planning: refresh Q4 roadmap with blocker prioritization #142
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| merge_group: | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ci-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| test: | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: actions/setup-go@v7 | |
| with: | |
| go-version-file: go.mod | |
| - uses: extractions/setup-just@v4 | |
| - name: Run the local-equivalent checks | |
| run: | | |
| go build ./... | |
| just check | |
| - name: Smoke generated project without a bootc host | |
| run: | | |
| go build -o remora ./cmd/remora | |
| D=$(mktemp -d) | |
| printf 'base: quay.io/fedora/fedora-bootc:latest\npackage_manager: dnf\npackages: [htop]\n' > "$D/remora.yaml" | |
| ./remora generate --dir "$D" | |
| grep -q 'FROM quay.io/fedora/fedora-bootc:latest' "$D/Containerfile" | |
| ./remora install --dir "$D" --no-build vim | |
| ./remora list --dir "$D" | grep -qx vim | |
| - name: Smoke the digest-pinned base path | |
| run: | | |
| D=$(mktemp -d) | |
| printf 'base: quay.io/fedora/fedora-bootc\npackage_manager: dnf\npackages: [htop]\n' > "$D/remora.yaml" | |
| # A pre-existing pin is reused verbatim, with no registry round trip. | |
| printf 'quay.io/fedora/fedora-bootc@sha256:%064d\n' 0 > "$D/base" | |
| ./remora generate --dir "$D" | |
| grep -q "FROM quay.io/fedora/fedora-bootc@sha256:" "$D/Containerfile" | |
| # The package transaction gets its own layer, so that editing a | |
| # build script does not invalidate the cached install. | |
| test "$(grep -c "<<'REMORA_EOF'" "$D/Containerfile")" = 3 | |
| # apply refuses to switch when nothing has been built. | |
| if ./remora apply --dir "$D" 2>/dev/null; then | |
| echo "apply should fail with no local image" >&2 | |
| exit 1 | |
| fi | |
| - name: Smoke the lockfile invariants without a container runtime | |
| run: | | |
| D=$(mktemp -d) | |
| printf 'package_manager: dnf\npackages: [htop]\n' > "$D/remora.yaml" | |
| printf 'quay.io/fedora/fedora-bootc@sha256:%064d\n' 0 > "$D/base" | |
| # A lockfile left by an earlier build must never outlive the | |
| # resolver: it would pin an old package set indefinitely, and the | |
| # Containerfile would COPY a file generation did not vouch for. | |
| echo stale > "$D/remora.lock.yaml" | |
| ./remora generate --dir "$D" | |
| test ! -e "$D/remora.lock.yaml" | |
| ! grep -q 'remora.lock.yaml' "$D/Containerfile" | |
| # Without a resolver the build still installs from the spec list. | |
| grep -q 'dnf -y install' "$D/Containerfile" | |
| required-checks: | |
| if: always() | |
| needs: [test] | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - name: Verify required validation passed | |
| run: test "${{ needs.test.result }}" = success |