diff options
| author | Chia <Chia@93.nz> | 2026-08-05 22:01:29 +1200 |
|---|---|---|
| committer | Chia <Chia@93.nz> | 2026-08-05 22:07:50 +1200 |
| commit | eadb2ffe85c43cf6fc741c9823cd28eedb4a844c (patch) | |
| tree | 1aba2536d57360da403aa35c9ced58b615c7064e /.github/workflows/ci.yml | |
| parent | cd0dd91ab93653631904f2ea0e574ccde6d60339 (diff) | |
feat: harden prepaid billing and commercial operations
Diffstat (limited to '.github/workflows/ci.yml')
| -rw-r--r-- | .github/workflows/ci.yml | 95 |
1 files changed, 95 insertions, 0 deletions
diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..ebfe3cb --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,95 @@ +name: ci + +on: + push: + branches: [main] + tags: ['v*'] + pull_request: + +permissions: + contents: read + +jobs: + test: + runs-on: ubuntu-latest + services: + postgres: + image: postgres:16-alpine + env: + POSTGRES_USER: aigw + POSTGRES_PASSWORD: integration-only + POSTGRES_DB: aigw_test + ports: ['5432:5432'] + options: >- + --health-cmd "pg_isready -U aigw -d aigw_test" + --health-interval 5s --health-timeout 3s --health-retries 20 + redis: + image: redis:7-alpine + ports: ['6379:6379'] + options: >- + --health-cmd "redis-cli ping" --health-interval 5s --health-timeout 3s --health-retries 20 + env: + AIGW_TEST_DATABASE_URL: postgres://aigw:integration-only@127.0.0.1:5432/aigw_test?sslmode=disable + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-go@v5 + with: + go-version-file: go.mod + cache: true + - run: go test -count=1 -p=1 ./... + - run: go test -race -count=1 -p=1 ./... + - run: go vet ./... + - run: CGO_ENABLED=0 go build -buildvcs=false -trimpath ./cmd/... + + image: + needs: test + runs-on: ubuntu-latest + permissions: + contents: read + packages: write + id-token: write + steps: + - uses: actions/checkout@v4 + - uses: docker/setup-buildx-action@v3 + - uses: docker/build-push-action@v6 + with: + context: . + load: true + tags: aigw:${{ github.sha }} + - uses: anchore/sbom-action@v0 + with: + image: aigw:${{ github.sha }} + format: spdx-json + output-file: sbom.spdx.json + - uses: actions/upload-artifact@v4 + with: + name: sbom-spdx + path: sbom.spdx.json + - uses: aquasecurity/trivy-action@0.28.0 + with: + image-ref: aigw:${{ github.sha }} + format: table + exit-code: '1' + ignore-unfixed: true + severity: HIGH,CRITICAL + - uses: docker/login-action@v3 + if: startsWith(github.ref, 'refs/tags/v') + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + - id: publish + uses: docker/build-push-action@v6 + if: startsWith(github.ref, 'refs/tags/v') + with: + context: . + push: true + tags: ghcr.io/${{ github.repository }}:${{ github.ref_name }} + - uses: sigstore/cosign-installer@v3 + if: startsWith(github.ref, 'refs/tags/v') + - name: Sign image by digest + if: startsWith(github.ref, 'refs/tags/v') + env: + IMAGE: ghcr.io/${{ github.repository }} + DIGEST: ${{ steps.publish.outputs.digest }} + run: cosign sign --yes "$IMAGE@$DIGEST" |
