summaryrefslogtreecommitdiff
path: root/.github
diff options
context:
space:
mode:
Diffstat (limited to '')
-rw-r--r--.github/workflows/ci.yml95
1 files changed, 95 insertions, 0 deletions
diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml
new file mode 100644
index 0000000..ebfe3cb
--- /dev/null
+++ b/.github/workflows/ci.yml
@@ -0,0 +1,95 @@
+name: ci
+
+on:
+ push:
+ branches: [main]
+ tags: ['v*']
+ pull_request:
+
+permissions:
+ contents: read
+
+jobs:
+ test:
+ runs-on: ubuntu-latest
+ services:
+ postgres:
+ image: postgres:16-alpine
+ env:
+ POSTGRES_USER: aigw
+ POSTGRES_PASSWORD: integration-only
+ POSTGRES_DB: aigw_test
+ ports: ['5432:5432']
+ options: >-
+ --health-cmd "pg_isready -U aigw -d aigw_test"
+ --health-interval 5s --health-timeout 3s --health-retries 20
+ redis:
+ image: redis:7-alpine
+ ports: ['6379:6379']
+ options: >-
+ --health-cmd "redis-cli ping" --health-interval 5s --health-timeout 3s --health-retries 20
+ env:
+ AIGW_TEST_DATABASE_URL: postgres://aigw:integration-only@127.0.0.1:5432/aigw_test?sslmode=disable
+ steps:
+ - uses: actions/checkout@v4
+ - uses: actions/setup-go@v5
+ with:
+ go-version-file: go.mod
+ cache: true
+ - run: go test -count=1 -p=1 ./...
+ - run: go test -race -count=1 -p=1 ./...
+ - run: go vet ./...
+ - run: CGO_ENABLED=0 go build -buildvcs=false -trimpath ./cmd/...
+
+ image:
+ needs: test
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+ packages: write
+ id-token: write
+ steps:
+ - uses: actions/checkout@v4
+ - uses: docker/setup-buildx-action@v3
+ - uses: docker/build-push-action@v6
+ with:
+ context: .
+ load: true
+ tags: aigw:${{ github.sha }}
+ - uses: anchore/sbom-action@v0
+ with:
+ image: aigw:${{ github.sha }}
+ format: spdx-json
+ output-file: sbom.spdx.json
+ - uses: actions/upload-artifact@v4
+ with:
+ name: sbom-spdx
+ path: sbom.spdx.json
+ - uses: aquasecurity/trivy-action@0.28.0
+ with:
+ image-ref: aigw:${{ github.sha }}
+ format: table
+ exit-code: '1'
+ ignore-unfixed: true
+ severity: HIGH,CRITICAL
+ - uses: docker/login-action@v3
+ if: startsWith(github.ref, 'refs/tags/v')
+ with:
+ registry: ghcr.io
+ username: ${{ github.actor }}
+ password: ${{ secrets.GITHUB_TOKEN }}
+ - id: publish
+ uses: docker/build-push-action@v6
+ if: startsWith(github.ref, 'refs/tags/v')
+ with:
+ context: .
+ push: true
+ tags: ghcr.io/${{ github.repository }}:${{ github.ref_name }}
+ - uses: sigstore/cosign-installer@v3
+ if: startsWith(github.ref, 'refs/tags/v')
+ - name: Sign image by digest
+ if: startsWith(github.ref, 'refs/tags/v')
+ env:
+ IMAGE: ghcr.io/${{ github.repository }}
+ DIGEST: ${{ steps.publish.outputs.digest }}
+ run: cosign sign --yes "$IMAGE@$DIGEST"