summaryrefslogtreecommitdiff
path: root/.github/workflows/ci.yml
blob: ebfe3cb813dbad18b662565eb58666a361b05c0d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
name: ci

on:
  push:
    branches: [main]
    tags: ['v*']
  pull_request:

permissions:
  contents: read

jobs:
  test:
    runs-on: ubuntu-latest
    services:
      postgres:
        image: postgres:16-alpine
        env:
          POSTGRES_USER: aigw
          POSTGRES_PASSWORD: integration-only
          POSTGRES_DB: aigw_test
        ports: ['5432:5432']
        options: >-
          --health-cmd "pg_isready -U aigw -d aigw_test"
          --health-interval 5s --health-timeout 3s --health-retries 20
      redis:
        image: redis:7-alpine
        ports: ['6379:6379']
        options: >-
          --health-cmd "redis-cli ping" --health-interval 5s --health-timeout 3s --health-retries 20
    env:
      AIGW_TEST_DATABASE_URL: postgres://aigw:integration-only@127.0.0.1:5432/aigw_test?sslmode=disable
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-go@v5
        with:
          go-version-file: go.mod
          cache: true
      - run: go test -count=1 -p=1 ./...
      - run: go test -race -count=1 -p=1 ./...
      - run: go vet ./...
      - run: CGO_ENABLED=0 go build -buildvcs=false -trimpath ./cmd/...

  image:
    needs: test
    runs-on: ubuntu-latest
    permissions:
      contents: read
      packages: write
      id-token: write
    steps:
      - uses: actions/checkout@v4
      - uses: docker/setup-buildx-action@v3
      - uses: docker/build-push-action@v6
        with:
          context: .
          load: true
          tags: aigw:${{ github.sha }}
      - uses: anchore/sbom-action@v0
        with:
          image: aigw:${{ github.sha }}
          format: spdx-json
          output-file: sbom.spdx.json
      - uses: actions/upload-artifact@v4
        with:
          name: sbom-spdx
          path: sbom.spdx.json
      - uses: aquasecurity/trivy-action@0.28.0
        with:
          image-ref: aigw:${{ github.sha }}
          format: table
          exit-code: '1'
          ignore-unfixed: true
          severity: HIGH,CRITICAL
      - uses: docker/login-action@v3
        if: startsWith(github.ref, 'refs/tags/v')
        with:
          registry: ghcr.io
          username: ${{ github.actor }}
          password: ${{ secrets.GITHUB_TOKEN }}
      - id: publish
        uses: docker/build-push-action@v6
        if: startsWith(github.ref, 'refs/tags/v')
        with:
          context: .
          push: true
          tags: ghcr.io/${{ github.repository }}:${{ github.ref_name }}
      - uses: sigstore/cosign-installer@v3
        if: startsWith(github.ref, 'refs/tags/v')
      - name: Sign image by digest
        if: startsWith(github.ref, 'refs/tags/v')
        env:
          IMAGE: ghcr.io/${{ github.repository }}
          DIGEST: ${{ steps.publish.outputs.digest }}
        run: cosign sign --yes "$IMAGE@$DIGEST"