test: add Kubernetes deployment end-to-end gate #49
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Pre-commit | |
| on: | |
| push: | |
| branches: [ main, develop ] | |
| pull_request: | |
| branches: [ main, develop ] | |
| workflow_dispatch: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| env: | |
| GO_VERSION: '1.25' | |
| jobs: | |
| pre-commit: | |
| name: Pre-commit Checks | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v5 | |
| with: | |
| fetch-depth: 0 | |
| - name: Set up Python | |
| uses: actions/setup-python@v6 | |
| with: | |
| python-version: '3.11' | |
| - name: Set up Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ env.GO_VERSION }} | |
| cache: false | |
| - name: Cache Python dependencies | |
| uses: actions/cache@v5 | |
| with: | |
| path: ~/.cache/pip | |
| key: ${{ runner.os }}-pip-${{ hashFiles('**/.pre-commit-config.yaml') }} | |
| restore-keys: | | |
| ${{ runner.os }}-pip- | |
| - name: Cache Go modules | |
| uses: actions/cache@v5 | |
| with: | |
| path: | | |
| ~/.cache/go-build | |
| ~/go/pkg/mod | |
| key: ${{ runner.os }}-go-v2-${{ hashFiles('**/go.sum') }} | |
| restore-keys: | | |
| ${{ runner.os }}-go-v2- | |
| - name: Cache pre-commit | |
| uses: actions/cache@v5 | |
| with: | |
| path: ~/.cache/pre-commit | |
| key: ${{ runner.os }}-pre-commit-${{ hashFiles('**/.pre-commit-config.yaml') }} | |
| restore-keys: | | |
| ${{ runner.os }}-pre-commit- | |
| - name: Install dependencies | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install pre-commit | |
| go mod download | |
| go mod tidy | |
| - name: Run pre-commit | |
| # The maintained composite action embeds actions/cache@v4 and cannot | |
| # select the Go toolchain required by the pinned golangci-lint release. | |
| # Run the tool installed above directly so this release gate is both | |
| # reproducible and on a supported Actions runtime. | |
| env: | |
| GOTOOLCHAIN: auto | |
| run: pre-commit run --show-diff-on-failure --color=always --all-files | |
| security-scan: | |
| name: Security Scan | |
| runs-on: ubuntu-latest | |
| permissions: | |
| actions: read | |
| contents: read | |
| security-events: write | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v5 | |
| - name: Set up Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ env.GO_VERSION }} | |
| cache: false | |
| - name: Cache Go modules | |
| uses: actions/cache@v5 | |
| with: | |
| path: | | |
| ~/.cache/go-build | |
| ~/go/pkg/mod | |
| key: ${{ runner.os }}-go-v2-${{ hashFiles('**/go.sum') }} | |
| restore-keys: | | |
| ${{ runner.os }}-go-v2- | |
| - name: Install dependencies | |
| run: | | |
| go mod download | |
| go mod tidy | |
| - name: Run Gosec Security Scanner | |
| run: | | |
| go install github.com/securego/gosec/v2/cmd/gosec@latest | |
| # Enforce the scanner's SARIF findings explicitly. This preserves a | |
| # strict gate even when GoSec exits non-zero after a successful scan. | |
| gosec -no-fail -concurrency=1 -exclude=G301,G306,G304,G204,G104,G302 -exclude-dir=examples -exclude-dir=cmd/examples -fmt sarif -out gosec-results.sarif ./... | |
| findings=$(jq '[.runs[].results[]?] | length' gosec-results.sarif) | |
| if [ "$findings" -ne 0 ]; then | |
| jq -r '.runs[].results[]? | [.ruleId, .level, .message.text, .locations[0].physicalLocation.artifactLocation.uri, (.locations[0].physicalLocation.region.startLine // 0)] | @tsv' gosec-results.sarif | |
| exit 1 | |
| fi | |
| - name: Upload Gosec SARIF file | |
| if: always() | |
| uses: github/codeql-action/upload-sarif@v4 | |
| with: | |
| sarif_file: gosec-results.sarif | |
| category: gosec | |
| continue-on-error: true | |
| - name: Run Trivy vulnerability scanner | |
| uses: aquasecurity/trivy-action@v0.36.0 | |
| with: | |
| scan-type: 'fs' | |
| scan-ref: '.' | |
| format: 'sarif' | |
| output: 'trivy-results.sarif' | |
| exit-code: '0' # Don't fail on vulnerabilities | |
| skip-dirs: 'examples,cmd/examples' | |
| - name: Upload Trivy SARIF file | |
| uses: github/codeql-action/upload-sarif@v4 | |
| with: | |
| sarif_file: trivy-results.sarif | |
| category: trivy | |
| continue-on-error: true | |
| - name: Run detect-secrets | |
| run: | | |
| pip install detect-secrets | |
| # Create baseline if it doesn't exist | |
| if [ ! -f .secrets.baseline ]; then | |
| detect-secrets scan --all-files --baseline .secrets.baseline || true | |
| fi | |
| # Run scan and audit | |
| detect-secrets scan --all-files --baseline .secrets.baseline --update || true | |
| if [ -f .secrets.baseline ]; then | |
| detect-secrets audit .secrets.baseline --report --fail-on-unaudited || echo "Secrets audit completed" | |
| fi | |
| continue-on-error: true | |
| dependency-check: | |
| name: Dependency Check | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v5 | |
| - name: Set up Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ env.GO_VERSION }} | |
| cache: false | |
| - name: Cache Go modules | |
| uses: actions/cache@v5 | |
| with: | |
| path: | | |
| ~/.cache/go-build | |
| ~/go/pkg/mod | |
| key: ${{ runner.os }}-go-v2-${{ hashFiles('**/go.sum') }} | |
| restore-keys: | | |
| ${{ runner.os }}-go-v2- | |
| - name: Install dependencies | |
| run: | | |
| go mod download | |
| go mod tidy | |
| - name: Check for vulnerabilities | |
| run: | | |
| go install golang.org/x/vuln/cmd/govulncheck@latest | |
| govulncheck ./... | |
| - name: Check for outdated dependencies | |
| run: | | |
| go list -u -m all | |
| - name: Verify dependencies | |
| run: | | |
| go mod verify | |
| code-quality: | |
| name: Code Quality | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v5 | |
| - name: Set up Go | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ env.GO_VERSION }} | |
| cache: false | |
| - name: Cache Go modules | |
| uses: actions/cache@v5 | |
| with: | |
| path: | | |
| ~/.cache/go-build | |
| ~/go/pkg/mod | |
| key: ${{ runner.os }}-go-v2-${{ hashFiles('**/go.sum') }} | |
| restore-keys: | | |
| ${{ runner.os }}-go-v2- | |
| - name: Install dependencies | |
| run: | | |
| go mod download | |
| go mod tidy | |
| - name: Install quality tools | |
| run: | | |
| go install github.com/fzipp/gocyclo/cmd/gocyclo@latest | |
| go install github.com/gordonklaus/ineffassign@latest | |
| go install github.com/client9/misspell/cmd/misspell@latest | |
| - name: Check cyclomatic complexity | |
| run: | | |
| gocyclo -over 15 ./pkg/... || echo "High complexity detected" | |
| - name: Check for inefficient assignments | |
| run: | | |
| ineffassign ./pkg/... || echo "Inefficient assignments detected" | |
| - name: Check for misspellings | |
| run: | | |
| misspell -error ./pkg/... ./docs/... ./README.md || echo "Misspellings detected" | |
| - name: Generate quality report | |
| run: | | |
| echo "## Code Quality Report" > quality-report.md | |
| echo "" >> quality-report.md | |
| echo "### Cyclomatic Complexity" >> quality-report.md | |
| gocyclo -avg ./pkg/... >> quality-report.md || true | |
| echo "" >> quality-report.md | |
| echo "### Inefficient Assignments" >> quality-report.md | |
| ineffassign ./pkg/... >> quality-report.md || true | |
| echo "" >> quality-report.md | |
| echo "### Misspellings" >> quality-report.md | |
| misspell ./pkg/... ./docs/... ./README.md >> quality-report.md || true | |
| - name: Upload quality report | |
| uses: actions/upload-artifact@v6 | |
| with: | |
| name: code-quality-report | |
| path: quality-report.md | |
| retention-days: 7 |