. - name: Upload test results
  239. uses: actions/upload-artifact@v4
  240. if: always()
  241. with:
  242. name: blob-report-${{ matrix.browser }}-mongo${{ matrix.mongodb-version }}-${{ steps.shard-id.outputs.shard_id }}
  243. path: ./apps/app/blob-report
  244. retention-days: 30
  245. - name: Slack Notification
  246. uses: weseek/ghaction-slack-notification@master
  247. if: failure()
  248. with:
  249. type: ${{ job.status }}
  250. job_name: '*Node CI for growi - run-playwright (${{ matrix.browser }}, MongoDB ${{ matrix.mongodb-version }})*'
  251. channel: '#ci'
  252. isCompactMode: true
  253. url: ${{ secrets.SLACK_WEBHOOK_URL }}
  254. report-playwright:
  255. needs: [run-playwright]
  256. if: always() && needs.run-playwright.result != 'skipped'
  257. runs-on: ubuntu-latest
  258. steps:
  259. - uses: actions/checkout@v4
  260. - uses: pnpm/action-setup@v4
  261. - uses: actions/setup-node@v4
  262. with:
  263. node-version: ${{ inputs.node-version }}
  264. cache: 'pnpm'
  265. - name: Install dependencies
  266. run: |
  267. pnpm install --frozen-lockfile
  268. - name: Download blob reports
  269. uses: actions/download-artifact@v4
  270. with:
  271. pattern: blob-report-*
  272. path: all-blob-reports
  273. merge-multiple: true
  274. - name: Merge into HTML Report
  275. run: |
  276. mkdir -p playwright-report
  277. if [ -z "$(ls all-blob-reports/*.zip all-blob-reports/*.blob 2>/dev/null || true)" ]; then
  278. echo "<html><body><h1>No test results available</h1><p>This could be because tests were skipped or all artifacts were not available.</p></body></html>" > playwright-report/index.html
  279. else
  280. pnpm playwright merge-reports --reporter html all-blob-reports
  281. fi
  282. - name: Upload HTML report
  283. uses: actions/upload-artifact@v4
  284. with:
  285. name: html-report
  286. path: playwright-report
  287. retention-days: 30